Turn TPM ON?


Tweakit

Member
Member
Local time
12:09 PM
Posts
20
OS
Windows 11 Pro, version 24H2 (OS Build 26100.4061)
I'm thinking I should probably turn TPM on if only to take full advantage of the enhanced security. My system should be fully capable but when I first built it, the default EUFI settings kept TPM off. I'm attaching some pictures showing the bios/eufi settings. I'm hoping someone can provide some coaching on how to change these settings to safely enable TPM. Thanks!
 
Windows Build/Version
24H2

Attachments

  • Pic 1.webp
    Pic 1.webp
    168 KB · Views: 2
  • Pic 2.webp
    Pic 2.webp
    144.6 KB · Views: 1

My Computer

System One

  • OS
    Windows 11 Pro, version 24H2 (OS Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS user built
    CPU
    i5-13500
    Motherboard
    ASUS Prime B760M-A AX D4
    Memory
    G.SKILL F4-3200C16D-16GVKB
    Graphics Card(s)
    on board
    Sound Card
    on board
    Monitor(s) Displays
    two monitors
    Screen Resolution
    1080p
    Hard Drives
    SSD for OS: Samsung 980 PRO 1TB, NVMe
    Case
    Antec Sonata II
    Antivirus
    OS Native
Hi

TPM 2.0 Device Found: Required for Windows 11 and modern security features.

Security Device Support: Enabled
This enables TPM functionality. Required for BitLocker and secure boot.

Active PCR Banks: SHA256
SHA256 is active, which is the current standard for secure hashing. Good configuration.

Available PCR Banks: SHA256
Only SHA256 is available, indicating legacy SHA1 is not enabled. This is good.

SHA256 PCR Bank: Enabled
Ensures proper functionality for secure boot chains, BitLocker, and attestation.

Pending Operation: None
No pending TPM reset or configuration change. This is a normal and stable state.

Platform Hierarchy: Enabled
This is required for managing TPM platform-specific authorizations. Leave enabled.

Storage Hierarchy: Enabled
Enables TPM to securely store keys and encrypt data. Required for most uses.

Endorsement Hierarchy: Enabled
Essential for device identity and endorsement key usage. Should remain enabled.

Physical Presence Spec Version: 1.3
Latest spec version; defines how user approval is handled during TPM changes. This should be good.

Disable Block SID: Disabled
This allows automatic domain join in some environments. Default and recommended unless your org policy requires otherwise. (SID stands for Security Identifier, used by Windows to identify users, groups, and machines.)
  • Disable Block SID: Disabled = Block SID is on, auto TPM SID-based ownership is blocked.
  • This is the default and secure setting — don't change it unless your IT/security policy requires you to.


All I can tell you about the Secure Boot (namely custom) is what it says at the bottom. Are you able to set OS Type to: Windows UEFI Mode?
And Set Secure Boot Mode to: Standard? Because this is what I found:
  • Secure Boot: Custom and not fully active is only really for unsigned Linux or manual key management
  • Risk: Reduced boot-time integrity checks

  • If you're using Windows or a Secure Boot-compatible Linux distro (e.g., Ubuntu, Fedora):
    1. Set OS Type to: Windows UEFI Mode
    2. Set Secure Boot Mode to: Standard
    3. Make sure Secure Boot State changes from "User" to "Enabled" or "Active"
    4. Save and exit BIOS
  • This will load the Microsoft keyset and enforce Secure Boot as designed — preventing rootkits or unauthorized UEFI bootloaders from running.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Thank you for this very complete and clear explanation! I did as you suggested in steps 1 and 2 of your reply. I attached a summary of those two changes made.
Screenshot 2025-07-10 091653_crp.webp
The apparent issue remaining is that Secure Boot State (your step 3 above) still remains as "User." It did not change to "Enabled" or "Active."
Can you advise on this?
I also attached a scrn shot of TPM Management after boot following the changes made although I'm not sure if this tells us anything.
after enable.webp
Let me know what you think and thanks!
 

My Computer

System One

  • OS
    Windows 11 Pro, version 24H2 (OS Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS user built
    CPU
    i5-13500
    Motherboard
    ASUS Prime B760M-A AX D4
    Memory
    G.SKILL F4-3200C16D-16GVKB
    Graphics Card(s)
    on board
    Sound Card
    on board
    Monitor(s) Displays
    two monitors
    Screen Resolution
    1080p
    Hard Drives
    SSD for OS: Samsung 980 PRO 1TB, NVMe
    Case
    Antec Sonata II
    Antivirus
    OS Native
Hi

I haven’t bought a new motherboard (for myself) since 2014
I actually had to spend a couple of hours googling the entries visible on your motherboard. For self interest also. Mainly because I’ve been interested in TPM2 lately although have not been able to buy a module for my motherboard that works and I’ve bought four already (I gave up)

There wasn’t a great deal of wiggle room to know what the options were in all of the drop down boxes. In hindsight I should have also probably looked at your MB manual but I had a hospital appointment.

I was more trying to explain the meaning of each entry (for myself also)
It’s after midnight here and to search entails coffee & cigarettes. But not at this time of night.

The apparent issue remaining is that Secure Boot State (your step 3 above) still remains as "User." It did not change to "Enabled" or "Active."

To be honest I am not sure that this is a deal breaker.
I’ll look into more when I get up 🙏
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Did you also enable PTT?
In setting go to Advanced > PCH-FW Configuration > PTT
Set it to enabled
 

My Computer

System One

  • OS
    Windows 11 Pro
Thanks for the help Sinto!

Did you also enable PTT?
In setting go to Advanced > PCH-FW Configuration > PTT
Set it to enabled
In my BIOS it wasn’t called PTT. I went to “PCH-FW Configuration” and was given the option to set the TPM Device Selection. This was already set to “Enable Firmware TPM.” I kept that setting. I think this is the preferred setting for Intel processors. I don’t have anything plugged into the TPM Header on the mobo.

I think I’m probably okay here but would like to get some confirmation especially since my bios was not set properly set for TPM when I upgraded to Windows 11 (see two pics in opening post).

Does the TPM Management Console below demonstrate that TPM is operational on my system or is there more to it?after enable.webp
 

My Computer

System One

  • OS
    Windows 11 Pro, version 24H2 (OS Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS user built
    CPU
    i5-13500
    Motherboard
    ASUS Prime B760M-A AX D4
    Memory
    G.SKILL F4-3200C16D-16GVKB
    Graphics Card(s)
    on board
    Sound Card
    on board
    Monitor(s) Displays
    two monitors
    Screen Resolution
    1080p
    Hard Drives
    SSD for OS: Samsung 980 PRO 1TB, NVMe
    Case
    Antec Sonata II
    Antivirus
    OS Native
Thanks for the help Sinto!
Hey no problem, I don’t want to ruin your confidence, but I’m still learning also. All good.


“The TPM is ready for use.” That should confirm that:

• The hardware TPM is detected and functioning
• The TPM is initialized and hasn’t encountered any errors
• It’s currently provisioned to support encryption, secure boot, credential storage, and other trusted computing functions
• Specification Version: 2.0 (the latest for full Windows 11 support)

• Options available: Ability to clear the TPM and reset ownership, which only appears when the TPM is truly active
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Do you plan on encrypting your OS or drives?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
HI @Tweakit

I assume the motherboard you refer to is the one listed in your system details in your profile at this forum?

You may find in helpful to download and refer to the bios manual for your motherboard linked below. My motherboard a ProArt Z790 and is covered by the same bios manual as yours. The manual is available for download in multiple languages.


Re Secure Boot settings, here for example is a snippet from the said manual that explains what the Custon setting is. With my Asus board I use the Custom Secure Boot setting and have TPM enabled at the default settings, I've never tampered with these TPM settings.

asus uefi bios secure boot.webp
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 Beta Insider Channel
    Computer type
    PC/Desktop
    Manufacturer/Model
    Homebuilt
    CPU
    Intel Core i9 13900K
    Motherboard
    Asus ProArt Z790 Creator WiFi - Bios 2703
    Memory
    Corsair Dominator Platinum 64gb 5600MT/s DDR5 Dual Channel
    Graphics Card(s)
    Sapphire NITRO+ AMD Radeon RX 7900 XTX Vapor-X 24GB
    Sound Card
    External DAC - Headphone Amplifier: Cambridge Audio DACMagic200M
    Monitor(s) Displays
    Panasonic MX950 Mini LED 55" TV 120hz
    Screen Resolution
    3840 x 2160 120hz
    Hard Drives
    Samsung 980 Pro 2TB (OS)
    Samsung 980 Pro 1TB (Files)
    Lexar NZ790 4TB
    LaCie d2 Professional 6TB external - USB 3.1
    Seagate One Touch 18TB external HD - USB 3.0
    PSU
    Corsair RM1200x Shift
    Case
    Corsair RGB Smart Case 5000x (white)
    Cooling
    Corsair iCue H150i Elite Capellix XT
    Keyboard
    Logitech K860
    Mouse
    Logitech MX Master 3S
    Internet Speed
    Fibre 900/500 Mbps
    Browser
    Microsoft Edge Chromium
    Antivirus
    Bitdefender Total Security
    Other Info
    AMD Radeon Software & Drivers 25.5.1
    AOMEI Backupper Pro
    Dashlane password manager
    Logitech Brio 4K Webcam
    Orico 10-port powered USB 3.0 hub
  • Operating System
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Asus Vivobook X1605VA
    CPU
    Intel® Core™ i9-13900H
    Motherboard
    Asus X1605VA bios 309
    Memory
    32GB DDR4-3200 Dual channel
    Graphics card(s)
    *Intel Iris Xᵉ Graphics G7 (96EU) 32.0.101.6078
    Sound Card
    Realtek | Intel SST Bluetooth & USB
    Monitor(s) Displays
    16.0-inch, WUXGA 16:10 aspect ratio, IPS-level Panel
    Screen Resolution
    1920 x 1200 60hz
    Hard Drives
    512GB M.2 NVMe™ PCIe® 3.0 SSD
    Other Info
    720p Webcam
“The TPM is ready for use.” That should confirm that:
• The hardware TPM is detected and functioning
• The TPM is initialized and hasn’t encountered any errors
• It’s currently provisioned to support encryption, secure boot, credential storage, and other trusted computing functions
• Specification Version: 2.0 (the latest for full Windows 11 support)

• Options available: Ability to clear the TPM and reset ownership, which only appears when the TPM is truly active
Perfect. This is what I wanted to know.
Do you plan on encrypting your OS or drives?
No plans for that but my plans have been known to change!! I was interested in turning TPM on just to keep life a little safer. Not sure why the default setting didn't have it enabled to begin with.
I assume the motherboard you refer to is the one listed in your system details in your profile at this forum?

You may find in helpful to download and refer to the bios manual for your motherboard linked below. My motherboard a ProArt Z790 and is covered by the same bios manual as yours. The manual is available for download in multiple languages.


Re Secure Boot settings, here for example is a snippet from the said manual that explains what the Custon setting is. With my Asus board I use the Custom Secure Boot setting and have TPM enabled at the default settings, I've never tampered with these TPM settings.
Yes, that is my mobo! Turns out a little earlier today I found my way to the Asus site and downloaded it. You are very correct that it is both helpful and relevant. Thanks for suggesting that.
 

My Computer

System One

  • OS
    Windows 11 Pro, version 24H2 (OS Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS user built
    CPU
    i5-13500
    Motherboard
    ASUS Prime B760M-A AX D4
    Memory
    G.SKILL F4-3200C16D-16GVKB
    Graphics Card(s)
    on board
    Sound Card
    on board
    Monitor(s) Displays
    two monitors
    Screen Resolution
    1080p
    Hard Drives
    SSD for OS: Samsung 980 PRO 1TB, NVMe
    Case
    Antec Sonata II
    Antivirus
    OS Native

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
I ran a test and learned from it today. Thought I'd mention it in case others watching this thread might be interested. As you may be able to see from the conversation so far, the only Bios settings I changed from the default settings are seen below.
Screenshot 2025-07-10 091653_crp.webp
These settings are found in the bios under Advanced tab, Boot Menu, Secure Boot heading.
As it turns out, TPM was ON, both before and after the above changes were made. I didn’t realize it at the time because I didn’t know how to determine if TPM was on or not (run TPM.msc). What the above changes accomplished was to turn on "Secure Boot" (run msinfo32 and look for Secure Boot State). It went from OFF to ON with the above change. TPM and Secure Boot are different security features in Windows. I’m not sure why the Asus default bios settings keep Secure Boot off. If anyone knows, I'm curious what the logic is on that. After all, the mobo is modern and pretty much made for windows 11.
Thanks for the help!
 

My Computer

System One

  • OS
    Windows 11 Pro, version 24H2 (OS Build 26100.4061)
    Computer type
    PC/Desktop
    Manufacturer/Model
    ASUS user built
    CPU
    i5-13500
    Motherboard
    ASUS Prime B760M-A AX D4
    Memory
    G.SKILL F4-3200C16D-16GVKB
    Graphics Card(s)
    on board
    Sound Card
    on board
    Monitor(s) Displays
    two monitors
    Screen Resolution
    1080p
    Hard Drives
    SSD for OS: Samsung 980 PRO 1TB, NVMe
    Case
    Antec Sonata II
    Antivirus
    OS Native

Latest Support Threads

Back
Top Bottom