If all else fails, you can patch the Windows 11 ISO manually using a script instead of relying on Rufus’s auto-patch.

After clicking Start, Rufus opens a menu with checkboxes for bypassing TPM and Secure Boot. If you select too many conflicting options, it may fail. Start with only "Remove requirement for 4GB+ RAM, Secure Boot and TPM 2.0."

Add a toggle that runs the entire patching sequence inside a Windows Sandbox or Windows Defender Application Guard temporary container — ensuring host security policies never interfere.