Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The “Trusted Platform Module has malfunctioned” message in Windows 11 is often a Microsoft 365 sign-in or activation problem, not proof that the TPM chip has failed. It can appear in Outlook, Word, Excel, PowerPoint, OneNote, Teams, and other Microsoft 365 apps, sometimes with error codes such as 80090016 or 80090030.

Start with cached credentials and account registration before clearing the TPM. Clearing it resets TPM-protected keys and can affect Windows Hello and BitLocker, so prepare the device first.

Before you clear the TPM

Do not clear the TPM as a first step. Before selecting Clear TPM:

  • Back up important files.
  • Make sure you can sign in to Windows with your account password, not only a Windows Hello PIN.
  • Find and save your BitLocker recovery key. A TPM reset can cause Windows to request it at startup.
  • Close Microsoft 365 apps and save any open work.

Clearing the TPM resets the security processor to its default state. The previous TPM key state cannot be restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
  • Compatible with TPM-M R2.0
  • Chipset: Infineon SLB9665
  • PIN DEFINE:14Pin
  • Interface:LPC
  • Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.

1. Remove stale Microsoft 365 credentials

This is a safe first fix when the error appears in Outlook, Teams, Word, Excel, or another Microsoft 365 app.

  1. Close all Microsoft 365 applications.
  2. Search for Credential Manager from Start and open it.
  3. Select Windows Credentials.
  4. Expand each credential whose name begins with MicrosoftOffice16.
  5. Select Remove for those credentials.
  6. Restart Windows.
  7. Open the affected Office application and sign in again.

This removes cached Office authentication information. It does not uninstall Office or delete your Microsoft account.

2. Disconnect and reconnect the work or school account

A stale Microsoft Entra, Microsoft 365, or workplace registration can prevent Office from obtaining a new authentication token.

  1. Open Settings.
  2. Go to Accounts > Access work or school.
  3. Select the work or school account used by Office.
  4. If it is not the account you use to sign in to Windows, select Disconnect.
  5. Confirm by selecting Yes.
  6. Restart the PC and test Office again.

Disconnecting removes that account’s sign-in information and data from the device; it does not delete the Microsoft Entra or Microsoft 365 account itself. To add it again, go to Settings > Accounts > Access work or school, select Connect, enter the account details, choose the account type, and select Add.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On an organization-managed PC, check with your administrator before disconnecting the account. The device may be subject to management or compliance policies.

3. Rebuild the Web Account Manager token cache

Windows uses Web Account Manager (WAM) components to provide sign-in tokens to Microsoft 365. Microsoft identifies antivirus, VPN, proxy, and firewall software as possible blockers of the Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy package.

If your organization’s policy allows it, temporarily test without third-party VPN or security software. Do not leave protection disabled permanently. Then clear the token-cache contents:

  1. Close Office and Teams.
  2. Open File Explorer.
  3. Paste this path into the address bar and press Enter: %LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts
  4. Select the files in that folder and delete them.
  5. Repeat with: %LOCALAPPDATA%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\TokenBroker\Accounts
  6. Restart Windows and run the Microsoft 365 sign-in troubleshooter in Get Help.

If Windows says a file such as settings.dat is in use, do not try to delete the entire BrokerPlugin package folder. Microsoft’s procedure targets the contents of the TokenBroker Accounts folders.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
ASRock TPM2-S TPM Module Motherboard (V2.0)
  • Nuvoton NPCT650
  • TCG PC Client Platform TPM Profile (PTP) Specification; Family 2.0 (Trusted Platform Module Library; Family 2.0)
  • TCG PC Client Specific TPM Interface Specification (TIS), Version 1.3 (TPM Main Specification; Family 1.2 Revision 116)
  • Low Standby Power Consumption

Re-register a missing WAM package

If the package is missing, open Windows PowerShell as administrator and run the command matching the account type.

For a work or school account:

if (-not (Get-AppxPackage Microsoft.AAD.BrokerPlugin)) { Add-AppxPackage -Register “$env:windir\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Appxmanifest.xml” -DisableDevelopmentMode -ForceApplicationShutdown } Get-AppxPackage Microsoft.AAD.BrokerPlugin

For a personal Microsoft account:

if (-not (Get-AppxPackage Microsoft.Windows.CloudExperienceHost)) { Add-AppxPackage -Register “$env:windir\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Appxmanifest.xml” -DisableDevelopmentMode -ForceApplicationShutdown } Get-AppxPackage Microsoft.Windows.CloudExperienceHost

4. Check Microsoft Entra registration

On a work-managed computer, the problem may be device registration rather than the physical TPM.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Search for cmd.exe.
  2. Right-click Command Prompt and select Run as administrator.
  3. Run dsregcmd /status.

In the Device State section, review AzureAdJoined, EnterpriseJoined, and DomainJoined. In User State, check WorkplaceJoined. Unexpected values can indicate a broken or incomplete registration. Microsoft also identifies Event ID 220 in User Device Registration logs and error 0x801c001d as possible hybrid-join or service-connection-point problems. These generally require administrator remediation, not a TPM replacement.

5. Reset Microsoft 365 activation

If Windows sign-in works but Office remains stuck in an activation loop, use Microsoft’s Microsoft 365 activation troubleshooter in Get Help. Run it on the same Windows device where Microsoft 365 is installed. If Windows asks, “This site is trying to open Get Help,” select Open.

Microsoft’s activation-reset procedure also covers Project and Visio for managed Microsoft 365 Apps for enterprise installations. The correct cleanup method depends on whether the device is Microsoft Entra joined, hybrid joined, or only Workplace Joined. Managed devices may require Microsoft’s signoutofwamaccounts.ps1 script or administrator help.

Manual Office license cleanup

Use manual cleanup only when the normal troubleshooter does not resolve the activation state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
  • Compatible with:TPM2.0(MS-4462)
  • Chipset: INFINEON 9670 TPM 2.0
  • PIN DEFINE:12-1Pin
  • Interface:SPI
  • Supports:MSI Intel 400 Series and 500 Series Motherboards,MSI AMD B550 and A520 Series Motherboards,Windows 10 TPM 2.0

Microsoft 365 Apps for enterprise version 1909 or later stores vNext licenses under %localappdata%\Microsoft\Office\Licenses. Shared Computer Activation licenses use %localappdata%\Microsoft\Office\16.0\Licensing.

For legacy Office licenses, open an elevated Command Prompt and move to the directory matching your installation:

  • 64-bit Office on 64-bit Windows: cd “C:\Program Files\Microsoft Office\Office16”
  • 32-bit Office on 64-bit Windows: cd “C:\Program Files (x86)\Microsoft Office\Office16”

List installed licenses with cscript ospp.vbs /dstatus. Remove a specific license using the final five characters of its product key: cscript ospp.vbs /unpkey:<last 5 characters of product key>.

Microsoft’s manual procedure also includes these registry locations: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Licensing and HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Identity. Back up the registry before changing it. An incorrect registry edit can cause additional Windows or Office problems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Update BIOS and firmware

TPM firmware and UEFI problems can produce genuine security-processor errors and can also break Microsoft 365 authentication after a BIOS update or motherboard replacement.

  1. Open Windows Security.
  2. Select Device security.
  3. Under Security processor, select Security processor troubleshooting.
  4. Read the reported condition and follow any recommended action.

Messages such as “A firmware update is needed for your security processor,” “TPM is disabled and requires attention,” or “Your TPM isn’t compatible with your firmware” point toward firmware or UEFI investigation.

Install BIOS and firmware updates only from the PC or motherboard manufacturer. Surface owners should use Microsoft’s Surface drivers-and-firmware process. Keep the device connected to power and prepare BitLocker according to the manufacturer’s instructions.

7. Clear the TPM only after preparing the device

Consider this step when Windows Security specifically reports a TPM storage, health, or compatibility problem, or when earlier credential and activation fixes have failed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS
  1. Back up your files, confirm that you have the BitLocker recovery key, and make sure you know the Windows account password.
  2. Open Windows Security.
  3. Select Device security.
  4. Under Security processor, select Security processor troubleshooting.
  5. Select Clear TPM and follow the restart prompts.

After the restart, Windows Hello may no longer accept the old PIN. Sign in with the account password and create a new PIN if prompted. BitLocker may also request its recovery key.

If Security processor is missing from Device security, Windows may not detect a TPM or the TPM may be disabled in UEFI. Check the manufacturer’s documentation for settings such as TPM, Intel PTT, or AMD fTPM. Do not change UEFI security settings blindly on a managed or encrypted computer.

8. Check Memory integrity and incompatible drivers

A problematic low-level driver can interfere with Windows security features and authentication.

  1. Open Windows Security.
  2. Go to Device security > Core isolation details.
  3. Turn on Memory integrity and restart.

If Windows identifies an incompatible driver, obtain an updated version from the hardware manufacturer or remove the device or application that installed it. Memory integrity also requires hardware virtualization to be enabled in UEFI or BIOS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Test with a new Windows profile

If the error affects only one Windows profile, the profile’s WAM or Office identity data may be damaged.

  1. Open Settings > Accounts > Other users.
  2. Select Add account.
  3. For a local test account, select I don’t have this person’s sign-in information.
  4. Select Add a user without a Microsoft account.
  5. Create the account, then select it under Other users and choose Change account type > Administrator.
  6. Sign in to the new profile, install or open Office, and test activation.

If Office works in the new profile, the TPM is less likely to be the cause. Move to the new profile or have an administrator repair the original profile. A clean boot can also help identify a third-party service blocking authentication.

Fixes to avoid

Suggested online fix Why to avoid it
Set EnableADAL=0 in the Office registry This is an old community workaround, not a current Microsoft-recommended fix.
Disable BitLocker BitLocker is not a general cause or cure for this Office error. Disabling it reduces protection and may not change the authentication problem.
Uninstall the TPM in Device Manager The current Windows 11 procedure uses Windows Security’s security-processor troubleshooting page instead.
Delete the entire BrokerPlugin package folder Files may be in use. Clear the contents of the documented TokenBroker Accounts subfolder instead.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to contact IT or the manufacturer

Contact your organization’s administrator if dsregcmd /status shows an unexpected join state, Event ID 220 appears repeatedly, or the PC is managed by Microsoft Intune or another device-management service. Contact the manufacturer if Windows Security reports incompatible TPM firmware, the TPM disappears from UEFI, or the problem began immediately after a BIOS or motherboard change.

For a standalone PC, provide support with the exact error code, affected application, whether BitLocker is enabled, the Windows Security TPM message, and whether the issue affects a new Windows profile.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Asus TPM-SPI Trusted Platform Module (TPM)
  • Product Color: Black
  • Width: 0.6"
  • Depth: 0.5"
  • Additional Information: Interface: SPI Features: TPM IC: Nuvoton NPCT750 TPM Version: TPM 2.0 Pin Dimension: 14-1pin System Requirements: Windows® 10, UEFI OS
  • Country of Origin: Vietnam

FAQ

Does this error mean my TPM is physically broken?

Not usually. Microsoft documents the message primarily as a Microsoft 365 activation or sign-in problem. Stale Office credentials, WAM data, Microsoft Entra registration, firmware, blocked authentication services, and a damaged Windows profile can all produce it.

Should I clear the TPM to fix error 80090016?

Not as the first step. Remove MicrosoftOffice16 credentials, reconnect the work or school account if appropriate, repair WAM or Office activation, and check firmware first. If you clear the TPM, back up data and obtain the BitLocker recovery key beforehand.

What happens after clearing the TPM?

TPM-protected keys and credentials are reset. Windows Hello may require your account password and a new PIN, and BitLocker may request its recovery key. The previous TPM key state cannot be restored.

Why is Security processor missing in Windows Security?

Windows may not detect TPM hardware, or TPM may be disabled in UEFI or BIOS. Check the manufacturer’s documentation for the correct TPM, Intel PTT, or AMD fTPM setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can disabling BitLocker fix the Trusted Platform Module error?

No. Disabling BitLocker is not a general fix and reduces device protection. The troubleshooting path focuses on credentials, WAM, device registration, firmware, TPM state, and Office activation.

The Bottom Line

For most Windows 11 Microsoft 365 cases, start by removing MicrosoftOffice16 credentials and repairing the work-account or WAM sign-in state. Check dsregcmd /status on managed devices and install the correct BIOS or firmware update when Windows reports a security-processor issue. Clear the TPM only after backing up data, confirming the BitLocker recovery key, and understanding that Windows Hello credentials may need to be recreated.

For more information, see Microsoft’s TPM malfunction troubleshooting guide and Windows Security Device security documentation.

Quick Recap

SaleBestseller No. 1
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
Compatible with TPM-M R2.0; Chipset: Infineon SLB9665; PIN DEFINE:14Pin; Interface:LPC
$19.99
SaleBestseller No. 2
ASRock TPM2-S TPM Module Motherboard (V2.0)
ASRock TPM2-S TPM Module Motherboard (V2.0)
Nuvoton NPCT650; Low Standby Power Consumption
$24.99
Bestseller No. 3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
Compatible with:TPM2.0(MS-4462); Chipset: INFINEON 9670 TPM 2.0; PIN DEFINE:12-1Pin; Interface:SPI
$24.99
SaleBestseller No. 4
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
TPM 2.0 module for Asus motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
$23.74
Bestseller No. 5
Asus TPM-SPI Trusted Platform Module (TPM)
Asus TPM-SPI Trusted Platform Module (TPM)
Product Color: Black; Width: 0.6"; Depth: 0.5"; Country of Origin: Vietnam
$33.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.