iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You normally do not install TPM 2.0 in Windows 11. TPM 2.0 is a security component built into the motherboard firmware or provided by a compatible physical module. On many computers it is already present but disabled in UEFI firmware.
Intel systems often call it Intel Platform Trust Technology (PTT). AMD systems commonly use AMD fTPM, AMD PSP fTPM, or Firmware TPM. There is no Microsoft TPM 2.0 installer or driver that can turn TPM 1.2—or a computer without TPM support—into TPM 2.0.
Check whether TPM 2.0 is already enabled
Check Windows before changing firmware settings. You may already meet the TPM requirement.
Using TPM Management
- Press Windows key + R.
- Type
tpm.mscand press Enter. - Read the status shown in the TPM Management window.
| Message or value | Meaning |
|---|---|
| The TPM is ready for use | Check TPM Manufacturer Information > Specification Version. It must be 2.0. |
| Compatible TPM cannot be found | TPM may be disabled in UEFI, hidden by firmware, unsupported, or affected by a driver or firmware problem. |
| Specification Version: 1.2 | The computer does not satisfy Windows 11’s TPM requirement. A driver cannot upgrade TPM 1.2 to TPM 2.0. |
Using Windows Security
- Open Start > Settings.
- Go to Privacy & security > Windows Security > Device security.
- Under Security processor, select Security processor details.
- Check Specification version. The required value is 2.0.
If the Security processor section is missing, TPM may be disabled or unavailable.
#1 Best Overall
- Compatible with TPM-M R2.0
- Chipset: Infineon SLB9665
- PIN DEFINE:14Pin
- Interface:LPC
- Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.
Using PowerShell
Open PowerShell and run:
Get-Tpm
Look for information indicating that a TPM is present and ready. The tpm.msc console is useful for confirming the exact specification version.
Prepare before enabling TPM
Changing TPM, boot, or UEFI settings can make BitLocker ask for its recovery key. Before continuing:
- Back up important files.
- Find and save your 48-digit BitLocker recovery key if BitLocker or Device Encryption is enabled. You can check Microsoft account recovery keys, your organization’s account, a saved file, or a printed copy.
- Check the current boot mode by pressing Windows key + R, entering
msinfo32, and selecting OK. - In System Information, note BIOS Mode and Secure Boot State.
BIOS Mode should normally be UEFI. If it says Legacy, do not simply switch the firmware to UEFI. A Legacy installation commonly uses an MBR system disk, and changing the boot mode without converting it can leave Windows unable to start.
Enable TPM 2.0 in UEFI firmware
Windows can usually take you directly to the appropriate firmware screen:
- Open Start > Settings > System > Recovery.
- Beside Advanced startup, select Restart now.
- After the restart, choose Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
- In UEFI, open a section such as Advanced, Security, or Trusted Computing.
- Enable the TPM-related option.
- Save the changes and exit, commonly with F10.
Menu names vary by motherboard and computer manufacturer. Look for one of these labels:
| System type | Possible setting |
|---|---|
| Intel | Intel PTT, Intel Platform Trust Technology, or Security Device Support |
| AMD | AMD fTPM, AMD PSP fTPM, Firmware TPM, or AMD CPU fTPM |
| Physical module | TPM Device, Discrete TPM, or dTPM |
Set the option to Enabled or, where applicable, choose Firmware TPM instead of Discrete TPM. Use the manual for the exact computer or motherboard if you cannot find the setting.
Convert Legacy BIOS installations to UEFI when necessary
TPM 2.0 works properly with native UEFI. If msinfo32 reports Legacy BIOS, first confirm that the system disk can be converted safely. Windows includes MBR2GPT.exe, but you should still create a backup and have the BitLocker recovery key available.
1. Find the system disk number
Open an elevated Command Prompt and run:
diskpart
list disk
exit
Identify the disk containing the Windows installation. Do not guess if the computer has several drives.
2. Validate the disk
Replace 0 below with the correct disk number:
mbr2gpt /validate /disk:0 /allowFullOS
Proceed only if validation succeeds.
3. Convert the disk
mbr2gpt /convert /disk:0 /allowFullOS
Restart into UEFI firmware after the conversion. Disable Legacy Boot or CSM, select UEFI boot mode, and then enable Intel PTT, AMD fTPM, or the applicable TPM setting. Enable Secure Boot as well if the system is ready for it.
Rank #2
- Compatible with:TPM2.0(MS-4462)
- Chipset: INFINEON 9670 TPM 2.0
- PIN DEFINE:12-1Pin
- Interface:SPI
- Supports:MSI Intel 400 Series and 500 Series Motherboards,MSI AMD B550 and A520 Series Motherboards,Windows 10 TPM 2.0
Do not run these commands against an unverified disk. If validation fails, read the error and resolve the partition or disk-layout issue rather than forcing the conversion.
Verify TPM 2.0 after enabling it
- Allow Windows to start normally.
- Run
tpm.mscagain. - Confirm that the status says The TPM is ready for use.
- Confirm Specification Version: 2.0.
- Optionally run
Get-Tpmin PowerShell.
Windows normally initializes a supported TPM automatically. You do not generally need to create a TPM owner password, manually take ownership, or install a separate TPM driver. Windows should use its built-in Microsoft TPM driver; third-party TPM drivers can prevent Windows from detecting the device.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To check the rest of the Windows 11 requirements, open PC Health Check and select Check now in the Windows 11 eligibility section. Windows Update eligibility information can take up to 24 hours to refresh after a firmware or hardware change, while PC Health Check may show the result sooner.
What to do if there is no TPM option
If UEFI contains no TPM, PTT, fTPM, or Security Device setting:
- Check the computer or motherboard specifications.
- Install a firmware update supplied by the manufacturer, if one is available.
- Check whether the manufacturer supports an approved TPM 2.0 module for that exact model.
- Do not buy a generic module without confirming compatibility.
TPM headers differ in pin layout and firmware support. A module made for one motherboard may not work in another, and some laptops and prebuilt computers have no user-installable TPM option. If the system only has TPM 1.2 or no supported TPM implementation, it does not meet the Windows 11 TPM requirement.
Do not clear the TPM to enable it
Clear TPM is a reset operation, not an enablement option. Clearing it removes cryptographic keys and can affect BitLocker, Windows Hello PINs, certificates, and other security features.
Recommended Free Tools
Only clear the TPM after backing up relevant data and recovery information, and only when troubleshooting or following a documented manufacturer or Microsoft procedure. If you genuinely need the option, it is located at Windows Security > Device security > Security processor details > Security processor troubleshooting > Clear TPM.
Common problems
“Compatible TPM cannot be found”
Confirm that Intel PTT or AMD fTPM is enabled in UEFI. Also check whether the system is using Legacy/CSM mode, install the manufacturer’s current firmware, and verify that Windows is using the Microsoft TPM driver. If no firmware option exists, the computer may not support TPM 2.0.
TPM is ready, but shows reduced functionality
This can occur when TPM 2.0 is enabled while Windows is still booting in Legacy BIOS mode. Check msinfo32; convert the system disk if appropriate, then boot in native UEFI mode.
Rank #3
- TPM 2.0 module for Asus motherboard.
- TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
- LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
- Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
- Packing list:1x TPM 2.0 Module for ASUS
BitLocker requests a recovery key
This is a normal protection response to changes in the TPM, firmware, or boot measurements. Enter the recovery key. Do not clear the TPM as a first response.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Update still rejects the upgrade
Use PC Health Check to identify the failing requirement. TPM 2.0 alone is not enough: the processor, memory, storage, UEFI capability, and other Windows 11 requirements must also be satisfied.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.FAQ
Can I download and install TPM 2.0 for Windows 11?
No. TPM 2.0 is a hardware- or firmware-based security component, not a downloadable Windows program. Enable the existing Intel PTT, AMD fTPM, or compatible TPM module in UEFI.
Is Intel PTT the same as TPM 2.0?
Intel PTT is Intel’s firmware-based TPM implementation. When supported and enabled, Windows can use it as a TPM 2.0 device.
Is AMD fTPM the same as TPM 2.0?
AMD fTPM is a firmware-based TPM implementation. On supported systems, enabling AMD fTPM provides the TPM 2.0 functionality Windows 11 requires.
Can a TPM 1.2 driver update it to TPM 2.0?
No. A driver cannot change TPM 1.2 into TPM 2.0. A manufacturer-specific firmware update or compatible hardware replacement may be possible on some systems.
Do I need to clear TPM before enabling it?
No. Clearing TPM resets the device and can invalidate keys used by BitLocker and Windows Hello. It is not the normal way to enable TPM.
Does Secure Boot have to be enabled for Windows 11?
The PC must support UEFI and be Secure Boot capable. Enabling Secure Boot is recommended, but the TPM setting itself is separate.
The Bottom Line
To “install” TPM 2.0 for Windows 11, first check tpm.msc. If TPM is missing, enter UEFI and enable Intel PTT, AMD fTPM, or the manufacturer’s TPM option. Make sure Windows uses UEFI rather than Legacy/CSM, verify the result after restarting, and keep your BitLocker recovery key available. If the computer has no compatible TPM implementation, a Windows driver or utility cannot add one.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

