Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

The Windows 11 upgrade fails, and the readiness check blames a chip the PC probably has. The TPM is often there, just switched off in firmware or set to a mode Windows can't see. Here's how to enable TPM 2.0, check it first so you only touch the machines that need it, and roll it out across a fleet without tripping BitLocker.

Check Before You Touch the Firmware

Start in Windows. Three checks answer whether the TPM is there, whether it's on, and which version it is.

The quick one is tpm.msc. Press Win+R, type it, and read the status panel. "The TPM is ready for use" and a Specification Version of 2.0 means you're done. "Compatible TPM cannot be found" means firmware work.

Windows Security shows the same thing in plainer words. Open Device security and look for a Security processor section. No section usually means no TPM that Windows can reach.

For scripts, use PowerShell as administrator:

powershell
Get-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated
Get-CimInstance -Namespace root\cimv2\security\microsofttpm -ClassName Win32_Tpm |
  Select-Object SpecVersion, ManufacturerVersion

Get-Tpm tells you whether the TPM is present, enabled and ready. It doesn't show the version, so the second line reads SpecVersion from the Win32_Tpm class. A value starting with 2.0 is what Windows 11 wants. A value starting with 1.2 is older hardware, and no firmware toggle turns it into 2.0.

If Windows sees nothing and firmware looks right, that's a different problem. Our guide to TPM device not detected covers that path, including when to clear the TPM.

What the Setting Is Called

TPM 2.0 comes in three forms, and the firmware menu names each one differently.

A firmware TPM runs inside the processor. Intel calls it Platform Trust Technology (PTT). AMD calls it fTPM. A discrete TPM is a separate chip on the board. Some newer AMD and Qualcomm laptops add a third option, Microsoft Pluton, built into the processor. For Windows, all three count as TPM 2.0 once they're on.

Microsoft's own list of menu labels covers the common ones: Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT and Intel Platform Trust Technology. The setting usually sits under Advanced, Security or Trusted Computing.

One desktop trap is easy to miss. The board offers a choice between Discrete TPM and Firmware TPM, the default is Discrete, and no discrete chip is fitted. Windows then finds nothing. Switching to Firmware TPM fixes it, as this thread shows:

How to Enable TPM 2.0 in BIOS, Vendor by Vendor

The steps are the same everywhere. Restart, enter firmware setup, switch the TPM on, save and exit (usually F10), and boot. Only the menu path changes.

VendorSetup keyWhere the TPM setting lives
DellF2Security, then Intel Platform Trust Technology, Trusted Platform Module, TPM 2.0 Security or Firmware TPM set to On
HP (business)F10Security, then TPM Embedded Security, with TPM Device set to Available
Lenovo ThinkPadF1Security, then Security Chip, set to On
Lenovo IdeaPadF2 or Fn+F2Security or Advanced tab, TPM option
ASUS boardsDeleteAdvanced, then PCH-FW Configuration, PTT on Intel; Advanced, then AMD fTPM, TPM Device Selection set to Firmware TPM on AMD
MSIDeleteSecurity, then Trusted Computing, Security Device Support set to Enabled

Menu layouts shift between models and firmware versions. Dell and Lenovo both say so in their own guides. If the label isn't where the table says, check the model's manual before you start guessing.

Before You Toggle It, Protect BitLocker

Turning the TPM on for the first time is safe. Changing it on a machine that already uses BitLocker is not.

Microsoft lists "turning off, disabling, deactivating, or clearing the TPM" and "hiding the TPM from the operating system" among the events that force BitLocker recovery. A firmware update can do it too. Switching between discrete TPM and firmware TPM counts, because the keys live in the old one.

So suspend BitLocker first, make the change, then check it resumed:

powershell
Suspend-BitLocker -MountPoint "C:" -RebootCount 1

A RebootCount of 1 resumes protection after the next restart. Use 0 only if you plan to run Resume-BitLocker yourself. Either way, confirm the recovery key is escrowed in Entra ID or Active Directory before you start.

Two vendor-specific traps are worth knowing. Lenovo's own documentation warns that switching a laptop from a discrete TPM to Pluton breaks its Autopilot registration, and the device has to be registered again. And after a firmware update, some AMD boards ask whether to reset the fTPM. Pressing Y on a BitLocker machine without the key means a PC that won't boot:

TPM 2.0 and Windows 11 Readiness

Microsoft's Windows 11 specifications list "Trusted Platform Module (TPM) version 2.0" alongside UEFI with Secure Boot capability. In December 2024, Microsoft's Windows IT Pro blog called TPM 2.0 "a non-negotiable standard for the future of Windows." Expect that line to hold.

Microsoft also says most PCs shipped in the last five years can run TPM 2.0. In practice, a failed TPM check on a recent business PC is often a settings problem, not missing hardware. A PC reporting TPM 1.2 is the exception, and that one needs replacing, not reconfiguring.

TPM is also only one of the checks. If the processor isn't on the supported list, enabling the TPM won't save the upgrade. Run PC Health Check or your own readiness script after the change and read every line, not just the TPM one.

This walkthrough shows the firmware side on a typical board, including Secure Boot, which usually travels with the TPM change:

Enabling TPM 2.0 Across a Fleet

Walking to fifty desks with a keyboard isn't a plan. Business PC makers ship tools that change firmware settings from Windows.

Start by finding which machines need it. Run the Get-Tpm and Win32_Tpm check above on every device and sort the results into three groups: ready, present but off, and 1.2 or missing. Only the middle group gets the firmware change.

Then use the vendor tool for each group:

  • Dell: Dell Command | Configure changes BIOS settings from the command line or a package. Its TPM security and TPM activation options need the BIOS setup password.
  • HP: the HP BIOS Configuration Utility or HP's PowerShell module, where Set-HPBIOSSettingValue sets a named BIOS setting, with the setup password if one is set.
  • Lenovo: the WMI BIOS interface exposes a SecurityChip setting, and Lenovo's Think BIOS Config Tool wraps it.

Each change needs a restart, and some models ask for a key press at boot to confirm a TPM change. Test on one model per vendor before you push. Suspend BitLocker in the same package if any target is already encrypted. The same vendor tools handle other firmware switches, like the ones in our guide to enable virtualization in BIOS.

Close the loop by running the check again. OpenFrame can run it as a script across a client's devices and collect the output, so the "present but off" list shrinks to zero where you can see it.

The Short Version

Check before you change anything: tpm.msc or Get-Tpm for state, Win32_Tpm for the version. If it's off, enable it in firmware under Intel PTT, AMD fTPM or Security Chip, depending on the vendor. On machines that already use BitLocker, suspend it first and confirm the recovery key is escrowed. For more than a handful of PCs, inventory first and push the change with the vendor's BIOS tool.

If a machine still reports no TPM after all that, read our guide on TPM device not detected.

If a firmware update is part of the fix, our guide on how to update firmware covers doing it safely.

"Fae" Grace Meadows

"Fae" Grace Meadows

Lead AI Fairy

Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Enable TPM 2.0

Restart into firmware setup (F2 on Dell, F10 on HP business PCs, F1 on ThinkPads, Delete on most ASUS and MSI boards), find the TPM setting under Security, Advanced or Trusted Computing, and switch it on. It may be called Intel PTT, AMD fTPM, Security Chip, Security Device Support or TPM State. Save, boot, and check tpm.msc shows the TPM as ready.
Run tpm.msc and read the status and Specification Version, or open Windows Security and look for Security processor under Device security. In PowerShell, Get-Tpm shows whether the TPM is present, enabled and ready, and the Win32_Tpm class in root\cimv2\security\microsofttpm shows SpecVersion, which should start with 2.0.
Turning a TPM on for the first time on a PC without BitLocker is safe. On a BitLocker PC, disabling, clearing or hiding the TPM, switching between discrete and firmware TPM, or updating firmware can force recovery. Suspend BitLocker first with Suspend-BitLocker -MountPoint "C:" -RebootCount 1, and make sure the recovery key is escrowed.
Not with a firmware toggle. A PC that reports SpecVersion 1.2 has older TPM hardware and will not meet the Windows 11 requirement, which Microsoft lists as TPM version 2.0. That machine belongs on the replacement list.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.