What Is TPM 2.0, and Why Does Windows 11 Require It?
The security chip behind Windows 11's most controversial requirement, what it does, how to check if you have it, and how to turn it on.
The requirement that blocked millions of PCs
When Windows 11 launched, one requirement caused more confusion and frustration than any other: TPM 2.0. Plenty of otherwise-capable PCs were told they could not upgrade. Per Microsoft's official system requirements, Windows 11 needs a 1GHz+ dual-core 64-bit CPU, 4GB RAM, 64GB storage, DirectX 12 / WDDM 2.0 graphics, UEFI with Secure Boot, and, the sticking point, Trusted Platform Module (TPM) version 2.0.
What a TPM actually is
A Trusted Platform Module is a small, dedicated security chip (or a firmware equivalent built into modern CPUs) that safely stores cryptographic keys, passwords, and certificates in tamper-resistant hardware. Think of it as a locked vault on your motherboard: secrets stored there cannot easily be extracted even by malware running on the main OS. It handles operations like generating and sealing encryption keys so they never sit exposed in regular memory or on disk.
Why Windows 11 requires it
Microsoft's reasoning is security by default. TPM 2.0 underpins several protections: BitLocker drive encryption (keys sealed to your hardware), Windows Hello (secure biometric/PIN credentials), Secure Boot and measured boot (detecting tampering before the OS loads), and defenses against firmware and credential-theft attacks. By making TPM 2.0 a baseline, Microsoft can assume every Windows 11 PC has a hardware root of trust, raising the security floor for the whole ecosystem rather than leaving these features optional and unused.
How to check if your PC has TPM 2.0
It is quick to check. Press Windows + R, type tpm.msc and press Enter. The Trusted Platform Module Management window shows whether a TPM is present and, under 'Specification Version,' whether it is 2.0. Alternatively, run the PC Health Check app or look in Settings > Privacy & security > Windows Security > Device Security. Many PCs from roughly 2016 onward have TPM 2.0, it may just be switched off in firmware.
How to enable it in BIOS/UEFI
If tpm.msc says no TPM is found, it is often disabled rather than absent. Restart into your UEFI/BIOS (usually by pressing Del, F2, F10, or F12 at boot, or via Settings > System > Recovery > Advanced startup > UEFI Firmware Settings). Look for a setting named TPM, Security Device, PTT (Intel Platform Trust Technology), or fTPM (AMD firmware TPM), and enable it. Save and exit, then re-check with tpm.msc. On most modern CPUs the firmware TPM (PTT/fTPM) satisfies the Windows 11 requirement with no physical chip needed.
What if your PC genuinely can't meet it?
Some older machines truly lack any TPM 2.0 option. Officially, those PCs are not supported for Windows 11, and while unofficial bypasses exist, Microsoft warns such installs may not receive updates and are not recommended. The more sustainable options are staying on a supported OS, upgrading the hardware, or considering a lightweight Linux distribution to keep an older machine useful and secure. For most people from the last several years, though, TPM 2.0 is present, just a BIOS toggle away.
Related on Skillo
See also: How to safely debloat Windows 11, What are passkeys and how do they work?.
Sources
Published date reflects the original event date (2026-09-02). This article is original Skillo editorial written from the sources above; facts were verified in September 2026.
Written by
Skillo Staff
0 Comments
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.