Manage TPM commands (2024)

Edit

Share via

This article for the IT professional describes how to manage which Trusted Platform Module (TPM) commands are available to domain users and to local users.

After a computer user takes ownership of the TPM, the TPM owner can limit which TPM commands can be run by creating a list of blocked TPM commands. The list can be created and applied to all computers in a domain by using Group Policy, or a list can be created for individual computers by using the TPM MMC. Because some hardware vendors might provide more commands or the Trusted Computing Group might decide to add commands in the future, the TPM MMC also supports the ability to block new commands.

The following procedures describe how to manage the TPM command lists. You must be a member of the local Administrators group.

Block TPM commands by using the Local Group Policy Editor

  1. Open the Local Group Policy Editor (gpedit.msc). If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then select Yes.

    Note

    Administrators with appropriate rights in a domain can configure a Group Policy Object (GPO) that can be applied through Active Directory Domain Services (AD DS).

  2. In the console tree, under Computer Configuration, expand Administrative Templates, and then expand System.

  3. Under System, select Trusted Platform Module Services.

  4. In the details pane, double-click Configure the list of blocked TPM commands.

  5. Select Enabled, and then select Show.

  6. For each command that you want to block, select Add, enter the command number, and then select OK.

    Note

    For a list of commands, see links in the TPM Specification.

  7. After adding numbers for each command that you want to block, select OK twice.

  8. Close the Local Group Policy Editor.

Block or allow TPM commands by using the TPM MMC

  1. Open the TPM MMC (tpm.msc). If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then select Yes.
  2. In the console tree, select Command Management. A list of TPM commands is displayed.
  3. In the list, select a command that you want to block or allow.
  4. Under Actions, select Block Selected Command or Allow Selected Command as needed. If Allow Selected Command is unavailable, that command is currently blocked by Group Policy.

Block new commands

  1. Open the TPM MMC (tpm.msc). If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then select Yes.
  2. In the console tree, select Command Management. A list of TPM commands is displayed.
  3. In the Action pane, select Block New Command. The Block New Command dialog box is displayed.
  4. In the Command Number text box, type the number of the new command that you want to block, and then select OK. The command number you entered is added to the blocked list.

Use the TPM cmdlets

You can manage the TPM using Windows PowerShell. For details, see TrustedPlatformModule PowerShell cmdlets.

Feedback

Was this page helpful?

Manage TPM commands (2024)
Top Articles
What do you meme you can get sued for that social post?
What Is SOAR? Security Orchestration, Automation, and Response | Fortinet
Fiskars X27 Kloofbijl - 92 cm | bol
Chs.mywork
English Bulldog Puppies For Sale Under 1000 In Florida
Quick Pickling 101
East Cocalico Police Department
Mr Tire Prince Frederick Md 20678
7543460065
Horned Stone Skull Cozy Grove
Cool Math Games Bucketball
Enderal:Ausrüstung – Sureai
Chris Hipkins Fue Juramentado Como El Nuevo Primer Ministro De...
Gma Deals And Steals Today 2022
Missed Connections Dayton Ohio
Chastity Brainwash
Hanger Clinic/Billpay
Candy Land Santa Ana
Trivago Sf
Nevermore: What Doesn't Kill
Mccain Agportal
Leccion 4 Lesson Test
Loft Stores Near Me
I Saysopensesame
Military life insurance and survivor benefits | USAGov
Best Nail Salons Open Near Me
Mini Handy 2024: Die besten Mini Smartphones | Purdroid.de
پنل کاربری سایت همسریابی هلو
Is Light Raid Hard
What Is a Yurt Tent?
Effingham Daily News Police Report
Osrs Important Letter
Wasmo Link Telegram
Where Can I Cash A Huntington National Bank Check
Lowell Car Accident Lawyer Kiley Law Group
JD Power's top airlines in 2024, ranked - The Points Guy
The Pretty Kitty Tanglewood
Tyler Sis 360 Boonville Mo
Chuze Fitness La Verne Reviews
Dynavax Technologies Corp (DVAX)
Labyrinth enchantment | PoE Wiki
Unifi Vlan Only Network
Express Employment Sign In
This Doctor Was Vilified After Contracting Ebola. Now He Sees History Repeating Itself With Coronavirus
Rétrospective 2023 : une année culturelle de renaissances et de mutations
Charlotte North Carolina Craigslist Pets
Read Love in Orbit - Chapter 2 - Page 974 | MangaBuddy
Scholar Dollar Nmsu
Noaa Duluth Mn
Olay Holiday Gift Rebate.com
login.microsoftonline.com Reviews | scam or legit check
Latest Posts
Article information

Author: Fr. Dewey Fisher

Last Updated:

Views: 5535

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Fr. Dewey Fisher

Birthday: 1993-03-26

Address: 917 Hyun Views, Rogahnmouth, KY 91013-8827

Phone: +5938540192553

Job: Administration Developer

Hobby: Embroidery, Horseback riding, Juggling, Urban exploration, Skiing, Cycling, Handball

Introduction: My name is Fr. Dewey Fisher, I am a powerful, open, faithful, combative, spotless, faithful, fair person who loves writing and wants to share my knowledge and understanding with you.