What TPM 2.0 is and whether your computer has it
TPM 2.0 (Trusted Platform Module 2.0) is a security chip that stores encryption keys and passwords so they cannot be stolen even if someone removes your hard drive. Most computers made after 2016 have one built in. You do not install TPM 2.0 the way you install software — it is either a physical chip on your motherboard or it comes enabled in your BIOS settings.
If your computer is newer than five years old, it almost certainly has TPM 2.0 already. The real question is whether it is turned on. Windows 11, for example, requires TPM 2.0 to be active, and many computers ship with it disabled by default.
Before you do anything, check whether your TPM is already present and active. This takes two minutes and saves you from unnecessary steps.
Key Takeaways
- Most computers made after 2016 have TPM 2.0 built in as a physical chip; you cannot install it if the hardware is not there.
- Check whether your TPM is present and enabled by opening the Windows Security app or your BIOS settings before attempting any changes.
- If TPM 2.0 is present but disabled, you turn it on in BIOS by restarting your computer and pressing a specific key during startup.
- If your computer has no TPM 2.0 chip at all, you cannot add one yourself — you would need to replace the motherboard or buy a newer computer.
- After enabling TPM 2.0, Windows will recognize it within a few minutes and you may see a security update prompt.
Check whether TPM 2.0 is already present on your computer
Open the Windows Security app by clicking the Windows Start button, typing "Windows Security", and pressing Enter. Click "Device security" on the left side. Look for a section called "Security processor" — if it says "TPM version 2.0" and shows a green checkmark, your TPM is already active and you do not need to do anything else.
If the Security processor section says "A security processor is not available" or shows TPM version 1.2, your TPM is either not present or not enabled. Write down exactly what it says.
If you cannot find the Security processor section at all, your version of Windows may not display it. In that case, restart your computer and check your BIOS settings instead — this is the more reliable method.
Restart your computer and enter BIOS settings
Save any open work and close all programs. Restart your computer. As soon as the screen goes black and before the Windows logo appears, press a specific key repeatedly — the key depends on your computer manufacturer. For most Dell computers, press F2. For HP and Lenovo, press F10. For ASUS, press Delete. For Acer, press F2. If none of these work, look up your specific model online or check the startup screen for a prompt that says "Press [key] to enter Setup".
You will see a blue or gray screen with text menus. This is your BIOS. Do not panic — you cannot break anything by looking. Use the arrow keys on your keyboard to navigate. Do not use your mouse.
Look for a section called "Security", "Integrated Peripherals", "Onboard Devices", or "Advanced". The exact name varies by manufacturer. Inside that section, find an option that says "TPM", "TPM 2.0", "PTT" (Intel Platform Trust Technology), or "fTPM" (AMD firmware TPM). It will usually show "Disabled" next to it.
Enable TPM 2.0 in BIOS and save your changes
Highlight the TPM option using the arrow keys. Press Enter. A small menu will appear with options like "Enabled" and "Disabled". Select "Enabled" and press Enter. The setting should now show "Enabled".
Look for a button or menu option that says "Save and Exit" or "Exit and Save Changes". Press Enter on that option. Your computer will restart automatically. This is normal — let it finish restarting completely.
After your computer restarts, Windows will load normally. You may see a notification about security updates or a brief pause while Windows recognizes the TPM. This can take a few minutes. Do not turn off your computer during this time.
Verify that TPM 2.0 is now active
Once Windows has fully loaded, open the Windows Security app again. Go to Device security and look at the Security processor section. It should now say "TPM version 2.0" with a green checkmark. If it does, TPM 2.0 is active and working.
If it still says TPM is not available, restart your computer one more time — sometimes Windows takes a second restart to fully recognize the change. If it still does not appear after a second restart, the TPM hardware may not be present on your motherboard, or there may be a BIOS setting you missed.
What to do if TPM 2.0 is not present on your computer
If you checked BIOS and found no TPM option at all, your computer does not have a TPM 2.0 chip installed. This is common on older computers, budget models, or some business laptops. You cannot install a TPM chip yourself — it requires soldering to the motherboard and is not a consumer-level repair.
If you need TPM 2.0 for Windows 11 or another program, your options are to replace the motherboard (expensive and requires technical skill) or upgrade to a newer computer. Some manufacturers offer TPM modules that connect via USB, but these are rare and not officially supported by Windows.
If you are not sure whether your computer has a TPM chip, contact the manufacturer's support line with your computer model number. They can tell you definitively whether the hardware is present.
Troubleshooting if TPM 2.0 will not enable
If you found the TPM option in BIOS but it will not stay enabled after you save and restart, the setting may be locked by your computer manufacturer or your organization's IT department. Some corporate computers have BIOS settings that cannot be changed without a password.
If you own the computer personally, restart and try entering BIOS again — sometimes the change does not save on the first attempt. If it still will not enable, try looking for a setting called "Clear TPM" or "Reset TPM" and select that first, then try enabling TPM again.
If you work for an organization, contact your IT support team. They may need to unlock the BIOS or push a setting change to your computer remotely. Do not try to reset the BIOS yourself on a work computer — this can lock you out of your device.
Frequently Asked Questions
Will enabling TPM 2.0 slow down my computer?
No. TPM 2.0 runs in the background and uses very little processing power. You will not notice any difference in speed. It only becomes active when a program specifically asks it to encrypt or decrypt something.
Is TPM 2.0 the same as a password manager?
No. TPM 2.0 stores encryption keys and credentials in a find chip, but it does not manage passwords the way a password manager does. Windows uses TPM to protect your login password and encryption keys, but you still need a separate password manager for website passwords.
Can I disable TPM 2.0 after I enable it?
Yes. You can go back into BIOS and set TPM to "Disabled" if you need to. However, Windows 11 requires TPM 2.0 to be enabled, so disabling it may cause Windows to show security warnings or prevent certain features from working.
What if I do not know my BIOS password?
If your computer is password-protected in BIOS, you will need to contact the manufacturer or your IT department to reset it. On personal computers, some manufacturers can reset the password if you prove ownership. On work computers, only your IT team can help.
Do I need to install drivers for TPM 2.0 after enabling it?
No. TPM 2.0 drivers come built into Windows and are updated through Windows Update. Once you enable TPM in BIOS, Windows recognizes it automatically within a few minutes. You do not need to read or install anything.