Happy Birthday, Windows 11... It's an amazing operating system with massive power just below the surface.
I would change and add many things, but there are many, many more I wouldn't. These are the hidden gems, pieces of Windows that people take for granted.
Like the subsystem model. Win32 was never the operating system. It was a personality bolted onto NT, same as the old OS/2 and POSIX subsystems. That design decision from 1993 is why WSL exists at all. WSL1 ran Linux binaries as pico processes against a translation layer; WSL2 runs a real Linux kernel in a utility VM, and your distro still shows up as a normal Windows process tree you can attach a debugger to. People treat that as a feature. It is Dave Cutler's subsystem idea, still paying rent thirty years later.
ACLs on every object, not just files. A process, a thread, a section, an event, a mutant, a token, a job — each one carries a security descriptor. The Object Manager doesn't special-case "files get security, everything else is a free-for-all." Open a handle and the Security Reference Monitor checks the ACL. That is why you can lock down a named pipe, a registry key, or another process with the same model, and why "run as" and restricted tokens actually mean something.
The Object Manager itself. One namespace. \Device, \BaseNamedObjects, \Sessions, \Registry.
Handles, reference counts, and a consistent lifetime model for almost everything the kernel exposes. Most of what you think of as "Windows APIs" is a user-mode wrapper over an object you opened by name or by inheritance.
I/O completion ports and the I/O manager. Overlapped I/O is not a later bolt-on. IRPs, cancel routines, and a completion port that a thread pool can drain are how a service handles tens of thousands of sockets without a thread per connection.
NTFS sits on the same path: journaling, the USN change journal, reparse points, sparse files, hard links, transactions when you want them. Cloud placeholders and symlinks are reparse points. They are not a hack layered on later.
Job objects. A process is not the unit of resource control. A job is. CPU rate, memory, I/O, kill-on-close, nested jobs. Windows containers and a lot of sandboxing are just job objects with a nicer hat.
ALPC for the cross-process calls you never see. Services, RPC, COM activation, the window manager talking to win32k — local procedure calls with security context carried along, not a pile of ad-hoc shared memory.
And under it all, a type-1 hypervisor. The root partition is a guest. VBS, HVCI, Credential Guard, and the WSL2 VM are the same machinery. Memory integrity and isolated LSASS are not apps. They are partitions the kernel agreed to live beside.
None of this shows up in a screenshot. It is why the thing still runs software from the 90s, a Linux toolchain, a GPU game, and a hypervisor-isolated credential store on the same box without each of those being a separate product. The shell can be argued with. The executive underneath it is the part I would keep.
You could slap a new face on it tomorrow, and it would look entirely fresh while being incredibly stable thanks to 30+ years of dedicated engineering.