# How to Turn on TPM and Secure Boot on Window 11

**URL:** https://www.compsmag.com/blogs/how-to-turn-on-tpm-and-secure-boot-on-window-11/
**Author:** Ayushi Chauhan
**Published:** 2021-11-21
**Updated:** 2021-11-21
**Categories:** Blogs
**Tags:** Blogs Daily, Computer Guides, Computers Tips and Tutorials, guiderobert, Guides and Tutorials, guiding12, How To Guide, How To Guides, Linux Guides, Tips, Tricks, Windows 10, Windows 11, Windows Tips
**Reading Time:** 6 min

---

This tip is about the how to Turn on TPM and Secure Boot on Window 11. So read this free guide, How to Turn on TPM and Secure Boot on Window 11 step by step. If you have query related to same article you may contact us.

## How to Turn on TPM and Secure Boot on Window 11 - Guide

If you have a PC, plan to change up for Windows 11. You need to check and enable TPM 2.0 and Secure Boot in BIOS (UEFI) of your PC motherboard (from Asus, Dell, MSI, GigaByte and so on) as a feature of the update preparation process.

In Windows 11, perhaps the main change is the need for version 2.0 of the Trusted Platform Module (TPM) and secure boot.  According to Microsoft, TPM 2.0 and safe boot are expected to provide a superior security environment and avoid (or possibly limit) modern dangers such as those against hardware and firmware, normal malware, ransomware and different attacks.

## What are Secure Boot and TPM?

The Trusted Module Platform (TPM) is a hardware-level security solution that protects your data from hackers and other data breaches.  The TPM keeps unique encryption keys stored in such a way that it is nearly impossible for a hacker to access.  If someone breaks into your computer and your data is encrypted, it will remain secure.

Microsoft's recommended requirements for Windows 11 list TMP 2.0, although you can still upgrade using an earlier version, TPM 1.2, which is the minimum requirement.

Along with TPM 2.0, Microsoft also requires you to enable safe boot, UEFI level security setting that prevents any unauthorized operating system from booting up.  Secure Boot is effectively a gatekeeper, preventing malicious code from starting up before your system and its main purpose is to protect against rootkits, bootkits and other malicious code.

But it also has some side effects.  For example, secure boot will prevent multiple Linux distributions from dual booting, which has led many users to disable secure boot.

In addition to these two vitals features, Windows 11 comes with specific hardware requirements, with Microsoft choosing to block the automatic update path for millions of users.  If you are using Windows 10 on an AMD Ryzen 3000 series or later, or an Intel 7th Gen CPU or later, you can upgrade to Windows 11 direct.

However, if not, you will have to opt for a clean install of Windows 11. A clean install of Windows 11 will work on most hardware, but comes with caveats.  Notably, Microsoft has repeatedly stated that it will not provide updates for Windows 11 installations on “unsupported” hardware, so you install at your own risk and expense.

## How to    Enable TPM and Secure Boot

Trusted Module Platform and Secure Boot are found in the UEFI settings.  You'll have to enter the system's UEFI to enable them before attempting to upgrade to Windows 11. Both settings are found in similar areas, but we'll break the steps into three parts for readability.

### How to    Enter your BIOS / UEFI

There are a few ways to get into the system BIOS / UEFI.  The old tried-and-true method of tapping a keyboard key during boot still works, but you might not get the chance if you have fast boot enabled.  If the boot screens whiz by and you run out up in Windows 10, there is another way to access the BIOS.

Go to Settings > Update & Security > Recovery > Restart Now.

When the computer restarts, you will see a big blue screen with several options.  Select Troubleshooting > Advanced Options > UEFI Firmware Settings > Restart.

When the computer restarts again, you should be in the BIOS / UEFI settings menu.

### How to    Enable TPM in your BIOS / UEFI

The location of TPM settings in your BIOS will differ depending on your motherboard manufacturer.  The following images were taken from an X570 MSI motherboard, although the TPM option is not necessarily similar.  Another thing to consider is that the TPM may be listed under a different name on some motherboards, depending on the CPU manufacturer:

Intel Platform Trust (PTT) Technology

AMD fTMP

## AMD FTPM and Intel PTT: Everything You Need to Know

So, on my motherboard, the TPM options are found in Settings > Security > Trusted Computing > TPM Device Selection, where I will enable AMD fTMP.

Once powered on, you can save your settings and go back to Windows 10. Once Windows starts up, you can check the TPM status to make sure everything is fine. up and running.

Press Windows key + R to open the Run dialog, enter tpm.msc and press Enter.  The TPM management console will load, indicating whether the TPM is enabled and, if so, which version you are using.

### How to    Enable secure boot

While you're deep in the system settings, take a moment to verify that secure boot is turned on.  As with the TPM options, where you find the Safe Boot option will be a little different, but it's usually located on the Boot tab.  Find the Boot tab and scroll down to find the Secure Boot option and make sure it is enabled.

One thing to note about secure boot is that it requires your drives to use the GUID Partition Table (GPT) rather than the older master boot record (MBR).  As the latest partition table, GPT comes with several improvements over MBR.  If Secure Boot is not enabled, you may need to convert your MBR drive to GPT.

## How to convert MBR to GPT without losing data on Windows

Alternatively, your computer or hardware may be too old to enable safe boot.

## Use Microsoft's PC Health Check app to verify that your hardware is compatible

Microsoft recommends using its PC Health Check application to verify hardware compatibility.  The PC Health Check app can be found at the bottom of the linked page.  download and shoot up to check its compatibility with Windows 11.

Alternatively, you can check out WhyNotWin11, an open source alternative that can provide a more in-depth look at Windows 11 compatibility.

So, there you have it.  You've enabled two of the most important settings that will block the Windows 11 upgrade path. Once enabled and assuming you're running supported hardware, Microsoft will offer you the Windows 11 upgrade. you're done, go to Settings> Update & Security> Windows Update, where you'll find the big update button.

## Final note

I hope you like the guide How to Turn on TPM and Secure Boot on Window 11. In case if you have any query regards this article you may ask us. Also, please share your love by sharing this article with your friends.

---

*End of Article*