Trusted Platform Module Technology Overview - Windows Security (2024)

  • Article
  • Applies to:
    Windows 11, ✅ Windows 10, ✅ Windows Server 2022, ✅ Windows Server 2019, ✅ Windows Server 2016

This article describes the Trusted Platform Module (TPM) and how Windows uses it for access control and authentication.

Feature description

The Trusted Platform Module (TPM) technology is designed to provide hardware-based, security-related functions. A TPM chip is a secure crypto-processor that is designed to carry out cryptographic operations. The chip includes multiple physical security mechanisms to make it tamper-resistant, and malicious software is unable to tamper with the security functions of the TPM. Some of the advantages of using TPM technology are:

  • Generate, store, and limit the use of cryptographic keys.
  • Use it for device authentication by using the TPM's unique RSA key, which is burned into the chip.
  • Help ensure platform integrity by taking and storing security measurements of the boot process.

The most common TPM functions are used for system integrity measurements and for key creation and use. During the boot process of a system, the boot code that is loaded (including firmware and the operating system components) can be measured and recorded in the TPM. The integrity measurements can be used as evidence for how a system started and to make sure that a TPM-based key was used only when the correct software was used to boot the system.

TPM-based keys can be configured in various ways. One option is to make a TPM-based key unavailable outside the TPM. This is good to mitigate phishing attacks because it prevents the key from being copied and used without the TPM. TPM-based keys can also be configured to require an authorization value to use them. If too many incorrect authorization guesses occur, the TPM activates its dictionary attack logic and prevents further authorization value guesses.

Different versions of the TPM are defined in specifications by the Trusted Computing Group (TCG). For more information, see the TCG Web site.

Windows edition and licensing requirements

The following table lists the Windows editions that support Trusted Platform Module (TPM):

Windows ProWindows EnterpriseWindows Pro Education/SEWindows Education
YesYesYesYes

Trusted Platform Module (TPM) license entitlements are granted by the following licenses:

Windows Pro/Pro Education/SEWindows Enterprise E3Windows Enterprise E5Windows Education A3Windows Education A5
YesYesYesYesYes

For more information about Windows licensing, see Windows licensing overview.

Automatic initialization of the TPM with Windows

Starting with Windows 10 and Windows 11, the operating system automatically initializes and takes ownership of the TPM. This means that in most cases, we recommend that you avoid configuring the TPM through the TPM management console, TPM.msc. There are a few exceptions, mostly related to resetting or performing a clean installation on a PC. For more information, see Clear all the keys from the TPM.

Note

We're no longer actively developing the TPM management console beginning with Windows Server 2019 and Windows 10, version 1809.

In certain specific enterprise scenarios limited to Windows 10, versions 1507 and 1511, Group Policy might be used to back up the TPM owner authorization value in Active Directory. Because the TPM state persists across operating system installations, this TPM information is stored in a location in Active Directory that is separate from computer objects.

Practical applications

Certificates can be installed or created on computers that are using the TPM. After a computer is provisioned, the RSA private key for a certificate is bound to the TPM and can't be exported. The TPM can also be used as a replacement for smart cards, which reduces the costs associated with creating and disbursing smart cards.

Automated provisioning in the TPM reduces the cost of TPM deployment in an enterprise. New APIs for TPM management can determine if TPM provisioning actions require physical presence of a service technician to approve TPM state change requests during the boot process.

Anti-malware software can use the boot measurements of the operating system start state to prove the integrity of a computer running Windows. These measurements include the launch of Hyper-V to test that datacenters using virtualization aren't running untrusted hypervisors. With BitLocker Network Unlock, IT administrators can push an update without concerns that a computer is waiting for PIN entry.

The TPM has several Group Policy settings that might be useful in certain enterprise scenarios. For more info, see TPM Group Policy Settings.

Device health attestation

Device health attestation enables enterprises to establish trust based on hardware and software components of a managed device. With device heath attestation, you can configure an MDM server to query a health attestation service that allows or denies a managed device access to a secure resource.

Some security issues that you can check on the devices include:

  • Is Data Execution Prevention supported and enabled?
  • Is BitLocker Drive Encryption supported and enabled?
  • Is SecureBoot supported and enabled?

Note

Windows supports Device Health Attestation with TPM 2.0. TPM 2.0 requires UEFI firmware. A device with legacy BIOS and TPM 2.0 won't work as expected.

Supported versions for device health attestation

TPM versionWindows 11Windows 10Windows Server 2022Windows Server 2019Windows Server 2016
TPM 1.2>= ver 1607Yes>= ver 1607
TPM 2.0YesYesYesYesYes
Trusted Platform Module Technology Overview - Windows Security (2024)

FAQs

Should I clear the trusted platform module? ›

Clearing the TPM can result in data loss. To protect against such loss, review the following precautions: Clearing the TPM causes you to lose all created keys associated with the TPM, and data protected by those keys, such as a virtual smart card or a sign-in PIN.

How to solve TPM problem for Windows 10? ›

Clear your TPM

Go to Start > Settings > Update & Security > Windows Security > Device security . Under Security processor, select Security processor details. Select Security processor troubleshooting, and then under Clear TPM, select Clear TPM. You'll need to restart your device to complete the process.

How to fix trusted platform module has malfunctioned error in Windows? ›

Open your Device Manager and proceed across the "Security devices" section. Step 2: On locating the TPM drivers, right-click and select "Uninstall device." Confirm the process across the pop-up and restart your device. Step 3: The TPM drivers are automatically reinstalled once you reboot your device.

What is TPM in Windows security? ›

A Trusted Platform Module (TPM) is a specialized chip on a laptop or desktop computer that is designed to secure hardware with integrated cryptographic keys. A TPM helps prove a user's identity and authenticates their device. A TPM also helps provide security against threats like firmware and ransomware attacks.

Does clearing the TPM break BitLocker? ›

Each TPM chip has a unique and secret RSA key that is embedded into it on production. If a TPM is used for security features such as BitLocker or Dell Data Security (DDS), that security must be suspended before clearing the TPM or replacing the system board.

Should I clear TPM when resetting PC? ›

When resetting your laptop, there's no need to clear the TPM unless you're concerned about security or transferring ownership. Clearing it erases sensitive data, so do it only if you have specific reasons.

How do I bypass TPM on Windows? ›

How to Bypass Windows 11 TPM the Official Microsoft Way
  1. Open Regedit. ...
  2. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup. ...
  3. Create a DWORD (32-bit) Value called AllowUpgradesWithUnsupportedTPMOrCPU if it doesn't already exist.
  4. Set AllowUpgradesWithUnsupportedTPMOrCPU to 1. ...
  5. Close regedit and restart your PC.
Jul 17, 2022

What causes TPM to fail? ›

The most common cause of TPMS sensor failure is battery exhaustion. TPMS sensors have built-in batteries with a limited lifespan.

What happens if TPM module fails? ›

So in short, if the TPM 'breaks': Any data you encrypted with a key that only exists in the TPM, which isn't backed up, is lost (i.e. your encrypted hard disk) Any cryptographic identity based on the TPM (i.e. Identity Keys) is now lost.

How to solve 80090016? ›

Solution
  1. Open File Explorer.
  2. Browse to C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\NGC.
  3. Copy the contents of NGC into a new folder and leave NGC empty. ...
  4. Go to Settings -> Accounts -> Sign in Options.
  5. Click Add a PIN and set your PIN.
  6. Delete and re-create the Account in question.
Feb 6, 2024

What is 80090016 Trusted Platform has malfunctioned? ›

This error usually happens due to the corruption of the NGC file folder which is located in the system. You may receive this error if you have replaced your system board. If your computer's trusted platform module has malfunctioned. This can also be a reason to give an Error Code 80090016.

How to skip TPM for Windows 11? ›

Create a Modified Installer: Use WinBootMate to tweak a Windows 11 ISO. It'll work its magic to remove the TPM and Secure Boot checks from the installation process. Boot and Install: Once you've got your modified Windows 11 ISO, you'll need to create a bootable USB with it.

Is TPM safe to turn on? ›

Does TPM 2.0 slow down computers? The simple answer is no, TPM has no effects on our computer system because it was built into the motherboard and, once enabled, it just serves as a cryptographic key storage device and performs cryptographic operations on drives.

How do I disable TPM security? ›

Solution
  1. Restart your computer and enter the BIOS setup by pressing the appropriate key during startup. ...
  2. Navigate to the Security or Advanced tab using the arrow keys.
  3. Look for the TPM option and select it.
  4. Choose the option to disable (or enable) the TPM.
  5. Save your changes and exit the BIOS setup.
  6. Restart your computer.

What happens if I clear the Trusted Platform Module? ›

As the warning message hints, we can conclude that clearing TPM will erase all created keys related to the TPM such as the BitLocker recovery key. In addition, it will delete all data protected by these TPM-relevant keys, such as a sign-in PIN, virtual smart card, etc.

Is it ok to clear TPM reddit? ›

PSA: Never remove the TPM module because removing it can brick the module permanently. : r/homelab.

What happens when you clear TPM on Reddit? ›

Users will not be able to log in to Windows if using Windows Hello. If the TPM is cleared, you'll have to sign in with your password and then remove the PIN and add it back.

Is Trusted Platform Module safe? ›

A TPM chip is a secure crypto-processor that is designed to carry out cryptographic operations. The chip includes multiple physical security mechanisms to make it tamper-resistant, and malicious software is unable to tamper with the security functions of the TPM.

Top Articles
UK 2015 Battle of Britain 50p is worth £1
The FTI Drug | The Progeria Research Foundation
Craigslist Home Health Care Jobs
Sprinter Tyrone's Unblocked Games
craigslist: kenosha-racine jobs, apartments, for sale, services, community, and events
Hk Jockey Club Result
Doublelist Paducah Ky
Fallout 4 Pipboy Upgrades
Uvalde Topic
Caroline Cps.powerschool.com
2021 Lexus IS for sale - Richardson, TX - craigslist
83600 Block Of 11Th Street East Palmdale Ca
D10 Wrestling Facebook
Scenes from Paradise: Where to Visit Filming Locations Around the World - Paradise
Q Management Inc
8664751911
Busted Newspaper Fauquier County Va
The BEST Soft and Chewy Sugar Cookie Recipe
Seeking Arrangements Boston
About My Father Showtimes Near Copper Creek 9
Greenville Sc Greyhound
Gas Buddy Prices Near Me Zip Code
Which Sentence is Punctuated Correctly?
Suspiciouswetspot
The Boogeyman (Film, 2023) - MovieMeter.nl
Jackie Knust Wendel
4Oxfun
Weathervane Broken Monorail
Webworx Call Management
208000 Yen To Usd
Afni Collections
Pulitzer And Tony Winning Play About A Mathematical Genius Crossword
Pronóstico del tiempo de 10 días para San Josecito, Provincia de San José, Costa Rica - The Weather Channel | weather.com
Rural King Credit Card Minimum Credit Score
Jackass Golf Cart Gif
Revelry Room Seattle
123Moviestvme
Kips Sunshine Kwik Lube
Build-A-Team: Putting together the best Cathedral basketball team
Admissions - New York Conservatory for Dramatic Arts
Rochester Ny Missed Connections
Doordash Promo Code Generator
Postgraduate | Student Recruitment
Mathews Vertix Mod Chart
Port Huron Newspaper
Joblink Maine
4Chan Zelda Totk
Mkvcinemas Movies Free Download
Fahrpläne, Preise und Anbieter von Bookaway
Gameplay Clarkston
Códigos SWIFT/BIC para bancos de USA
Wayward Carbuncle Location
Latest Posts
Article information

Author: Errol Quitzon

Last Updated:

Views: 6088

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.