Why Windows 11 Is Forcing Everyone To Use TPM Chips - The Verge
Có thể bạn quan tâm
- The VergeThe Verge logo.
- Tech
- Reviews
- Science
- Entertainment
- AI
- Policy
- Hamburger Navigation Button
- Login / Sign Up
- TechExpand
- Amazon
- Apple
- Microsoft
- Samsung
- Business
- See all tech
- ReviewsExpand
- Smart Home Reviews
- Phone Reviews
- Tablet Reviews
- Headphone Reviews
- See all reviews
- ScienceExpand
- Space
- Energy
- Environment
- Health
- See all science
- EntertainmentExpand
- TV Shows
- Movies
- Audio
- See all entertainment
- AIExpand
- OpenAI
- Anthropic
- See all AI
- PolicyExpand
- Antitrust
- Politics
- Law
- Security
- See all policy
- GadgetsExpand
- Laptops
- Phones
- TVs
- Headphones
- Speakers
- Wearables
- See all gadgets
- Verge ShoppingExpand
- Buying Guides
- Deals
- Gift Guides
- See all shopping
- GamingExpand
- Xbox
- PlayStation
- Nintendo
- See all gaming
- StreamingExpand
- Disney
- HBO
- Netflix
- YouTube
- Creators
- See all streaming
- TransportationExpand
- Electric Cars
- Autonomous Cars
- Ride-sharing
- Scooters
- See all transportation
- Features
- Verge VideoExpand
- TikTok
- YouTube
- PodcastsExpand
- Decoder
- The Vergecast
- Version History
- Newsletters
- Archives
- Store
- Verge Product Updates
- Threads
- Youtube
- RSS
- TechCloseTech
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Tech
- NewsCloseNews
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All News
- ReportCloseReport
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Report
Microsoft’s security effort is complicated
Microsoft’s security effort is complicated
by Close
Tom WarrenSenior EditorPosts from this author will be added to your daily email digest and your homepage feed.
FollowFollowSee All by Tom Warren
Jun 25, 2021, 5:10 PM UTC- Link
- Share
- Gift

Image: Microsoft
Tom WarrenPosts from this author will be added to your daily email digest and your homepage feed.
FollowFollowSee All by Tom Warren
is a senior editor and author of Notepad, who has been covering all things Microsoft, PC, and tech for over 20 years.Microsoft announced yesterday that Windows 11 will require TPM (Trusted Platform Module) chips on existing and new devices. It’s a significant hardware change that has been years in the making, but Microsoft’s messy way of communicating this has left many confused about whether their hardware is compatible. What is a TPM, and why do you need one for Windows 11 anyway?
“The Trusted Platform Modules (TPM) is a chip that is either integrated into your PC’s motherboard or added separately into the CPU,” explains David Weston, director of enterprise and OS security at Microsoft. “Its purpose is to protect encryption keys, user credentials, and other sensitive data behind a hardware barrier so that malware and attackers can’t access or tamper with that data.”
Related
- Windows 11 is free, but your CPU might not be officially supported
So it’s all about security. TPMs work by offering hardware-level protection instead of software only. It can be used to encrypt disks using Windows features like BitLocker, or to prevent dictionary attacks against passwords. TPM 1.2 chips have existed since 2011, but they’ve typically only been used widely in IT-managed business laptops and desktops. Microsoft wants to bring that same level of protection to everyone using Windows, even if it’s not always perfect.

Microsoft has been warning for months that firmware attacks are on the rise. “Our own Security Signals report found that 83 percent of businesses experienced a firmware attack, and only 29 percent are allocating resources to protect this critical layer,” says Weston.
That 83 percent figure seems huge, but when you consider the various phishing, ransomware, supply chain, and IoT vulnerabilities that exist, the broad range of attacks becomes a lot clearer. Ransomware attacks hit the headlines weekly, and ransomware funds more ransomware so it’s a difficult problem to solve. TPMs will certainly help with certain attacks, but Microsoft is banking on a combination of modern CPUs, Secure Boot, and its set of virtualization protections to really make a dent in ransomware.
Microsoft is trying to play its part, particularly as Windows is the platform that’s often most affected by these attacks. It’s widely used by businesses worldwide, and there are more than 1.3 billion Windows 10 machines in use today. Microsoft software has been at the core of devastating attacks that made global headlines, like the Russia-linked SolarWinds hack and the Hafnium hacks on Microsoft Exchange Server. And while the company isn’t responsible for forcing its clients to keep its software patched, it’s trying to be more proactive about protection.

Microsoft has a habit of struggling to move Windows into the future in both hardware and software, and this particular change hasn’t been explained well. While Microsoft has required OEMs to ship devices with support for TPM chips since Windows 10, the company hasn’t forced users or its many device partners to turn these on for Windows to work. That’s what’s really changing with Windows 11, and combined with Microsoft’s Windows 11 upgrade checker, it has resulted in a lot of understandable confusion.
Microsoft’s Windows 11 website lists the minimum system requirements, with a link to compatible CPUs and a clear mention that a TPM 2.0 is required at a minimum. The PC Health Check app that Microsoft asks people to download and check to see if Windows 11 runs will flag systems that do not have Secure Boot or TPM support enabled or devices that have CPUs that aren’t officially supported (anything older than 8th Gen Intel chips).
That’s left many trying to figure out if their device supports TPM or not, confusion with BIOS settings, and even people rushing to buy separate TPM modules they don’t need. Some are even scalping TPM 2.0 modules on eBay!
It also didn’t help that Microsoft originally had a second webpage with contradictory information, one which it changed a couple hours after we published this story. According to the original version of the page, the true minimum requirements were TPM 1.2 and a 64-bit dual-core CPU that’s 1GHz or greater, but the new page now clarifies it requires TPM 2.0 and a processor that Microsoft has explicitly certified as compatible — which might mean everything before an 8th Gen Intel Core and AMD Ryzen 2000 won’t work.
We’re still waiting for explicit confirmation from Microsoft on the CPU requirement, but a rep confirms that TPM 2.0 will be mandatory, and that the original information on that page was wrong. “The referenced docs page was a mistake that has since been corrected,” an MS rep tells The Verge.

Microsoft is promoting TPM 2.0 and performing checks for 8th Gen or newer Intel chips because these are the requirements for certified OEM hardware — the machines you’ll find in stores with an inevitable Windows 11 sticker. But it’s no longer clear whether the Windows 11 update will work on older machines either, and Microsoft is suggesting to us that it won’t. We understand Microsoft is currently putting together a blog post that will explain the minimum requirements in more detail.
But that doesn’t mean your existing PC is out of luck just because you’re having issues with Microsoft’s compatibility tool. Unless your CPU is very old, it probably already has baked-in TPM 2.0 support.
If you’re having issues with the PC Health App checker for Windows 11, make sure you have “PTT” on Intel systems enabled in the BIOS, or “PSP fTPM” on AMD devices. The company’s system checker should also be less confusing now: shortly after we published this story, Weston tweeted that the tool will now be more specific about why your PC isn’t passing muster.
What Microsoft is trying to achieve here will benefit the Windows ecosystem in years to come, alongside its new efforts for Xbox-like security on Windows. Microsoft just totally dropped the ball on explaining that to everyone on day one.
Update, 2:26PM ET: Added that Microsoft updated its PC Health Check app, shortly after we published this story, to be more specific about why your computer isn’t meeting Windows 11 system requirements.
Update, 3:53PM ET: Added that Microsoft has changed its compatibility page to mention TPM 2.0 as a requirement instead of TPM 1.2, and that specific CPUs may be a requirement. We’re getting to the bottom of this now.
Correction, 8:06PM ET: This story originally stated Windows 11 would likely still install on PCs with access to TPM 1.2 and older CPUs, because that’s what we read in Microsoft’s documentation. Microsoft has now corrected those documents to specify TPM 2.0 is a minimum requirement for Windows 11.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.- MicrosoftCloseMicrosoft
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Microsoft
- NewsCloseNews
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All News
- ReportCloseReport
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Report
- TechCloseTech
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Tech
- WindowsCloseWindows
Posts from this topic will be added to your daily email digest and your homepage feed.
FollowFollowSee All Windows
Most Popular
Most Popular- Inside Microsoft’s big Xbox leadership shake-up
- Yep, it’s fast: Donut Lab’s solid-state battery gets its first test result
- Anker’s X1 Pro shouldn’t exist, but I’m so glad it does
- How many AIs does it take to read a PDF?
- Billions of dollars later and still nobody knows what an Xbox is
The Verge Daily
A free daily digest of the news that matters most.
Email (required)Sign UpBy submitting your email, you agree to our Terms and Privacy Notice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.Advertiser Content FromThis is the title for the native ad
More in Tech
Apple’s newest AirTags are already on sale if you’re looking to upgrade
The creators of Dark Sky have a new weather app that shares multiple predictions
Discord distances itself from Persona age verification after user backlash
Kohler’s new shower reuses dirty water to get you clean
Does Big Tech actually care about fighting AI slop?
Xbox shakeup: Phil Spencer and Sarah Bond are leaving Microsoft
Apple’s newest AirTags are already on sale if you’re looking to upgradeSheena VasaniFeb 23
The creators of Dark Sky have a new weather app that shares multiple predictionsAndrew LiszewskiFeb 23
Discord distances itself from Persona age verification after user backlashEmma RothFeb 23
Kohler’s new shower reuses dirty water to get you cleanAndrew LiszewskiFeb 23
Does Big Tech actually care about fighting AI slop?Jess WeatherbedFeb 23
Xbox shakeup: Phil Spencer and Sarah Bond are leaving MicrosoftStevie BonifieldFeb 23Advertiser Content FromThis is the title for the native ad
Top Stories
Two hours agoInside Anthropic’s existential negotiations with the PentagonFeb 23Inside Microsoft’s big Xbox leadership shake-upFeb 23Will Trump’s DOJ actually take on Ticketmaster?Feb 23Billions of dollars later and still nobody knows what an Xbox isFeb 23Why is AI so bad at reading PDFs?Feb 23Does Big Tech actually care about fighting AI slop?Từ khóa » Chip Tpm 2.0
-
Trusted Platform Module Technology Overview (Windows)
-
TPM Chip
-
Where To Buy A TPM 2.0 For Windows 11 | Tom's Hardware
-
What Is A TPM, And Why Do I Need One For Windows 11? - PCMag
-
Trusted Platform Module - Wikipedia
-
Windows 11 Demands TPM 2.0 And Here's What That Means For You
-
What Is TPM 2.0 — The Chip You Need To Run Windows 11
-
TPM 2.0 Module - MSI
-
Does Your Computer Have A TPM 2.0 Chip?
-
TPM 2.0 Là Gì? Tại Sao Lại Cần Khi Nâng Cấp Windows 11?
-
How To Check If Your PC Has A Trusted Platform Module (TPM)
-
All The Motherboards That Support TPM For Windows 11
-
Why Does Windows 11 Need TPM 2.0? - MakeUseOf