Skip to content
WindowsAdvanced

What Is TPM (Trusted Platform Module)? TPM 2.0 Explained, Uses, Security and Windows 11 Requirements

Quick Answer TPM (Trusted Platform Module) is a security technology built into many modern computers that provides a protected environment for cryptographic ...

BI
Bison Technical Team Enterprise IT specialists
Updated 04 Sep 2026 17 min read 0 total views

Quick Answer

TPM (Trusted Platform Module) is a security technology built into many modern computers that provides a protected environment for cryptographic keys, credentials, measurements, and other security-related information.

TPM helps Windows and security applications establish trust in a computer and protect sensitive information. It is commonly used with technologies such as BitLocker Drive Encryption, Windows Hello, Device Encryption, Measured Boot, credential protection, and hardware-backed authentication.

Advertisement

Modern Windows computers normally use TPM 2.0, and Microsoft requires TPM 2.0 for officially supported Windows 11 installations.

A TPM may be implemented as a dedicated hardware component or through platform firmware. On Intel-based systems, firmware TPM functionality may appear in UEFI/BIOS as Intel PTT (Platform Trust Technology), while AMD systems commonly call it AMD fTPM.

To quickly check TPM on Windows, press Windows + R, type:

tpm.msc

and press Enter.

If the TPM is enabled and working, Windows should normally report “The TPM is ready for use.”


Complete Article

What Does TPM Stand For?

TPM stands for:

Trusted Platform Module

It is a security technology standardized by the Trusted Computing Group (TCG). TPM is designed to provide security functions that can be used as a hardware-backed or hardware-isolated root of trust.

The current TPM family widely used in modern PCs is TPM 2.0. The Trusted Computing Group's current TPM 2.0 Library specification is Version 185, published in March 2026.

In simple terms, you can think of TPM as a secure foundation inside your computer that Windows and other trusted software can use for security-sensitive operations.

It does not replace antivirus software, a firewall, encryption, strong passwords, or security updates. Instead, it strengthens other security technologies by providing protected cryptographic capabilities.


Why Is TPM Important?

Many security systems need somewhere safer than ordinary disk storage to work with cryptographic secrets.

For example, if a disk-encryption key were simply stored as an ordinary unprotected file on the same disk it protects, an attacker might be able to copy or manipulate it.

TPM helps provide a more secure mechanism for generating, protecting, and using cryptographic keys.

TPM technology can contribute to:

  • Disk encryption
  • Device identity
  • Authentication
  • Platform integrity verification
  • Secure boot measurements
  • Credential protection
  • Hardware-backed cryptographic operations
  • Protection against certain offline attacks
  • Establishing whether the computer started in an expected state

The Trusted Computing Group describes TPM as technology capable of providing a secure root of trust and protecting systems and data against various digital and physical attacks.


How Does TPM Work?

A TPM provides specialized cryptographic capabilities that Windows and other applications can use.

Rather than treating every secret like ordinary data stored on the SSD or hard disk, software can use TPM-protected keys and operations.

A simplified process might look like this:

  1. The computer starts.
  2. Firmware and boot-related components are measured.
  3. Measurements can be recorded using TPM capabilities.
  4. Windows starts and can use TPM-backed security functions.
  5. Applications such as BitLocker or Windows Hello can use TPM capabilities to help protect keys and credentials.
  6. If the expected security state changes, TPM-backed protections can require additional verification or recovery.

The exact behavior depends on the Windows feature and security configuration being used.


What Information Does a TPM Protect?

Depending on the operating system and application, TPM technology can be used in connection with:

  • Cryptographic keys
  • Encryption-related secrets
  • Authentication credentials
  • Platform measurements
  • Device identity information
  • Certificates and certificate-related keys
  • PIN-protected authentication operations

One important concept is that TPM-protected private keys can be designed so that sensitive private key material does not need to be exported from the protected environment during normal operation.

TCG specifically identifies safeguarding cryptographic keys and protecting authentication information among the security capabilities enabled by TPM technology.


TPM 1.2 vs TPM 2.0

TPM 1.2 is an older TPM standard. TPM 2.0 provides a more modern architecture and support for additional cryptographic algorithms and authorization mechanisms.

Feature TPM 1.2 TPM 2.0
Generation Older Modern
Cryptographic flexibility More limited Greater algorithm flexibility
SHA-1 Supported Supports newer algorithms as well
Windows 11 requirement Does not satisfy TPM 2.0 requirement Yes
Modern PC recommendation Legacy Recommended
New Windows PCs Uncommon Standard

TCG states that TPM 2.0 introduced improvements including support for additional cryptographic algorithms, enhanced authorization mechanisms, simplified TPM management, and additional platform-security capabilities.

For modern Windows systems, TPM 2.0 should be preferred.


Is TPM 2.0 Required for Windows 11?

Yes.

Microsoft's minimum hardware requirements for Windows 11 specify:

Trusted Platform Module (TPM) version 2.0

as a requirement. Windows 11 also requires UEFI firmware that is Secure Boot capable.

This requirement was introduced because TPM 2.0 provides a hardware-backed security foundation that Windows can use for several security capabilities.

Important distinction

TPM 2.0 and Secure Boot are not the same thing.

TPM provides cryptographic and trust-related security capabilities.

Secure Boot helps prevent unauthorized bootloaders and certain untrusted software from executing during the boot process.

A Windows 11-compatible PC generally needs to satisfy Microsoft's requirements involving both technologies.


What Is Intel PTT?

Some computers do not show an option literally named "TPM" in BIOS/UEFI.

On Intel platforms, TPM functionality may be provided through:

Intel Platform Trust Technology (Intel PTT)

Therefore, BIOS/UEFI options may include names such as:

  • Intel PTT
  • PTT
  • Platform Trust Technology
  • Security Device
  • Trusted Computing
  • TPM Device
  • TPM State
  • Security Device Support

Microsoft specifically identifies Intel PTT / Intel Platform Trust Technology among the possible firmware names used when enabling TPM.


What Is AMD fTPM?

AMD-based computers may provide TPM functionality through firmware known as:

AMD fTPM — Firmware Trusted Platform Module

Depending on the motherboard or computer manufacturer, you may see BIOS/UEFI options such as:

  • AMD fTPM
  • AMD PSP fTPM
  • Firmware TPM
  • Security Device Support
  • Trusted Computing
  • TPM Device Selection

Microsoft recognizes AMD fTPM and AMD PSP fTPM as common names for TPM-related firmware settings.

So, if Windows says TPM is unavailable, do not immediately assume the motherboard has no TPM. TPM functionality may simply be disabled in UEFI/BIOS.


Discrete TPM vs Firmware TPM

TPM can be implemented in different ways.

Discrete TPM

A discrete TPM is a dedicated security chip physically installed on the motherboard.

It is specifically designed to perform TPM security operations.

Firmware TPM

Firmware TPM provides TPM functionality through the computer's platform firmware and processor/chipset security architecture.

Common examples include:

  • Intel PTT
  • AMD fTPM

For typical Windows 11 users, a supported firmware TPM 2.0 implementation can satisfy the TPM requirement; purchasing a separate physical TPM module is therefore not automatically necessary.


Do I Need to Buy a TPM Chip for Windows 11?

Usually, no.

Many relatively recent computers already have TPM 2.0 capability but may have it disabled in BIOS/UEFI.

Microsoft notes that many PCs capable of running TPM 2.0 may simply not have the feature configured or enabled.

Before purchasing a TPM module:

  1. Check Windows using tpm.msc.
  2. Check Windows Security.
  3. Check BIOS/UEFI for Intel PTT or AMD fTPM.
  4. Check your motherboard or PC manufacturer's documentation.
  5. Verify whether your motherboard supports a discrete TPM module if one is actually required.

Do not buy a random TPM module based only on the connector appearance.

TPM modules and motherboard TPM headers are not universally interchangeable. Always verify compatibility with the exact motherboard model and manufacturer documentation.


How to Check Whether TPM Is Enabled in Windows

There are several ways to check TPM status.

Method 1: Check TPM Using TPM Management

Press:

Windows + R

Type:

tpm.msc

Press Enter.

The Trusted Platform Module (TPM) Management console should open.

Look under Status.

A properly configured system will normally display:

The TPM is ready for use.

Next, look under:

TPM Manufacturer Information

Check:

Specification Version

For Windows 11 compatibility, it should show:

2.0

Microsoft recommends this method for verifying TPM 2.0 availability.


What Does "Compatible TPM Cannot Be Found" Mean?

If tpm.msc displays:

Compatible TPM cannot be found

it does not necessarily mean that your computer lacks TPM hardware.

Possible reasons include:

  • TPM is disabled in BIOS/UEFI.
  • Intel PTT is disabled.
  • AMD fTPM is disabled.
  • BIOS/UEFI configuration is incorrect.
  • Firmware requires an update.
  • The motherboard does not support TPM.
  • The system has an older TPM version.
  • The TPM or firmware has a problem.

Microsoft specifically advises checking firmware configuration when Windows cannot detect a compatible TPM.


Method 2: Check TPM Through Windows Security

In Windows 11, open:

Settings → Privacy & security → Windows Security → Device security

Look for:

Security processor

Select:

Security processor details

You can view information such as the TPM manufacturer and specification version.

You want to see:

Specification version: 2.0

for Windows 11 requirements.


Method 3: Check TPM Using PowerShell

Open PowerShell as Administrator and run:

Get-Tpm

Typical output includes values such as:

TpmPresent
TpmReady
TpmEnabled
TpmActivated
TpmOwned

For example:

TpmPresent : True
TpmReady   : True

indicates that Windows detects a TPM and that it is ready.

Administrator rights may be required for some TPM management operations.


How to Enable TPM 2.0 in BIOS or UEFI

The exact procedure varies by computer and motherboard manufacturer.

A typical process is:

  1. Restart the computer.
  2. Enter BIOS/UEFI Setup.
  3. Open Security, Advanced, or Trusted Computing.
  4. Locate the TPM-related setting.
  5. Enable it.
  6. Save changes.
  7. Restart Windows.
  8. Run tpm.msc.
  9. Confirm that Specification Version shows 2.0.

Possible TPM setting names include:

Intel systems

  • Intel PTT
  • Intel Platform Trust Technology
  • Security Device Support
  • TPM State

AMD systems

  • AMD fTPM
  • AMD PSP fTPM
  • Firmware TPM
  • Security Device Support

Microsoft confirms that TPM configuration names differ among manufacturers and commonly include these terms.


How to Enter UEFI Firmware Settings from Windows 11

You can also reach UEFI through Windows.

Go to:

Settings → System → Recovery

Under Advanced startup, select:

Restart now

Then navigate to:

Troubleshoot → Advanced options → UEFI Firmware Settings → Restart

Your computer should restart into its firmware setup interface.

The exact menu names inside UEFI vary by manufacturer.


Warning Before Changing TPM Settings

TPM configuration should not be changed casually on an existing encrypted or business computer.

Before disabling, clearing, resetting, or making major TPM/firmware changes:

  • Back up important files.
  • Verify BitLocker status.
  • Make sure your BitLocker recovery key is available.
  • Record required recovery information.
  • Follow the computer manufacturer's instructions.
  • In a managed business environment, consult the IT administrator.

This is particularly important when BitLocker is enabled.

Changing TPM or firmware-related security settings can cause BitLocker to request the recovery key during startup.


Do Not Clear TPM Just to Fix a TPM Error

This is an important troubleshooting rule.

Do not select "Clear TPM" simply because Windows reports a TPM problem.

Clearing TPM removes information and keys maintained in the TPM and can affect services that depend on them.

Before clearing TPM:

  1. Back up your data.
  2. Confirm your BitLocker recovery information.
  3. Understand which applications use TPM-protected credentials.
  4. Follow Microsoft or your PC manufacturer's troubleshooting procedure.

Clearing TPM should be a deliberate troubleshooting or administrative action—not a routine first step.


How Does TPM Work With BitLocker?

BitLocker is Microsoft's drive-encryption technology.

A TPM can work with BitLocker to help protect encryption-related secrets and verify aspects of the startup environment before allowing normal access to an encrypted operating-system drive.

If the expected startup environment changes significantly, BitLocker may enter recovery rather than automatically releasing access.

This can help protect encrypted data against certain offline attacks.

Microsoft states that BitLocker supports TPM 1.2 and TPM 2.0, although TPM 2.0 is recommended. BitLocker can also operate in certain configurations without TPM, but those configurations use different startup authentication arrangements.


Does BitLocker Require TPM?

Not absolutely.

BitLocker itself can be configured in certain Windows editions and scenarios without TPM, although this requires an alternative startup authentication method.

However, using TPM provides a convenient and security-focused way to protect key material and validate the boot environment.

TPM 2.0 is recommended for modern Windows deployments.


TPM and Windows Hello

Windows Hello allows users to authenticate using methods such as:

  • PIN
  • Fingerprint
  • Facial recognition

TPM can be used to protect cryptographic material associated with Windows Hello authentication.

This is one reason a Windows Hello PIN is fundamentally different from simply using a conventional reusable password: the authentication architecture can use device-bound cryptographic credentials protected by the device's security hardware.

Microsoft lists Windows Hello identity protection among the Windows features that make use of TPM 2.0.


TPM and Measured Boot

TPM can also participate in Measured Boot.

During startup, measurements representing components involved in the boot process can be recorded.

These measurements can later be used by security technologies to assess the integrity or trust state of the system.

Microsoft identifies TPM as a requirement for Measured Boot and recommends TPM 2.0 because it supports newer cryptographic algorithms.


TPM vs Secure Boot

TPM and Secure Boot are related to system security but perform different jobs.

TPM Secure Boot
Provides trusted cryptographic capabilities Controls trusted boot components
Protects or works with cryptographic keys Helps block unauthorized boot software
Can record platform measurements Verifies signatures during boot
Used by BitLocker and other security features Protects the boot process
TPM 2.0 required by Windows 11 Secure Boot capability required by Windows 11

They complement each other rather than replace each other.


TPM vs BitLocker

TPM and BitLocker are also not the same technology.

TPM = security foundation

BitLocker = drive encryption technology

TPM can help BitLocker securely protect key material and verify the startup environment.

Think of it this way:

BitLocker protects the data on the drive, while TPM can help protect the keys and trust decisions involved in unlocking that encrypted data.


Does TPM Encrypt Your Hard Drive?

No.

TPM itself is not disk-encryption software.

BitLocker or another encryption system performs the actual disk encryption.

TPM provides cryptographic and trust-related capabilities that encryption technologies can use.

Therefore:

TPM ≠ BitLocker

but:

TPM + BitLocker can provide stronger and more convenient protection than relying on disk encryption alone in many configurations.


Does TPM Store Your BitLocker Recovery Key?

It is misleading to describe TPM simply as a storage location for the BitLocker recovery key.

BitLocker uses TPM-protected key material as part of its key-protection architecture, while the BitLocker recovery key/recovery password is a separate recovery mechanism.

Your recovery information may be backed up to places such as a Microsoft account, Microsoft Entra ID, Active Directory, a file, printout, or another administrator-controlled location depending on how the device is configured.

Therefore, you should still make sure you have access to your BitLocker recovery information before making firmware or TPM changes.


Does TPM Make a Computer Impossible to Hack?

No.

TPM significantly strengthens certain security functions, but it does not make a computer invulnerable.

TPM does not replace:

  • Antivirus or endpoint protection
  • Windows security updates
  • Firewall protection
  • Strong authentication
  • Secure passwords
  • Multi-factor authentication
  • Data backups
  • Application updates
  • Safe browsing practices
  • Physical security

TPM should be considered one layer in a defense-in-depth security strategy.


Does TPM Affect Computer Performance?

For normal users, TPM generally does not cause a noticeable performance reduction.

TPM performs specialized security and cryptographic operations rather than acting as the main processor for everyday applications.

You normally should not disable TPM to improve PC performance.

Doing so may instead disable or interfere with important security features.


Can TPM Be Disabled?

Many systems allow TPM, Intel PTT, or AMD fTPM to be disabled through UEFI/BIOS.

However, disabling TPM without a specific reason is generally not recommended on a modern Windows computer.

It can affect:

  • BitLocker
  • Device Encryption
  • Windows Hello
  • Measured Boot
  • Credential-related security
  • Windows 11 compatibility
  • Other applications relying on TPM

Always check encryption and recovery information before changing the setting.


Can TPM Be Upgraded From 1.2 to 2.0?

Sometimes—but not universally.

Whether TPM 1.2 can be upgraded to TPM 2.0 depends on:

  • Computer manufacturer
  • Motherboard
  • TPM implementation
  • Firmware
  • BIOS/UEFI
  • Hardware generation

Some older systems received manufacturer-supported firmware upgrades from TPM 1.2 to TPM 2.0, while others cannot be upgraded.

Do not attempt unofficial TPM firmware modifications.

Check the computer or motherboard manufacturer's documentation for the exact model.


Does Every Computer Have TPM?

No.

Older computers may:

  • Have TPM 1.2
  • Have TPM 2.0
  • Support an optional discrete TPM module
  • Support firmware TPM
  • Have TPM functionality disabled
  • Have no supported TPM capability

Most modern Windows PCs are much more likely to include TPM 2.0 capability.


TPM 2.0 and Legacy BIOS

TPM 2.0 Windows deployments are closely associated with modern UEFI firmware.

Microsoft's BitLocker documentation notes that TPM 2.0 is not supported in Legacy BIOS/Compatibility Support Module (CSM) mode for this scenario; TPM 2.0 systems should use native UEFI with Legacy/CSM disabled.

This is particularly relevant when preparing an older computer for Windows 11.

Do not simply switch an existing Windows installation from Legacy BIOS to UEFI without checking how Windows and the disk are configured, because an incorrect change can make the system unbootable.


Common TPM Problems

TPM is not detected

Check:

  • BIOS/UEFI TPM setting
  • Intel PTT
  • AMD fTPM
  • BIOS updates
  • Windows Device Security
  • tpm.msc

TPM 1.2 is detected instead of 2.0

Check whether the computer manufacturer provides a supported TPM firmware upgrade.

TPM is enabled but Windows 11 still says the PC is unsupported

TPM is only one Windows 11 requirement.

Also check:

  • Supported processor
  • UEFI
  • Secure Boot capability
  • RAM
  • Storage
  • Graphics requirements

Microsoft's current Windows 11 requirements include TPM 2.0 and UEFI Secure Boot capability along with other hardware requirements.

BitLocker asks for a recovery key after BIOS changes

This can occur after security-sensitive firmware or hardware configuration changes.

Use the legitimate BitLocker recovery information associated with the computer rather than attempting to bypass encryption.


Should TPM 2.0 Be Enabled?

For a supported modern Windows computer, yes, TPM 2.0 should generally remain enabled.

It supports important Windows security technologies and is part of Microsoft's Windows 11 hardware security baseline.

There is usually no benefit for an ordinary user in disabling a properly functioning TPM.


FAQ

1. What is TPM in simple words?

TPM is a security technology in your computer that provides protected cryptographic functions used by Windows and other security applications.

2. What does TPM stand for?

TPM stands for Trusted Platform Module.

3. What is TPM 2.0?

TPM 2.0 is the modern generation of the Trusted Platform Module specification and supports newer and more flexible security capabilities than TPM 1.2.

4. Is TPM 2.0 required for Windows 11?

Yes. Microsoft's minimum Windows 11 requirements specify TPM version 2.0.

5. How do I check TPM in Windows 11?

Press Windows + R, type tpm.msc, and press Enter. Check the Specification Version under TPM Manufacturer Information.

6. What TPM version do I need for Windows 11?

You need TPM 2.0 for Microsoft's officially supported Windows 11 hardware requirements.

7. Is Intel PTT the same as TPM?

Intel PTT provides firmware-based TPM functionality on supported Intel platforms and may appear instead of a setting simply called TPM.

8. What is AMD fTPM?

AMD fTPM is AMD's firmware-based implementation of TPM functionality.

9. Do I need to buy a physical TPM chip?

Usually not. Many modern computers already provide TPM 2.0 through integrated or firmware-based technology. Check BIOS/UEFI before purchasing hardware.

10. Does TPM encrypt my SSD?

No. TPM is not disk-encryption software. Technologies such as BitLocker perform drive encryption.

11. Does BitLocker need TPM?

BitLocker can operate in supported configurations without TPM, but TPM provides important security and usability benefits and TPM 2.0 is recommended for modern Windows systems.

12. Is TPM the same as Secure Boot?

No. TPM provides cryptographic trust capabilities, while Secure Boot helps prevent unauthorized software from loading during the boot process.

13. Is it safe to enable TPM?

Generally, yes. TPM is an important security feature. However, changes to TPM or firmware settings on an existing encrypted system should be made carefully.

14. Is it safe to clear TPM?

Clearing TPM can remove TPM-protected information and affect security features. Do not clear TPM casually, especially on a BitLocker-protected or business-managed computer.

15. Does TPM slow down a computer?

TPM normally has no noticeable negative effect on everyday PC performance.

16. Can TPM 1.2 be upgraded to TPM 2.0?

Some systems support manufacturer-provided TPM firmware upgrades, but many do not. Compatibility depends on the specific computer and TPM implementation.

17. Why does tpm.msc say "Compatible TPM cannot be found"?

TPM may be disabled in UEFI/BIOS, or the computer may not have a compatible TPM. Check for Intel PTT, AMD fTPM, Security Device Support, or Trusted Computing settings.

18. Can I disable TPM after installing Windows 11?

It may be technically possible on some systems, but doing so is not recommended because Windows security features can depend on TPM and TPM 2.0 is part of the Windows 11 hardware requirements.

19. Does TPM protect against viruses?

TPM is not antivirus software. It strengthens certain cryptographic, authentication, and platform-integrity protections but does not replace antivirus or endpoint security.

20. Should I enable TPM 2.0?

For a modern supported Windows computer, TPM 2.0 should generally be enabled unless you have a specific technical or administrative reason to disable it.


Final Recommendation / Conclusion

TPM is one of the foundational security technologies in modern Windows computers. It provides protected cryptographic capabilities that Windows can use for technologies including BitLocker, Windows Hello, Device Encryption, and Measured Boot.

For Windows 11 users, TPM 2.0 is especially important because it is part of Microsoft's minimum hardware requirements.

If tpm.msc reports that no compatible TPM is available, do not immediately purchase a TPM module. First check the computer's UEFI/BIOS for Intel PTT, AMD fTPM, Security Device Support, Trusted Computing, or TPM State, because TPM 2.0 capability may already be built into the system but disabled.

Most importantly, do not clear, reset, disable, or significantly change TPM settings on a BitLocker-encrypted computer without first ensuring that your BitLocker recovery information and important data are safely backed up.

 

#TPM #TPM2 #TPM20 #TrustedPlatformModule #Windows11 #WindowsSecurity #TPMSecurity #HardwareSecurity #CyberSecurity #ComputerSecurity #Windows11Security #Windows11TPM #BitLocker #BitLockerEncryption #SecureBoot #WindowsHello #DeviceEncryption #MeasuredBoot #IntelPTT #AMDfTPM #FirmwareTPM #DiscreteTPM #TPMChip #TPMModule #TPMWindows11 #WindowsTips #WindowsHelp #WindowsSupport #WindowsTroubleshooting #PCSecurity #DataSecurity #Encryption #Cryptography #HardwareEncryption #TrustedComputing #TCG #UEFI #BIOS #BIOSSettings #SecurityProcessor #GetTPM #WindowsPowerShell #TPMTroubleshooting #TPMError #TPMNotDetected #Windows11Requirements #PCCompatibility #BitLockerSecurity #RootOfTrust #ITSupport

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy.