TPM 2.0 is a security feature used by Windows 11 for capabilities such as BitLocker and Windows Hello. Most Windows 11-capable PCs already have firmware TPM support, but it may be disabled in UEFI/BIOS.
- Before changing firmware settings, save important work and make sure any BitLocker/device-encryption recovery key is accessible.
- Press Windows+R, run
tpm.msc, and check whether Windows already reports a ready TPM and its specification version. - If TPM 2.0 is absent but the hardware supports it, enter the PC’s UEFI/BIOS using the manufacturer’s documented method.
- Find the TPM setting, which may be called Intel PTT, AMD fTPM, Security Device Support, or similar, and enable it.
- Save firmware changes, restart Windows, and check
tpm.mscagain.
Do not clear the TPM casually
Clearing a TPM removes keys stored/protected by it and can affect BitLocker, Windows Hello, certificates, and other security functions. Enabling TPM is not the same as clearing it.
BitLocker recovery
Firmware/security changes can trigger a BitLocker recovery prompt. Confirm the recovery key is available before making the change.
Hardware limitations
A very old PC may have TPM 1.2 or no supported TPM 2.0 implementation. Do not flash unofficial firmware or use bypass scripts simply to make unsupported hardware appear compliant.
Managed devices
On a work or school computer, firmware security settings belong under the organization’s management process. Coordinate with IT rather than changing TPM state yourself.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.