How to Enable TPM in Windows 11 and Windows 10

To enable TPM on a supported PC, first check its status with tpm.msc. If it is disabled, enable the existing TPM in your computer’s firmware settings, save the change, and verify the result in Windows. Windows 11 requires TPM 2.0; a firmware switch cannot add missing hardware or guarantee that an older TPM can be upgraded.

The steps below cover a physical PC running Windows 11 or Windows 10, including a Windows 10 PC being checked for a Windows 11 upgrade. Firmware menus differ by model. Use the computer or motherboard maker’s instructions for the actual switch.

Check Whether TPM Is Already Enabled

  1. Press Windows + R, type tpm.msc, and select OK.
  2. Read the status. If the TPM is ready for use, look under TPM Manufacturer Information for Specification Version.
  3. For Windows 11, verify that the version is 2.0. If it is ready and already 2.0, you do not need to enable it again.
Steps to check whether TPM is enabled: open the TPM console, read the status, check Specification Version
Illustration: how to check whether TPM is enabled.

A message saying a compatible TPM cannot be found can mean it is disabled; it does not alone prove that the computer lacks one. Microsoft’s TPM enabling guide explains these checks and common firmware labels.

Prepare Before Changing Firmware

Have a usable recovery method for encrypted data before changing TPM settings. Microsoft’s TPM troubleshooting documentation warns that switching between TPM implementations can trigger BitLocker recovery, and clearing a TPM can lose keys and access to protected data. Enabling an existing TPM is different from clearing it. Do not choose Clear TPM, reset its keys, or switch between firmware and discrete TPM as part of this basic guide.

If BitLocker or Device Encryption protects your drive, locate the recovery key before restarting. Microsoft’s recovery-key guide covers Microsoft accounts, work or school accounts, printouts, and saved USB copies. A recovery key is a 48-digit number; a key ID helps identify the right one. Store it where you can retrieve it if this PC cannot open Windows.

Save your work and back up important files. For an organization-managed computer, ask IT to handle the change. If the firmware demands an administrator password you do not know, stop and contact its owner or administrator.

Open the Firmware Settings

  1. On Windows 11, open Settings > System > Recovery. Under Advanced startup, select Restart now. Microsoft’s firmware-access instructions document this route.
  2. On Windows 10, use Settings > Update & Security > Recovery, then Restart now under Advanced startup.
  3. After the restart, choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Expect the manufacturer’s setup screen instead of the Windows desktop.

If UEFI Firmware Settings is absent, check the manufacturer’s startup-key instructions. For example, Dell’s TPM guide uses F2 at the Dell logo. That key is a Dell example, not a universal shortcut. Do not change Legacy/CSM boot mode, storage settings, or partition layout just to make this menu appear.

Enable the Existing TPM and Verify It

  1. Locate the model’s TPM control. Menus may use Security, Advanced, or Trusted Computing. Labels can include Security Device Support, TPM State, Intel PTT, or AMD fTPM.
  2. Follow the maker’s instructions to turn that existing TPM control on. Record its previous setting. Read any warning carefully; if the action would clear keys or change TPM type, stop and get model-specific guidance.
  3. Use the firmware’s documented save-and-exit command. Allow the PC to restart, then sign in to Windows.
  4. Run tpm.msc again. Confirm that the TPM is ready for use and check its specification version. For Windows 11 compatibility, it must show 2.0.

Dell documents Intel PTT and AMD fTPM as firmware implementations, so a separate add-in chip is not always necessary. Its menus and available controls still depend on the model. Windows normally initializes an available TPM automatically; creating a TPM owner password is not a required step in this guide.

If the Check Still Fails

  • No TPM control: Check the exact model’s manual and support information. Buy no add-in module until the manufacturer confirms compatibility.
  • Version 1.2: That does not meet Windows 11’s TPM 2.0 requirement. For continued Windows 10 use, check the requirements of the particular security feature you need. A supported version upgrade is model-dependent; enabling TPM does not itself convert 1.2 to 2.0.
  • Enabled but not detected: Record the Windows message and firmware setting, then use manufacturer support. Do not clear TPM or install firmware from an unrelated model as a generic fix.
  • Windows 11 upgrade still blocked: TPM is only one requirement. Check the other compatibility results rather than repeating the firmware change. If the processor is what fails, read about your options when Windows 11 does not support your CPU.

For locating model and version information, see our BIOS and UEFI settings guides. Start with the Windows status check, change only the documented TPM control if necessary, and confirm the result afterward.

Join Our Free Newsletter

Featured guides and deals

You may opt out at any time.
Read our Privacy Policy