A device TPM problem in Windows 11 can involve a disabled security processor, a firmware issue, or a TPM initialization failure. Windows 11 requires TPM 2.0. Check the exact Windows Security message and use the matching steps below. Before changing firmware or resetting TPM, back up your data and confirm that you can access your BitLocker recovery key if encryption is enabled. On a work or school PC, contact your IT administrator before firmware changes or TPM resets.
Restart When Windows Security Requests It
Open Windows Security.
Select Device security.
Open Security processor details, then Security processor troubleshooting to read the TPM error message.
Choose Start > Power > Restart when Windows shows TPM measured boot log is missing. Try restarting your device. or There is a problem with your TPM. Try restarting your device.
After Windows loads again, return to Windows Security > Device security > Security processor details > Security processor troubleshooting and check whether the warning is gone.
Tip: use Restart from the power menu so Windows completes the restart cycle it requested.
Check Whether TPM 2.0 Is Detected
Use this when Windows 11 shows a TPM warning, BitLocker setup reports a TPM problem, or you need to confirm TPM 2.0 before changing firmware settings. Windows 11 requires TPM 2.0.
Open Windows Security, then select Device security. Look for Security processor.
Select Security processor details and read Specification version.
Press Windows key + R, type tpm.msc, and select OK. If TPM is ready, check TPM Manufacturer Information > Specification Version.
If tpm.msc says Compatible TPM cannot be found, go to the UEFI firmware step next.
Turn On TPM In UEFI Firmware
Use the Windows recovery path to enter firmware settings and enable the security processor.
- 1.Open Settings > System > Recovery.
- 2.Under Recovery options, next to Advanced startup, select Restart now.
- 3.Select Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
- 4.In UEFI or BIOS, open Advanced, Security, or Trusted Computing.
- 5.Enable Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT, or Intel Platform Trust Technology.
- 6.Save the firmware changes and restart Windows.
Use Dell BIOS Settings On Dell PCs
On current Dell systems that support TPM 2.0, save your work and restart the computer. When the Dell logo appears, press F2 once per second to enter setup.
Open Security. Set Intel Platform Trust Technology, Trusted Platform Module, TPM 2.0 Security, or Firmware TPM to On or Enabled.
Save the setting and restart Windows. Dell lists this path for supported Alienware, Inspiron, Latitude, OptiPlex, Precision, Vostro, XPS, Dell Pro, and Dell Plus systems.
Install Windows Updates And Check TPM Drivers
Use this when Windows Security reports a security processor firmware issue, Device Manager shows a TPM warning, or TPM detection fails after an update.
Open Settings > Windows Update, select Check for updates, and install applicable updates. Restart if prompted.
Before installing TPM firmware, follow the update prerequisites for your exact PC model. Microsoft's linked TPM firmware advisory specifies Windows updates first for the particular Windows 10 vulnerability it covers.
On a Dell PC where Trusted Platform Module 2.0 has a warning in Device Manager, right-click Start and open Device Manager.
Expand Security Devices, right-click Trusted Platform Module 2.0, select Update Driver, choose Search Automatically for updated Driver version, then select Search for updated driver version on Windows Update.
In Windows 11, open Settings > Windows Update > Advanced options > Optional updates. If a relevant TPM driver is offered under Driver updates, select it and choose Download and install, then restart. If no update is offered, check the support page for your exact PC model.
Install The Manufacturer Firmware Update
When Windows Security reports a TPM firmware problem, check your PC maker's support page for an update intended for your exact model. Microsoft's linked TPM firmware advisory concerns a specific Windows 10 vulnerability. Its Windows-update-first requirement is part of that advisory's remediation.
For Surface, follow Microsoft's Surface driver and firmware guidance for your model. For other brands, follow the PC manufacturer's firmware instructions or contact its support department.
Complete all operating-system prerequisites specified by the applicable firmware instructions before installing the package.
If the manufacturer’s instructions tell you to clear TPM after the firmware update, use Windows Security, not the UEFI firmware screen.
If the warning remains after the appropriate firmware update, check Security processor troubleshooting again. Follow the action for that message and contact the PC maker if it persists.
Clear TPM Safely From Windows
Clear TPM when Windows explicitly requests it, Windows cannot initialize it, or your PC maker's applicable update instructions require it. Use an administrator account. Back up data and recovery information for everything protected by TPM, including your BitLocker recovery key. Clearing removes TPM keys and can disrupt Windows Hello PIN or biometric sign-in. Reset your PIN if needed afterward. On a work or school PC, have IT handle the reset.
Open Windows Security > Device security > Security processor details > Security processor troubleshooting. Under Clear TPM, select Clear TPM.
Restart when Windows prompts you. During restart, press the required confirmation button if the UEFI screen asks for physical confirmation.
Use the Windows path for clearing TPM instead of clearing TPM directly from UEFI.
Use Advanced TPM Repair Tools
Use these only after the Windows Security, UEFI, update, and firmware steps fail.
Open tpm.msc and select Turn TPM On when TPM was turned off and Windows offers that action.
Use Turn TPM Off only for temporary troubleshooting, then follow the dialog and UEFI prompts.
Run Clear-Tpm in Windows PowerShell as administrator only after backing up recovery information. Clear-Tpm needs a valid TPM owner authorization value: type it in, point to a saved copy with -File, or let the cmdlet use the value stored in the registry. To clear without an owner authorization value, run Clear-Tpm -UsePPI to use the Physical Presence Interface, then restart and approve the clear request if the firmware asks. On a personal PC, Windows Security is still the path to use.
Windows normally initializes and takes ownership of TPM automatically. If an administrator needs to troubleshoot failed initialization, Initialize-Tpm -AllowClear -AllowPhysicalPresence can clear TPM during provisioning. Apply the same data and recovery-key backups as for Clear TPM before running it. Its physical-presence option can request confirmation at the next restart; follow the status information returned by the command. On a managed PC, leave this procedure to IT.
Use Reset TPM Lockout or Unblock-Tpm only when TPM is in lockout mode and you have the required owner authorization or owner authorization file.
Leave Managed Or Unsupported PCs Alone
On a work or school PC, leave TPM resets and firmware changes to your IT administrator. Managed devices use policies that control TPM reset prompts, the Clear TPM button, and firmware update recommendations.
Skip Windows 11 TPM-bypass install tricks. Microsoft’s supported path is to meet the Windows 11 minimum requirements, including TPM 2.0.
If this PC was upgraded from Windows 10 to Windows 11 and does not meet Windows 11 requirements, use Settings > System > Recovery > Recovery options > Go back to undo the upgrade while that option remains available. It is normally available for only 10 days after upgrading. Windows 10 reached end of support on October 14, 2025, but enrolled PCs can still receive critical and important security updates through the Windows 10 Consumer Extended Security Updates program — at no additional cost if you sync your PC settings, for 1,000 Microsoft Rewards points, or for a one-time $30 USD purchase — through October 12, 2027. Factor that support limit into any rollback decision.
Frequently Asked Questions
Why does Windows 11 need TPM 2.0?
Windows 11 requires TPM 2.0 as part of its minimum system requirements. Windows uses TPM as the device security processor.
What does “Compatible TPM cannot be found” mean?
It means Windows cannot detect a usable TPM. Check UEFI firmware settings next and enable the TPM option if your PC supports it.
Is it safe to clear TPM in Windows 11?
Clearing TPM removes its stored keys and can disrupt access to protected data and Windows Hello sign-in. Back up your data and all needed recovery information, including the BitLocker recovery key, first. Clear it only when the relevant troubleshooting instructions call for it; on a work or school PC, involve IT. Restart may require firmware confirmation.
Should I update TPM firmware before Windows Update?
Follow the firmware instructions for your exact PC model. Microsoft's linked TPM vulnerability advisory is labeled for Windows 10 and requires the applicable Windows update before its TPM firmware update. For Windows 11, use the PC maker's documented prerequisites and update sequence.











