How to Enable TPM 2.0 Windows 11: A Step-by-Step Guide

TPM 2.0 is a security feature used by Windows 11 for capabilities such as BitLocker and Windows Hello. Most Windows 11-capable PCs already have firmware TPM support, but it may be disabled in UEFI/BIOS.

  1. Before changing firmware settings, save important work and make sure any BitLocker/device-encryption recovery key is accessible.
  2. Press Windows+R, run tpm.msc, and check whether Windows already reports a ready TPM and its specification version.
  3. If TPM 2.0 is absent but the hardware supports it, enter the PC’s UEFI/BIOS using the manufacturer’s documented method.
  4. Find the TPM setting, which may be called Intel PTT, AMD fTPM, Security Device Support, or similar, and enable it.
  5. Save firmware changes, restart Windows, and check tpm.msc again.

Do not clear the TPM casually

Clearing a TPM removes keys stored/protected by it and can affect BitLocker, Windows Hello, certificates, and other security functions. Enabling TPM is not the same as clearing it.

BitLocker recovery

Firmware/security changes can trigger a BitLocker recovery prompt. Confirm the recovery key is available before making the change.

Hardware limitations

A very old PC may have TPM 1.2 or no supported TPM 2.0 implementation. Do not flash unofficial firmware or use bypass scripts simply to make unsupported hardware appear compliant.

Managed devices

On a work or school computer, firmware security settings belong under the organization’s management process. Coordinate with IT rather than changing TPM state yourself.