What TPM is and why it matters for your computer
TPM (Trusted Platform Module) is a small chip on your motherboard that stores encryption keys and security settings. It acts like a vault for sensitive data — Windows uses it to encrypt your hard drive, verify that your system hasn't been tampered with, and protect passwords stored on your device. If TPM is off, Windows can still run, but you lose those protections.
Most modern computers have TPM built in, but it's often disabled by default in the BIOS (the firmware that runs before Windows starts). Turning it on takes 10 to 15 minutes and requires you to restart your computer and enter a settings menu most people never see. The steps differ slightly depending on your computer's manufacturer, but the process is the same idea across all of them.
You don't need TPM to use your computer day-to-day. But if you store financial information, work documents, or anything you'd rather not lose to theft or malware, enabling it adds a real layer of protection — especially if your laptop gets stolen or someone tries to access your files without your permission.
Key Takeaways
- TPM is a security chip that encrypts your hard drive and protects stored passwords, but it must be turned on in your BIOS settings before Windows can use it.
- You access BIOS by restarting your computer and pressing a specific key during startup — usually Delete, F2, F10, or F12, depending on your computer's manufacturer.
- Once in BIOS, look for a setting called "TPM", "Security Chip", or "PTT" (Platform Trust Technology), then change it from Disabled to Enabled.
- After you enable TPM and save your changes, Windows may take several minutes to set up encryption on your first restart — do not turn off your computer during this time.
How to restart your computer and enter BIOS
The first step is to get into BIOS, the firmware menu that runs before Windows loads. Save any open work, then restart your computer. As soon as the screen goes black (before the Windows logo appears), press a key repeatedly — the key depends on your computer's brand. Common keys are Delete, F2, F10, or F12. If you're not sure which one, look for a message on the startup screen that says "Press [key] to enter Setup" or "Press [key] for BIOS".
If you miss the window and Windows starts loading, shut down your computer completely and try again. You have only a few seconds to press the key. On some newer computers, you may need to hold the key down rather than tap it repeatedly.
Once you're in BIOS, you'll see a menu with white text on a dark background. The layout varies by manufacturer, but you navigate using arrow keys and Enter. Do not use your mouse — BIOS does not respond to it. Take a moment to get your bearings before making any changes.
Finding and enabling TPM in your BIOS settings
Look for a section called "Security", "Integrated Peripherals", "Onboard Devices", or "Advanced". The exact name depends on your computer's manufacturer. Use the arrow keys to move between sections. Once you find the right area, look for a setting with one of these names: "TPM", "Security Chip", "PTT" (Platform Trust Technology), "fTPM" (firmware TPM), or "AMD fTPM" (if you have an AMD processor).
When you find it, the setting will usually show "Disabled" or "Off". Press Enter to open it, then select "Enabled" or "On" from the list. Some BIOS menus also ask you to set a TPM password — this is optional, and most people leave it blank. If you do set one, write it down somewhere safe, because you'll need it if you ever want to turn TPM off again.
After you enable TPM, look for a button or menu option to save and exit — usually labeled "Save and Exit" or "Exit and Save Changes". Press Enter and confirm when prompted. Your computer will restart automatically.
What happens after you enable TPM
When your computer restarts, Windows will detect that TPM is now on. If you have Windows Pro, Enterprise, or Education, Windows may automatically begin encrypting your hard drive using BitLocker (Windows' built-in encryption tool). This process can take anywhere from a few minutes to several hours, depending on how much data is on your drive. Your computer will still be usable during this time, but it may run slower than usual.
Do not turn off your computer or unplug it while encryption is running. If you do, you risk corrupting your files or making your drive unreadable. If you need to stop the process, you can pause it through Windows Settings, but restarting your computer will resume it automatically.
On Windows Home edition, TPM is enabled but BitLocker encryption does not turn on automatically. You can still use TPM for other security features like Windows Hello (facial recognition or fingerprint login) and Device Encryption (a lighter version of BitLocker). These features improve your security without the performance impact of full disk encryption.
Troubleshooting if TPM won't turn on
If you can't find a TPM setting in your BIOS, your computer may not have a TPM chip, or it may be built into your processor rather than as a separate chip. Newer computers often use fTPM (firmware TPM) or PTT (Platform Trust Technology) instead of a physical chip — these work the same way but are managed by your processor. Look for these terms in your BIOS settings if "TPM" doesn't appear.
If you find the TPM setting but it's grayed out and you can't select it, your computer's manufacturer may have locked it. This is rare, but it happens on some corporate or school-issued devices. Contact your IT department or the manufacturer's support line — they may be able to unlock it for you, or they may have a reason it's disabled that you should know about.
If you're still stuck, restart your computer and look carefully at the startup screen for the manufacturer's name and support website. Most manufacturers (Dell, HP, Lenovo, ASUS, etc.) have step-by-step BIOS guides specific to your model. You can also search "[your computer model] enable TPM" online — you'll usually find a guide with screenshots that matches your exact BIOS layout.
When TPM causes problems and what to do
In rare cases, enabling TPM can cause compatibility issues with older software or with certain security programs. If your computer starts crashing, freezing, or running very slowly after you enable TPM, the problem is usually one of two things: outdated drivers or a conflict with antivirus software.
First, check for BIOS updates. Restart your computer, enter BIOS again, and look for an option to update the BIOS firmware — this often fixes compatibility problems. If that doesn't work, temporarily disable TPM the same way you enabled it (go back into BIOS and set it to "Disabled"), then update your antivirus software and any drivers related to security or storage. Once those are updated, turn TPM back on.
If problems persist, you can leave TPM off without harming your computer. TPM adds security, but it's not required for Windows to run. The trade-off is that you lose the encryption and tamper-detection features it provides — a reasonable choice if the stability problems outweigh the security benefit for your situation.
Frequently Asked Questions
Will enabling TPM slow down my computer?
TPM itself has minimal impact on speed — the chip handles security tasks in the background. However, if Windows automatically enables BitLocker encryption, your computer may run noticeably slower during the encryption process (which can take hours). After encryption finishes, performance returns to normal. On Windows Home, Device Encryption is much lighter and has almost no impact on speed.
Can I turn TPM off after I enable it?
Yes, you can go back into BIOS and disable it the same way you enabled it. If you set a TPM password when you enabled it, you'll need that password to turn it off. If you encrypted your drive with BitLocker, you should decrypt it first before disabling TPM — otherwise you may not be able to access your files. Windows will warn you if you try to disable TPM while encryption is active.
Do I need to enable TPM if I don't use Windows Hello or BitLocker?
TPM provides security benefits even if you don't use those specific features. It protects stored passwords, verifies that your system hasn't been modified by malware, and secures other sensitive data. If you rarely travel with your laptop and don't store sensitive information, the benefit is smaller — but it costs nothing to enable, so most people turn it on as a precaution.
What if my computer doesn't have TPM?
Older computers (generally before 2010) may not have TPM at all. If you can't find any TPM setting in your BIOS, your computer likely doesn't have one. You can still use Windows and most security features, but you won't have hardware-level encryption. If security is important to you, consider upgrading to a newer computer that includes TPM.
Is TPM the same as a password?
No. TPM is a hardware chip that stores encryption keys and security settings. A password is something you type. They work together — TPM encrypts your drive, and your password controls who can access it. Even if someone steals your computer, TPM makes it much harder for them to read your files without your password.