A TPM chip is a small security processor built into your computer that stores encryption keys and verifies your device hasn't been tampered with

TPM stands for Trusted Platform Module. It's a dedicated chip (or sometimes software running on your main processor) that acts as a secure vault for sensitive information. The chip stores encryption keys, passwords, and other data that your operating system and programs need to keep private. Unlike your regular hard drive or memory, a TPM is designed so that even if someone physically removes it or gains access to your computer, they cannot extract the secrets stored inside.

Think of it like a safe bolted to your computer. Your operating system can ask the TPM to unlock something or verify that a file hasn't been changed, but the TPM itself keeps the actual keys hidden. This separation matters because it means malware running on your computer cannot simply read the encryption keys from memory the way it could if they were stored in a regular file.

Key Takeaways

  • A TPM chip stores encryption keys and security information in a way that prevents malware and physical theft from exposing them.
  • Windows 11 requires a TPM 2.0 chip, which is why older computers cannot run the latest version of Windows.
  • Your TPM works in the background and you do not need to do anything to use it — Windows and your programs handle it automatically.
  • A TPM can be a separate physical chip soldered to your motherboard, or it can run as firmware on your main processor, depending on your computer's age and manufacturer.

What a TPM actually does on your computer

Your TPM performs three main jobs. First, it stores encryption keys that Windows uses to protect your files and passwords. When you set up Windows Hello (the facial recognition or fingerprint login), that biometric data is encrypted and stored on the TPM, not in a regular file where it could be stolen. Second, the TPM verifies that your operating system and core system files have not been modified. When your computer starts up, the TPM checks that Windows and your firmware are still the original versions — if something has been changed, it can alert you or prevent the system from booting. Third, the TPM can encrypt your entire hard drive using a technology called BitLocker (on Windows Pro and Enterprise editions). The encryption key lives on the TPM, so even if someone steals your hard drive and connects it to another computer, they cannot read the files without that key.

In everyday use, you will not notice your TPM working. It runs silently in the background. You do not open it, configure it, or interact with it directly. Windows and your security software use it automatically whenever they need to store or verify something sensitive.

TPM 1.2 versus TPM 2.0 — why the version matters

There are two versions of TPM in use: TPM 1.2 and TPM 2.0. TPM 2.0 is newer, faster, and more secure. It uses stronger encryption algorithms and can handle more complex security tasks. Most importantly, Windows 11 requires TPM 2.0. If your computer has only TPM 1.2 or no TPM at all, you cannot install Windows 11, even if your processor and RAM are powerful enough. This is why many computers from 2015 to 2017 cannot run Windows 11 — they have TPM 1.2 or no TPM chip at all.

You can check which version your computer has by opening the Windows Run dialog (press Windows key + R), typing tpm.msc, and pressing Enter. A window will open showing your TPM version. If you see "TPM 2.0", you are set. If you see "TPM 1.2" or nothing appears, your computer does not have TPM 2.0.

Where the TPM chip is located

On newer computers (roughly 2016 and later), the TPM is usually a small chip soldered directly to the motherboard. You would see it if you opened your computer case — it looks like a small rectangular component about the size of a postage stamp. On some newer systems, especially laptops, the TPM functionality is built into the main processor itself as firmware, so there is no separate physical chip to see.

Older computers may have a TPM module that plugs into a slot on the motherboard, similar to a RAM stick, but this is less common. Some very old computers have no TPM at all. If your computer was built before 2010, it almost certainly does not have one.

Do you need to enable your TPM?

In most cases, your TPM comes enabled from the factory and you do not need to do anything. Windows automatically uses it. However, on some computers — particularly business laptops — the TPM may be disabled in the BIOS (the firmware settings that run before Windows starts). If you are trying to install Windows 11 and you get a message saying your computer does not have TPM 2.0, it might actually have it but it is turned off.

To enable it, restart your computer and enter the BIOS setup. The key to press varies by manufacturer — common ones are Delete, F2, F10, or F12, and the correct key usually appears on the startup screen. Look for a setting called "TPM", "Security Chip", "PTT" (Platform Trust Technology), or "fTPM" (firmware TPM). Change it from Disabled to Enabled, save, and exit. Then restart Windows. This is a one-time step and you will not need to touch it again.

TPM and Windows 11 installation

Windows 11 checks for TPM 2.0 during installation and will refuse to proceed if it is not present. This is not a suggestion or a warning — it is a hard requirement. If your computer does not have TPM 2.0, you cannot install Windows 11 at all. You can continue using Windows 10, which does not require TPM 2.0, but Windows 10 support ends in October 2025.

If you have an older computer without TPM 2.0 and you want to run Windows 11, you have two options: upgrade to a newer computer that has TPM 2.0, or use a workaround that bypasses the TPM check during installation (though this is not supported by Microsoft and may cause security issues). Most people in this situation simply stay on Windows 10 or upgrade their hardware.

Security risks if your TPM fails

If your TPM chip fails or becomes corrupted, Windows may not start, or you may lose access to encrypted files. This is rare — TPM chips are very reliable — but it can happen. If your hard drive is encrypted with BitLocker and your TPM fails, you will need your BitLocker recovery key to decrypt the drive on another computer. This is why Microsoft recommends saving your BitLocker recovery key to your Microsoft account or printing it and storing it safely.

If your TPM simply stops working but your hard drive is not encrypted, you may be able to reinstall Windows or disable TPM checks in the BIOS. However, you will lose the security benefits of the TPM, and some features like Windows Hello may no longer work.

Frequently Asked Questions

Can I add a TPM chip to an older computer that does not have one?

On some older desktop computers with a TPM slot on the motherboard, you can purchase and install a TPM 2.0 module. However, many older computers have no slot at all, making it impossible to add one. Check your motherboard manual or contact the manufacturer to see if your model supports a TPM module. For most laptops, adding a TPM is not possible.

Does a TPM slow down my computer?

No. The TPM runs independently and does not compete with your processor or memory. You will not notice any performance difference whether your TPM is in use or not. It is designed to work in the background without affecting everyday speed.

Is a TPM the same as antivirus software?

No. A TPM is a hardware security tool that protects encryption keys and verifies your system has not been tampered with. Antivirus software detects and removes malware. They work together but do different jobs. You need both for good security.

What happens if someone steals my computer with BitLocker encryption?

If your hard drive is encrypted with BitLocker and your TPM is working, the thief cannot read your files even if they remove the drive and connect it to another computer. The encryption key is locked inside the TPM and cannot be extracted. Without your BitLocker recovery key, the drive is unusable to them.

Can I disable my TPM if I do not want it?

You can disable it in the BIOS, but this is not recommended. Disabling the TPM removes important security protections and may prevent Windows 11 from running. There is no practical reason to disable it unless you are troubleshooting a specific problem.