Example embodiments relate to providing encrypted in-place operating system migration. In example embodiments, authentication keys are stored to an authentication area of a storage device, where the authentication area is designated for protection from data wipes. Next, a pre-installation environment that is configured to install an image of a target operating system is booted, where the pre-installation environment includes data recovery drivers for accessing an encrypted partition of the storage device. The authentication keys are used to authenticate access by the data recover drivers to the encrypted partition. At this stage, the image of the target operating system is installed to the encrypted partition by using the data recovery drivers.