What TPM is and why you might disable it
TPM (Trusted Platform Module) is a small chip on your motherboard that stores encryption keys and security credentials. Windows uses it to encrypt your hard drive, protect your login password, and verify that your system hasn't been tampered with. On newer Windows machines, TPM 2.0 is required for features like Windows Hello facial recognition and BitLocker encryption.
You might want to disable TPM if you're troubleshooting a hardware problem, testing software compatibility, or preparing a computer for a specific use case where TPM causes conflicts. Disabling it won't break Windows, but you will lose the security features that depend on it — mainly BitLocker encryption and some Windows Hello authentication methods.
The steps differ depending on whether you access TPM through Windows settings or your computer's BIOS (the firmware that runs before Windows starts). Most people can disable it from Windows itself, but some situations require going into BIOS.
Key Takeaways
- You can disable TPM from Windows Settings under Device Security, which is the simplest route for most users.
- If TPM doesn't appear in Windows Settings, you'll need to restart your computer and enter BIOS to disable it there.
- Disabling TPM will turn off BitLocker encryption and some Windows Hello sign-in methods, but Windows will still run normally.
- After disabling TPM in BIOS, restart your computer and check Windows Settings to confirm the change took effect.
Disable TPM from Windows Settings
Open Settings by pressing Windows key + I, then go to Privacy & Security in the left sidebar. Scroll down and click Device Security. You should see a section labeled Security Processor with information about your TPM version.
Click Manage Security Processor. A new window will open showing TPM settings. Look for an option to turn off or disable the security processor — the exact wording varies by manufacturer. Click that option, then restart your computer when prompted. Windows will disable TPM on the next startup.
If you don't see a "Manage Security Processor" button, or if Device Security doesn't appear in Privacy & Security, your computer's TPM is controlled only through BIOS and you'll need to follow the BIOS method instead.
Disable TPM through BIOS
Restart your computer and watch the startup screen carefully. As soon as you see the manufacturer's logo (Dell, HP, Lenovo, Asus, etc.), look for a message that says "Press F2 to enter Setup" or "Press Delete to enter BIOS" — the key varies by brand. Press that key repeatedly until the BIOS menu opens. If you miss it, restart and try again.
Once in BIOS, look for a section called Security, Integrated Peripherals, or Advanced. The exact menu structure depends on your manufacturer. Inside that section, find an option labeled TPM, Security Chip, PTT (Platform Trust Technology), or fTPM (firmware TPM). The setting is usually a toggle between Enabled and Disabled.
Change it to Disabled, then save your changes. BIOS will ask you to confirm — usually by pressing F10 or another key shown on screen. Your computer will restart automatically. Once Windows loads, go back to Settings > Privacy & Security > Device Security to confirm that TPM is now off.
What happens after you disable TPM
BitLocker encryption will stop protecting your hard drive. If BitLocker was already on, Windows will ask you to suspend it before you can disable TPM. You can turn BitLocker back on later if you re-enable TPM, but you'll need to restart the encryption process.
Windows Hello facial recognition and fingerprint login will no longer work — you'll fall back to your password or PIN. Other sign-in methods like a Microsoft account password will still function normally.
Windows itself will run without problems. TPM is a security feature, not a core requirement for the operating system to function. You won't see error messages or performance changes.
Re-enabling TPM when you're done
If you disabled TPM through Windows Settings, open Settings again, go to Privacy & Security > Device Security > Manage Security Processor, and turn the security processor back on. Restart your computer.
If you disabled it in BIOS, restart your computer, press the BIOS key during startup, find the TPM setting in the same menu where you disabled it, change it back to Enabled, save, and restart. Windows will recognize TPM again on the next startup.
If you had BitLocker on before disabling TPM, you can turn it back on once TPM is re-enabled. Go to Settings > System > About, scroll down to find Device Encryption or BitLocker, and turn it on. The encryption process will take time depending on your drive size.
Troubleshooting if TPM won't disable
If you see TPM in Windows Settings but the disable option is greyed out, BitLocker is likely still active. Go to Settings > System > About and look for Device Encryption or BitLocker. Turn it off first, restart, then try disabling TPM again.
If TPM doesn't appear in Windows Settings at all and you can't find it in BIOS either, your computer may not have a TPM chip — some older or budget models don't include one. In that case, there's nothing to disable.
If you enter BIOS but can't find the TPM setting, check your computer's manual or the manufacturer's support website for your specific model. BIOS menu layouts vary widely, and the setting might be under a different name or in a section you haven't checked yet.
Frequently Asked Questions
Will disabling TPM make Windows less secure?
Yes, you'll lose BitLocker encryption and some authentication methods. If security is important for your use case, you should leave TPM on. Disabling it is mainly useful for troubleshooting or specific compatibility situations.
Can I disable TPM without restarting?
No. Whether you disable it through Windows Settings or BIOS, your computer must restart for the change to take effect. Windows needs to communicate with the firmware during startup to confirm the change.
What's the difference between disabling TPM in Windows and in BIOS?
Windows Settings is simpler and works for most people. BIOS is the deeper level where the actual chip is controlled, and you need it if Windows Settings doesn't show TPM options. Both methods achieve the same result.
If I disable TPM, will I lose my files?
No. Your files stay on your drive. If BitLocker was on, Windows will suspend encryption before letting you disable TPM, so your data remains readable. You won't lose anything by disabling TPM itself.
Do I need to disable TPM to upgrade Windows?
Not usually. Windows upgrades work fine with TPM on. If an upgrade fails and you suspect TPM is the cause, you can disable it to test, but that's a troubleshooting step, not a normal part of upgrading.