Geeks in Phoenix

Geek Blog


Enabling TPM for Windows 11 upgrade on 2018-2021 Windows 10 PCs

Was your computer manufactured between 2018 and 2021 and still running Windows 10 because you have yet to be prompted to upgrade to Windows 11? If so, it could be Windows 11 compatible and needs a feature turned on. Here is how to enable the Trusted Platform Module (TPM) in your computer.

Enabling TPM for Windows 11 Upgrade on 2018-2021 Windows 10 PCs

One of the services we offer is to perform a clean installation of Windows. When doing clean installs, I find that most systems manufactured between 2018 and 2021 do not have the TPM enabled. Once I enable the TPM, I usually will do a clean installation of Windows 11 instead of Windows 10.

So, what is the TPM? The TPM is a microchip that provides hardware-based security functions. It is designed to provide a secure foundation for various security-related functions, such as BitLocker drive encryption, Windows Hello, secure boot, and more. By providing a secure environment for sensitive operations, TPM helps protect the system's integrity and the data's confidentiality.

The first version of the TPM, 1.2, started to appear in computers in 2006 and was a dedicated chip. TPM version 2.0 (the version required by Windows 11) began to appear in computers in 2018 and is a firmware extension of the CPU (Central Processing Unit). Between 2018 and 2021, the TPM function of most computers was turned off by default, as no version of Windows required it.

Then, in 2021, Microsoft released Windows 11 and changed the hardware requirements for Windows. Windows 11 now requires a TPM version 2.0 for Windows 11 to be installed. There were registry hacks and other ways to get around it, but Microsoft quickly patched those flaws.

So, the first thing you need to do is find out the status of the TPM inside Windows 10. By bringing up the TPM Management console, you can see if a TPM is enabled and what version it is. To open the TPM Management console, perform either of the following:

  • Open a RUN dialog box by pressing the Windows logo key Windows logo key + R, type tpm.msc in the Open field, and left-click on OK.
    or
  • Open a search box by pressing the Windows logo key Windows logo key + S, type tpm.msc, and choose tpm.msc Microsoft Common Console Document.

Once the TPM Management console appears, it will tell you if a TPM is enabled and what version it is.
TPM status inside of Windows 10
If it states that a compatible TPM could not be found, you will have to either research the system/motherboard specifications online or boot your computer into the BIOS (Basic Input/Output System) / UEFI (Unified Extensible Firmware Interface).

Now, before you research online or boot into the BIOS/UEFI, let's talk about what you will be looking for. The CPU manufacturers (Intel and AMD) have different names for implementing the TPM firmware extensions.

  • The TPM extension inside Intel processors is called Platform Trust Technology (PTT).
  • The TPM extension inside AMD processors is called Firmware TPM (fTPM).

The quickest and easiest way to check for a TPM is to boot your computer into the BIOS/UEFI. This may take several tries, as interrupting the booting cycle for your computer can be challenging. If you don't interrupt the boot process the first time, just let the computer boot to the login screen and restart it.

  1. Restart your computer and access the BIOS/UEFI settings. The method to access these settings varies depending on the manufacturer of your computer. Typically, you can access the BIOS/UEFI settings by pressing a specific key (such as F2, F10, or Del) during the boot process. Most of the time, pressing either the F2 or the Del key rapidly when the splash screen (the manufacturer logo) appears will get you into the BIOS/UEFI settings. Consult your computer's manual or the manufacturer's website for specific instructions.
  2. Once in the BIOS/UEFI settings, navigate to the Security or Advanced tab. Look for an option related to TPM or Security. The wording may vary depending on the manufacturer. Remember to look for PTT in systems with Intel processors and fTPM for systems with AMD processors.
  3. Enable the TPM feature and save the changes before exiting the BIOS/UEFI settings. Your computer will restart.
  4. After enabling TPM in the BIOS/UEFI settings, you can verify that it is enabled in Windows 10 by opening the TPM Management console (as previously outlined). It should now show that TPM is enabled.

Once the TPM is enabled, you can wait for Windows Update to offer the Windows 11 upgrade or manually upgrade Windows 10 to Windows 11. Enabling the Trusted Platform Module on computers manufactured between 2018 and 2021 running Windows 10 is an important step towards being able to upgrade to Windows 11. By following the steps outlined in this article, users can verify the presence and version of a TPM and enable it in the BIOS/UEFI.

Windows 11 hardware requirements explained

Updated May 16, 2024

Are you confused about the hardware requirements for Windows 11? Want to know why your computer can or cannot be upgraded to Windows 11? Let's take a detailed look at the hardware requirements for Windows 11.

Windows 11 hardware requirements explained

With Windows 11, Microsoft is focusing on security and is enforcing the hardware requirements to run it. Previous versions of Windows (10, 8.1, and 7) all had the exact general hardware requirement.

However, with Windows 10, the security requirements were still there, but they were not being enforced. The Unified Extensible Firmware Interface (UEFI), Secure Boot, and Trusted Platform Module (TPM) (see below) requirements were optional for Windows 10 to install and run.

For example, TPM has always been required to enable BitLocker drive encryption. Windows 10 would use either TPM 1.2 or TPM 2.0. However, the TPM 1.2 standard has been depreciated, so TPM 2.0 is now the de facto standard.

And if you look into UEFI, you will find that Secure Boot is part of that standard. And since UEFI can take advantage of the TPM, it makes sense to include all three (3) in the requirements for Windows 11.

Note: Sorry if anybody still running a 32-bit version of Windows 10, but Windows 11 is only available in a 64-bit version.

Hardware requirements for Windows 7, 8.1 and 10

Processor - 1 Gigahertz (GHz) or faster 32-bit (x86) or 64-bit (x64) processor

Memory - 1 Gigabyte (GB) RAM (32-bit) or 2 GB RAM (64-bit)

Storage - 16 GB (32-bit) or 20 GB (64-bit)

Graphics card - Compatible with DirectX 9 with WDDM 1.0 or higher driver

Hardware requirements for Windows 11

Processor - 1 Gigahertz (GHz) or faster with two or more cores on a compatible 64-bit processor or System on a Chip (SoC). This requirement is now particular about which processors are compatible with Windows 11. General Rule of thumb: If the processor is under six (6) years old, it should run Windows 11. Microsoft has a list of processors that are compatible with Windows 11.

Memory - 4 Gigabytes (GB) RAM. This requirement has increased from 2GB to 4GB, which is no biggie. I have not seen a computer with only 2 GB of memory in over a decade.

Storage - 64 GB or larger storage device. This requirement has also increased, and it is about time. I have seen Windows 8.1 and Windows 10 installed on 32 GB drives, which is not pretty. The biggest problem is there usually is not enough free space to perform a feature update. I recommend at least a 256 GB drive for the operating system and programs.

Graphics card - DirectX 12 graphics device or later with WDDM 2.0 driver. Since DirectX 12 was released with Windows 10 back in 2015, most modern graphic cards will be compatible with Windows 11.

Hardware requirements that are no longer optional

Display - A high definition (720p) display greater than 9" diagonally, 8 bits per color channel. This requirement is pretty easy to meet.

System firmware - UEFI and Secure Boot capable. UEFI (Unified Extensible Firmware Interface) has been used for over a decade now, so most computers running have UEFI enabled. And since the Secure Boot specification is part of the UEFI, that should already be in place. However, you may have to change some settings in your computer's BIOS (Basic Input / Output System) to enable UEFI and Secure Boot.

TPM - Trusted Platform Module (TPM) 2.0. Besides the processor requirement, this is another stumbling point for upgrading to Windows 11. A TPM can be a separate module that you connect to your motherboard or be part of the chipset on your motherboard. Most modern motherboards will use FTPM (Firmware Trusted Platform Module) included in the chipset. However, you may have to change some settings in your computer's BIOS (Basic Input / Output System) to enable the TPM.

Note: Computers with TPM 2.0 started hitting the market in 2018. Since the Windows 10 hardware requirements did not require the TPM, most computer system and motherboard manufacturers disabled the TPM by default. It wasn't until Microsoft released Windows 11 in 2021 that manufacturers started to enable the TPM 2.0 by default. So, if your computer was built between 2018 and 2021, there is a good possibility that it can run Windows 11. To enable the TPM 2.0 on one of these systems, you must check the owner manual for your computer/motherboard to see how to enable the TPM 2.0.

Storage structure - There are two (2) types of drive structures: MBR (Master Boot Record) and GPT (GUID Partition Table). Previous versions of Windows would run on either of these structures. Windows 11 requires GTP for the drive that contains Windows 11. Microsoft has included a tool inside Windows 10 to convert drives from MBR to GPT. Here is a link to the documentation for MBR2GPT.EXE.

Free computer diagnostics

Repairing a PC can sometimes be expensive, and that is why we offer free basic in-shop diagnostics. Give one of our professional and experienced technicians a call at (602) 795-1111, and let's see what we can do for you.

Check out our reviews

Geeks In Phoenix LLC, BBB Business Review

Customer service is #1

Here at Geeks in Phoenix, we take pride in providing excellent customer service. We aim to give the highest quality of service  from computer repair, virus removal, and data recovery.

Bring your computer to us and save

Repairing a computer can be time-consuming. That is why we base our in-shop service on the time we work on your computer, not the time it takes for your computer to work! From running memory checking software to scanning for viruses, these are processes that can take some time.

Contact us

If you have any questions, please feel free to give us a call at (602) 795-1111  and talk with one of our Geeks. Or you can send us a message from our contact page , and one of our Geeks will get back to you as soon as possible. Or you can stop by and see us. Here are our hours and location.

Like Geeks in Phoenix on Facebook

Follow Geeks in Phoenix on Twitter

Watch Geeks in Phoenix on YouTube