What Trusted Platform Module does and why you might need it

Trusted Platform Module (TPM) is a security chip built into most modern computers that stores encryption keys and passwords in a way that's harder for hackers to steal. It works like a vault inside your machine — even if someone removes your hard drive, the data locked in TPM stays locked.

You may need to turn TPM on if Windows Update requires it, if you're setting up BitLocker disk encryption, or if your workplace security policy demands it. Some newer versions of Windows 11 actually require TPM 2.0 to be present and enabled. The chip itself is already in your computer; enabling it just means telling your system to use it.

TPM is not something you interact with directly. Once it's on, it runs in the background protecting sensitive information without slowing down your everyday work.

Key Takeaways

  • TPM is a physical security chip in your computer that stores encryption keys; enabling it means turning on access to that chip.
  • Most computers made in the last five years have TPM 2.0 built in, but it may be turned off by default in your BIOS settings.
  • You reach TPM settings through your computer's BIOS or UEFI firmware, not through Windows itself.
  • The exact steps and menu names vary by computer manufacturer, but the process takes five to ten minutes and requires a restart.
  • If you cannot find TPM in your BIOS, your computer may not have the chip, or it may be labeled under a different name like "Security Chip" or "PTT".

Check whether your computer has TPM before you start

Not every computer has a TPM chip. Older machines and some budget models skip it entirely. Before you go hunting through your BIOS settings, check whether yours actually has one.

On Windows 10 or 11, press the Windows key and type "tpm.msc" (without quotes), then press Enter. A window titled "Trusted Platform Module Management" will open. If it says "Compatible TPM cannot be found" or shows no TPM version, your computer does not have the chip and you cannot enable it. If it shows "TPM 2.0" or "TPM 1.2" with a status, your chip is present — it may just be disabled.

On a Mac, TPM is built in and always on; you do not need to enable it. If you are using a Mac, you can stop here.

Restart your computer and enter the BIOS or UEFI settings

TPM lives in your computer's firmware, not in Windows. You reach it by restarting and pressing a specific key during startup — before Windows loads. The key varies by manufacturer: Dell and Lenovo usually use F2, HP and Asus use F10, and some others use Delete or F12. If you are not sure, restart your computer and watch the first screen carefully; it usually says "Press [key] to enter Setup" or "Press [key] for BIOS."

Shut down your computer completely. Turn it back on and immediately start pressing your BIOS key repeatedly (about once per second) until a blue or gray menu appears. Do not wait for Windows to load. If Windows starts, shut down again and try once more, pressing the key faster.

Once you are in the BIOS or UEFI menu, you will see text options or a graphical interface. Look for a section called "Security," "Integrated Peripherals," "Onboard Devices," or "Advanced." The exact name depends on your manufacturer.

Find and enable the TPM setting

Inside the Security or Advanced section, look for an option labeled "TPM," "Trusted Platform Module," "Security Chip," "PTT" (Platform Trust Technology — Intel's version), or "fTPM" (AMD's version). Some manufacturers hide it under "Onboard Devices" instead.

Highlight that option and press Enter. You will see a choice between "Enabled" and "Disabled" (or sometimes "On" and "Off"). Select "Enabled" or "On," then press Enter to confirm.

If you cannot find TPM under any of these names after checking Security, Advanced, and Onboard Devices, your computer may not have the chip. You can also check your computer's manual or the manufacturer's website by searching for your model number plus "TPM" to confirm whether it is installed.

Save your changes and restart

After enabling TPM, you must save and exit the BIOS. Look for an option that says "Save and Exit," "Exit and Save Changes," or "Save Changes and Reset." Press Enter on that option. Your computer will restart automatically.

Let Windows load completely. Do not interrupt the restart or turn off the computer during this process — TPM initialization can take a few minutes on first boot.

Once Windows is fully loaded, you can verify that TPM is now on by opening tpm.msc again (Windows key, type "tpm.msc," press Enter). The status should now show "Ready" instead of "Not Ready," and you should see your TPM version listed.

What to do if TPM does not appear in your BIOS

If you have looked through Security, Advanced, and Onboard Devices sections and found no TPM option, your computer likely does not have the chip installed. This is common on older machines, budget laptops, and some business computers.

You can confirm by checking your computer's specifications on the manufacturer's website. Search for your exact model number (usually on a sticker on the bottom or back of your machine) plus "TPM" or "specifications." If the spec sheet does not list TPM 2.0, the chip is not there.

If you need TPM for Windows 11 or for work security requirements, you may need to upgrade to a newer computer. Some external TPM devices exist, but they are rare, expensive, and not compatible with most consumer machines.

Common problems and what they mean

If you see "TPM is not ready" in tpm.msc after enabling it in BIOS, restart your computer again. TPM can take several minutes to initialize on first boot. If it still shows "Not Ready" after a second restart, the chip may be faulty or not fully recognized by Windows.

If Windows Update or a program tells you TPM is required but you have enabled it and it still shows as not ready, try updating your BIOS. Visit your computer manufacturer's support website, find your model, and download the latest BIOS update. Follow their instructions carefully — a BIOS update gone wrong can make your computer unbootable. If you are not comfortable doing this, contact the manufacturer's support line.

If you enabled TPM and now your computer will not start, restart and go back into the BIOS to disable it. This is rare, but it can happen if your system has a conflict. You can then contact your manufacturer's support to troubleshoot further.

Frequently Asked Questions

Will enabling TPM slow down my computer?

No. TPM runs on its own dedicated chip and does not use your main processor or memory. You will not notice any change in speed or performance after enabling it.

Can I disable TPM after I turn it on?

Yes. Go back into your BIOS using the same steps, find the TPM setting, and select "Disabled." Save and exit. However, if you have set up BitLocker encryption or other security features that rely on TPM, disabling it may cause problems with those features.

What is the difference between TPM 1.2 and TPM 2.0?

TPM 2.0 is newer and more secure. Windows 11 requires TPM 2.0. If your computer shows TPM 1.2, it is older and may not meet current security standards, though it can still be used with Windows 10.

Do I need to do anything after enabling TPM?

No. Once TPM is on and showing "Ready" in tpm.msc, it works automatically in the background. You do not need to configure it or check on it unless a program or update specifically asks you to.

My computer is asking for a TPM password — what should I do?

Some business computers set a TPM password during setup. If you do not know it, contact your IT department or your computer's administrator. Without the password, you cannot change TPM settings.