What TPM 2.0 is and whether your computer needs it

TPM 2.0 (Trusted Platform Module 2.0) is a security chip that stores encryption keys and passwords so they cannot be stolen even if someone removes your hard drive. Most computers made after 2016 have TPM 2.0 built in as a physical chip on the motherboard. You do not install the chip itself — it is already there. What you do install is the driver software that lets Windows and other programs talk to the chip.

If you are reading this because Windows 11 told you that you need TPM 2.0, your computer almost certainly has the chip already. The problem is usually that the driver is missing or turned off in the BIOS (the firmware that runs before Windows starts). If you have an older computer from before 2015, it may not have TPM 2.0 at all, and you would need to add a separate module — but this is rare and requires opening your computer.

Before you start, check whether your computer actually has TPM 2.0. The fastest way is to open the Windows search box, type tpm.msc, and press Enter. If a window opens showing "TPM Manufacturer Information" and a version number of 2.0, you already have it working. If nothing opens or you see version 1.2, keep reading.

Key Takeaways

  • Most computers made after 2016 have TPM 2.0 built in as a physical chip, and you only need to enable the driver or turn it on in BIOS settings.
  • Check whether TPM 2.0 is already present by opening the search box, typing tpm.msc, and pressing Enter to see the TPM status window.
  • If TPM 2.0 is not showing up, restart your computer and enter the BIOS setup screen (usually by pressing Delete, F2, or F12 during startup) and look for a TPM or Security Chip setting to enable.
  • After enabling TPM 2.0 in BIOS, restart Windows and check tpm.msc again to confirm the driver is now working.
  • If your computer has no TPM 2.0 option in BIOS and was made before 2015, you may need to purchase and install a separate TPM module, which requires opening the computer case.

Check your BIOS to see if TPM 2.0 is disabled

The most common reason TPM 2.0 is not working is that it is turned off in the BIOS. The BIOS is the firmware that runs before Windows starts, and it controls which hardware features are active. To enter the BIOS, restart your computer and watch the screen carefully as it boots. During the first few seconds, you will see a message like "Press Delete to enter Setup" or "Press F2 for BIOS Settings." The key varies by manufacturer — common ones are Delete, F2, F10, and F12.

Once you are in the BIOS, look for a section called Security, Integrated Peripherals, or Advanced. The TPM setting might be labeled "TPM 2.0," "Security Chip," "PTT" (Platform Trust Technology, used by Intel), or "fTPM" (firmware TPM, used by AMD). The exact name and location depend on your motherboard manufacturer. If you cannot find it, look for a menu item that mentions "Trusted," "Security," or "Module."

When you find the TPM setting, make sure it is set to Enabled or On. Some BIOS versions also have a separate option to clear the TPM — leave that alone unless you are troubleshooting a specific problem. After you change the setting, look for a button or menu option to Save and Exit (usually F10). Your computer will restart.

Update your TPM driver through Windows Device Manager

After you enable TPM 2.0 in the BIOS and restart Windows, the driver should load automatically. However, sometimes Windows does not find the latest version. Open the search box, type Device Manager, and press Enter. Look for a section called "Security Devices" or "Trusted Platform Module." If you see an entry for TPM 2.0 with a green checkmark, the driver is working.

If you see a yellow warning triangle or a question mark next to the TPM entry, right-click on it and select "Update driver." Choose "Search automatically for updated driver software." Windows will connect to Windows Update and download the correct driver. This usually takes a few minutes. When it finishes, restart your computer.

If Device Manager shows no TPM entry at all, go back to the BIOS and double-check that TPM 2.0 is enabled. Some motherboards require you to save the BIOS change and restart twice before the TPM appears in Device Manager. If you have restarted twice and still see nothing, your computer may not have TPM 2.0 hardware.

Install TPM 2.0 as a separate module (older computers only)

If your computer was made before 2015 and has no TPM 2.0 option in the BIOS, the motherboard may not have a TPM chip at all. In this case, you can purchase a separate TPM 2.0 module and install it yourself. These modules cost between $20 and $50 and connect to a header on the motherboard — a small connector with pins that looks like a tiny grid.

Before you buy a module, check your motherboard manual to see whether it has a TPM header and which type it uses. The two common standards are TPM 2.0 on a 14-pin header and TPM 2.0 on a 20-pin header. Your motherboard manual will tell you which one yours has. You can usually find the manual by searching for your motherboard model number on the manufacturer's website (ASUS, Gigabyte, MSI, or ASRock).

Installing a TPM module requires opening your computer case and connecting the module to the header. If you are not comfortable doing this, a computer repair shop can do it for you, usually for $30 to $60 in labor. After the module is installed, restart your computer, enter the BIOS, and enable TPM 2.0 the same way you would if it were already on the motherboard.

Verify TPM 2.0 is working after installation

Once you have enabled TPM 2.0 in the BIOS (or installed a separate module and enabled it), restart your computer and check that Windows recognizes it. Open the search box, type tpm.msc, and press Enter. You should see a window titled "TPM Management Console" with information about your TPM. Look for the line that says "TPM Manufacturer Information" — it should show version 2.0.

If the window still does not open or shows version 1.2, restart your computer again. Sometimes Windows takes a few minutes to recognize a newly enabled TPM. If you have restarted twice and still see no TPM 2.0, go back to Device Manager and check whether there is a warning triangle next to the TPM entry. If there is, right-click it and select "Update driver" again.

You can also check TPM status in the Settings app. Open Settings, go to System, then About, and scroll down to look for "TPM version." If it shows 2.0, you are done. If Windows 11 was the reason you needed TPM 2.0 in the first place, you should now be able to install or update to Windows 11 without the TPM error.

Troubleshoot if TPM 2.0 still does not appear

If you have enabled TPM 2.0 in the BIOS, restarted your computer twice, and TPM 2.0 still does not show up in tpm.msc or Device Manager, try these steps in order. First, restart your computer and enter the BIOS again. Look for an option to "Clear TPM" or "Reset TPM" and select it. This erases any old data on the chip and forces Windows to re-initialize it. Save and exit the BIOS, then restart Windows and check tpm.msc again.

If that does not work, check whether your BIOS is up to date. Visit your motherboard manufacturer's website (ASUS, Gigabyte, MSI, or ASRock), find your motherboard model, and download the latest BIOS file. Updating the BIOS is more complex than updating a driver and carries a small risk if the power fails during the update, so only do this if you are comfortable with the process. Your motherboard manual will have instructions for BIOS updates.

If you have tried all these steps and TPM 2.0 still does not work, your motherboard may have a hardware problem or may not support TPM 2.0 at all. At this point, contact the computer manufacturer's support line or take the computer to a repair shop. They can run diagnostics to confirm whether the TPM chip is present and working.

Frequently Asked Questions

Do I need to buy TPM 2.0 or is it already in my computer?

If your computer was made after 2016, TPM 2.0 is almost certainly already built in as a physical chip on the motherboard. You do not need to buy anything. You only need to enable it in the BIOS or install the driver. If your computer is older than 2015, it may not have TPM 2.0, and you would need to buy a separate module for $20 to $50.

What does TPM 2.0 do, and why does Windows 11 require it?

TPM 2.0 stores encryption keys and passwords in a secure way that makes them much harder to steal. Windows 11 requires it because it improves security against malware and theft. If you do not plan to upgrade to Windows 11, you do not need TPM 2.0 for Windows 10.

Is it safe to enable TPM 2.0 in the BIOS?

Yes, enabling TPM 2.0 in the BIOS is safe and has no downside. It does not slow down your computer or cause problems with existing programs. The only reason to leave it disabled is if you have a very old program that does not work with TPM, which is extremely rare.

Can I install TPM 2.0 myself, or do I need a technician?

Enabling TPM 2.0 in the BIOS is something you can do yourself by following the steps in this guide. Installing a separate TPM module requires opening your computer case and connecting a small component to the motherboard. If you are not comfortable doing this, a repair shop can do it for $30 to $60.

What if my BIOS does not have a TPM 2.0 option?

If your BIOS has no TPM option at all, your motherboard does not have TPM 2.0 built in. Check your motherboard manual to see if it has a TPM header where you can install a separate module. If it does not have a header, your motherboard cannot support TPM 2.0 without replacing the motherboard.