Updated: October 2026
The Windows 11 upgrade fails, and the readiness check blames a chip the PC probably has. The TPM is often there, just switched off in firmware or set to a mode Windows can't see. Here's how to enable TPM 2.0, check it first so you only touch the machines that need it, and roll it out across a fleet without tripping BitLocker.
Check Before You Touch the Firmware
Start in Windows. Three checks answer whether the TPM is there, whether it's on, and which version it is.
The quick one is tpm.msc. Press Win+R, type it, and read the status panel. "The TPM is ready for use" and a Specification Version of 2.0 means you're done. "Compatible TPM cannot be found" means firmware work.
Windows Security shows the same thing in plainer words. Open Device security and look for a Security processor section. No section usually means no TPM that Windows can reach.
For scripts, use PowerShell as administrator:
powershellGet-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated Get-CimInstance -Namespace root\cimv2\security\microsofttpm -ClassName Win32_Tpm | Select-Object SpecVersion, ManufacturerVersion
Get-Tpm tells you whether the TPM is present, enabled and ready. It doesn't show the version, so the second line reads SpecVersion from the Win32_Tpm class. A value starting with 2.0 is what Windows 11 wants. A value starting with 1.2 is older hardware, and no firmware toggle turns it into 2.0.
If Windows sees nothing and firmware looks right, that's a different problem. Our guide to TPM device not detected covers that path, including when to clear the TPM.
What the Setting Is Called
TPM 2.0 comes in three forms, and the firmware menu names each one differently.
A firmware TPM runs inside the processor. Intel calls it Platform Trust Technology (PTT). AMD calls it fTPM. A discrete TPM is a separate chip on the board. Some newer AMD and Qualcomm laptops add a third option, Microsoft Pluton, built into the processor. For Windows, all three count as TPM 2.0 once they're on.
Microsoft's own list of menu labels covers the common ones: Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT and Intel Platform Trust Technology. The setting usually sits under Advanced, Security or Trusted Computing.
One desktop trap is easy to miss. The board offers a choice between Discrete TPM and Firmware TPM, the default is Discrete, and no discrete chip is fitted. Windows then finds nothing. Switching to Firmware TPM fixes it, as this thread shows:
How to Enable TPM 2.0 in BIOS, Vendor by Vendor
The steps are the same everywhere. Restart, enter firmware setup, switch the TPM on, save and exit (usually F10), and boot. Only the menu path changes.
| Vendor | Setup key | Where the TPM setting lives |
|---|---|---|
| Dell | F2 | Security, then Intel Platform Trust Technology, Trusted Platform Module, TPM 2.0 Security or Firmware TPM set to On |
| HP (business) | F10 | Security, then TPM Embedded Security, with TPM Device set to Available |
| Lenovo ThinkPad | F1 | Security, then Security Chip, set to On |
| Lenovo IdeaPad | F2 or Fn+F2 | Security or Advanced tab, TPM option |
| ASUS boards | Delete | Advanced, then PCH-FW Configuration, PTT on Intel; Advanced, then AMD fTPM, TPM Device Selection set to Firmware TPM on AMD |
| MSI | Delete | Security, then Trusted Computing, Security Device Support set to Enabled |
Menu layouts shift between models and firmware versions. Dell and Lenovo both say so in their own guides. If the label isn't where the table says, check the model's manual before you start guessing.
Before You Toggle It, Protect BitLocker
Turning the TPM on for the first time is safe. Changing it on a machine that already uses BitLocker is not.
Microsoft lists "turning off, disabling, deactivating, or clearing the TPM" and "hiding the TPM from the operating system" among the events that force BitLocker recovery. A firmware update can do it too. Switching between discrete TPM and firmware TPM counts, because the keys live in the old one.
So suspend BitLocker first, make the change, then check it resumed:
powershellSuspend-BitLocker -MountPoint "C:" -RebootCount 1
A RebootCount of 1 resumes protection after the next restart. Use 0 only if you plan to run Resume-BitLocker yourself. Either way, confirm the recovery key is escrowed in Entra ID or Active Directory before you start.
Two vendor-specific traps are worth knowing. Lenovo's own documentation warns that switching a laptop from a discrete TPM to Pluton breaks its Autopilot registration, and the device has to be registered again. And after a firmware update, some AMD boards ask whether to reset the fTPM. Pressing Y on a BitLocker machine without the key means a PC that won't boot:
TPM 2.0 and Windows 11 Readiness
Microsoft's Windows 11 specifications list "Trusted Platform Module (TPM) version 2.0" alongside UEFI with Secure Boot capability. In December 2024, Microsoft's Windows IT Pro blog called TPM 2.0 "a non-negotiable standard for the future of Windows." Expect that line to hold.
Microsoft also says most PCs shipped in the last five years can run TPM 2.0. In practice, a failed TPM check on a recent business PC is often a settings problem, not missing hardware. A PC reporting TPM 1.2 is the exception, and that one needs replacing, not reconfiguring.
TPM is also only one of the checks. If the processor isn't on the supported list, enabling the TPM won't save the upgrade. Run PC Health Check or your own readiness script after the change and read every line, not just the TPM one.
This walkthrough shows the firmware side on a typical board, including Secure Boot, which usually travels with the TPM change:
Enabling TPM 2.0 Across a Fleet
Walking to fifty desks with a keyboard isn't a plan. Business PC makers ship tools that change firmware settings from Windows.
Start by finding which machines need it. Run the Get-Tpm and Win32_Tpm check above on every device and sort the results into three groups: ready, present but off, and 1.2 or missing. Only the middle group gets the firmware change.
Then use the vendor tool for each group:
- Dell: Dell Command | Configure changes BIOS settings from the command line or a package. Its TPM security and TPM activation options need the BIOS setup password.
- HP: the HP BIOS Configuration Utility or HP's PowerShell module, where
Set-HPBIOSSettingValuesets a named BIOS setting, with the setup password if one is set. - Lenovo: the WMI BIOS interface exposes a
SecurityChipsetting, and Lenovo's Think BIOS Config Tool wraps it.
Each change needs a restart, and some models ask for a key press at boot to confirm a TPM change. Test on one model per vendor before you push. Suspend BitLocker in the same package if any target is already encrypted. The same vendor tools handle other firmware switches, like the ones in our guide to enable virtualization in BIOS.
Close the loop by running the check again. OpenFrame can run it as a script across a client's devices and collect the output, so the "present but off" list shrinks to zero where you can see it.
The Short Version
Check before you change anything: tpm.msc or Get-Tpm for state, Win32_Tpm for the version. If it's off, enable it in firmware under Intel PTT, AMD fTPM or Security Chip, depending on the vendor. On machines that already use BitLocker, suspend it first and confirm the recovery key is escrowed. For more than a handful of PCs, inventory first and push the change with the vendor's BIOS tool.
If a machine still reports no TPM after all that, read our guide on TPM device not detected.
If a firmware update is part of the fix, our guide on how to update firmware covers doing it safely.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
