A Trusted Platform Module (TPM) is a small security processor in a computer that creates and guards cryptographic keys and records how the machine started. Windows 11 requires TPM 2.0, and features such as BitLocker drive encryption and Windows Hello sign-in rely on it.
The TPM does not encrypt your files, scan for malware or make a PC secure by itself. It is a building block: other software asks it to hold a key, to release that key only under set conditions, or to report what loaded during startup.
What a TPM actually does
Microsoft’s TPM technology overview describes three main jobs:
- Generate, store and limit the use of keys. A key can be made so that it never leaves the TPM, which stops it from being copied to another machine.
- Identify the device. Each TPM has a unique RSA key, a type of public-key credential, built into it.
- Record how the system booted. During startup, the firmware and operating system components that load are measured and recorded in the TPM.
A measurement here is a cryptographic fingerprint of a piece of code. If the boot code changes, the fingerprint changes.
Microsoft Research compares the TPM to a smart card or a hardware security module, but notes that it is tied into how a computer boots and runs, which a card is not. Its project page also lists a secure clock, monotonic counters and a small amount of protected storage among its features.
Sealing: a key that depends on the boot
The feature that matters most to everyday users is sealing. According to Microsoft’s TPM fundamentals, a TPM can wrap a key and tie it to specific platform measurements. The key can be unwrapped only when those measurements match the values they had when it was created.
This is how BitLocker uses the chip. The disk encryption key is protected by the TPM, and the TPM releases it only if the device has not been tampered with while it was off. Someone who removes the drive and puts it in another computer does not get the key, because the other computer’s TPM never held it.
BitLocker can add a startup PIN or a USB startup key on top of the TPM. Without a TPM, Microsoft says BitLocker can still encrypt the system drive with a startup key or a password, but neither option provides the pre-boot integrity check that a TPM adds, and the password option is disabled by default because it has no lockout against guessing.
Lockout against guessing
TPM keys can require an authorization value, such as a PIN. If too many wrong values are entered, the TPM’s dictionary-attack logic blocks further guesses. Microsoft’s fundamentals page says TPM 2.0 defines this anti-hammering behaviour in the specification, while under TPM 1.2 each manufacturer implemented it differently. Because the lockout is global rather than per key, the TPM is designed to forget failures over time so that normal use does not trigger it.
Microsoft says Windows Hello uses the TPM to store sign-in data such as PINs, so the number of guesses on that device is limited by the TPM rather than by software alone.
Chip, firmware or processor
A TPM does not have to be a separate chip. Microsoft’s support article says it can be a discrete chip on the motherboard or integrated into the main processor. Microsoft’s Pluton security processor is one integrated design, which removes the connection between the CPU and a separate security chip.
Where the TPM runs in processor firmware, the UEFI settings may label it AMD fTPM, AMD PSP fTPM or Intel PTT (Platform Trust Technology); other boards use names such as Security Device or TPM State, according to Microsoft’s guide to enabling TPM 2.0.
| Form | Where it lives | What to check |
|---|---|---|
| Discrete TPM | Separate chip on the motherboard | Present and enabled in UEFI |
| Firmware TPM | Processor firmware (fTPM, Intel PTT) | Enabled in UEFI; often off on retail motherboards |
| Integrated security processor | Inside the CPU, such as Pluton | Reported as the security processor in Windows |
TPM 1.2 and TPM 2.0
The Trusted Computing Group (TCG), an industry standards body, publishes the TPM specifications. TPM 2.0 added support for more cryptographic algorithms, stronger authorization methods and simpler management compared with TPM 1.2. The TPM 2.0 library was also published as the international standard ISO/IEC 11889:2015, and the TCG’s latest library revision is Version 185 from March 2026.
For Windows 11 the distinction is simple: the operating system requires 2.0. Microsoft also notes that TPM 2.0 needs native UEFI firmware mode; it is not supported in the legacy BIOS or Compatibility Support Module (CSM) modes.
How to check your PC
Microsoft says most PCs shipped in the last five years can run TPM 2.0, but some are not set up to do so, and retail motherboards for self-built PCs usually ship with the TPM turned off. Two checks:
- Windows Security: open Device Security. If a Security processor section appears, select Security processor details and look for Specification version 2.0.
- TPM management console: run
tpm.msc. A “Compatible TPM cannot be found” message suggests the TPM may be disabled; otherwise check Specification Version under TPM Manufacturer Information.
If the TPM is off, it is switched on in the UEFI firmware settings, which vary by manufacturer. Windows 10 and Windows 11 initialize the TPM and take ownership of it automatically, so there is normally no owner password to set up.
If you are still deciding whether to replace an older Windows 10 machine, our operating system end-of-life dates list when its updates stop.
Be careful before clearing it
Windows offers a Clear TPM option for troubleshooting or before a clean installation. Microsoft’s TPM troubleshooting page warns that clearing it can cause data loss: every key created in the TPM is lost, along with data those keys protect, such as a virtual smart card or a sign-in PIN.
Microsoft’s precautions are to make sure you have a backup and recovery method for anything the TPM protects, not to clear the TPM on a work or school PC without your IT administrator’s instruction, and to clear it from within Windows rather than directly from UEFI. For a BitLocker-encrypted drive, that means having the recovery key before you start. The same page notes that switching between two TPMs on a system that has both puts BitLocker into recovery mode.
What a TPM cannot do
A TPM protects keys and reports on startup. Once Windows has booted and you have signed in, the encrypted drive is unlocked for that session, so the TPM does not protect files from malware or from someone using your unlocked account. It also cannot restore data whose keys were lost when the TPM was cleared or the motherboard replaced. That is the job of recovery keys and backups.
For sign-in that builds on hardware-held keys, see our explainer on password managers and passkeys.
Sources and document stamp
Checked 10 October 2026 against Microsoft’s TPM technology overview, TPM fundamentals, TPM troubleshooting, BitLocker overview and Enable TPM 2.0, and the Trusted Computing Group’s TPM 2.0 Library page. No hardware was tested for this article.





