No TPM? No Windows 11 for you!


Recommended Posts

As far as the whole TPM thing goes, I thought my i7 6700k would support Intels TPP but look as hard as I could and I couldn't find any sort of setting for it in my UEFI, I just went online and ordered a Asus TPM chip online and will install it on my board once I have it.

  • Like 2
1 hour ago, Xenon said:

I just bought a Asus TPM-M R2.0 module that is supposed to be TPM 2.0 from amazon (us) for $15. It is 14 pin. 

 

https://www.amazon.com/gp/product/B01DQQLH74/ref=ppx_yo_dt_b_asin_title_o00_s00?ie=UTF8&psc=1

Did you check your motherboard to make sure it's the 14-1 pin?

1 hour ago, Xenon said:

I am using a i7 7700k on asus prime z270-a I have cant find anything in my bios with tpm. You know a way please post it. 

From your motherboard's manual


image.png.6637721045cb3314d54b0e0c5fca34af.png
 

51 minutes ago, Talaba said:

"No TPM? No Windows 11 for you!" Who said that? If you know how? Sabretooth 990FX  has no TPM but I install Windows 11 easy.

2021-06-18-11-15-58.png

That's the dev build, it probably doesn't include the check, By the way, I hope you didn't sign in with your Microsoft account, apparently Microsoft been checking for people using it.

3 minutes ago, PsYcHoKiLLa said:

From your motherboard's manual


image.png.6637721045cb3314d54b0e0c5fca34af.png
 

Well I fooled around in the setting, and turned it on and checked tpm.msc and I think I got it running. 

 

But still says I wont be able to run 11. I checked secure boot is on and my gtx 1060 seem directx 12 compatible. 

 

 

Screenshot 2021-06-24 173143.png

12 minutes ago, PsYcHoKiLLa said:

That's the dev build, it probably doesn't include the check, By the way, I hope you didn't sign in with your Microsoft account, apparently Microsoft been checking for people using it.

Actually it does check. I tried to install it on a old notebook and it would not install.  Because of.... well you know. 

After following this thread, I have been able to enable TMP 2.0 on my motherboard's configuration. Before enabling it, when I tried to join the Windows Insider Program it wouldn't let me join the Dev channel and said the PC was not compatible with Windows 11. (Expected) So I enabled it, rebooted and this time when I tried to join the Insider Program it allowed me to join the Dev channel, but it still said that the PC was not compatible. The  Microsoft PC Health app however says that the PC is compatible. Very confusing. I guess I need to check if Secure Boot is enabled also. I have Linux installed and might have disabled it in the  past.

 

Here's are the changes I did on my MSI Z2390M for anyone who might need it. Just go to Settings/Security/Trusted Computing:

 

w2dG2Bg.jpgHr4pjGm.jpg

T5pKXZI.jpg

 

Control Panel still says not compatible, but the Health App says it is 🙂

 

PS: Well, after another reboot, the PC now shows as fully compatible with Windows 11.

 

 

1 hour ago, gate1975mlm said:

My two desktops have a Intel i7-4790K which apparently have TPM 1.2.

 

But Microsoft says you need TPM 2.0 so I guess I will not be able to upgrade the simple way?

 

I guess I will need to install Windows from an ISO on a USB and remove the "appraiserres.dll" entry?

 

If I do it this way will my copy of Windows 11 still activate using my Windows 10 key?

 

Unless you have a very modern PC this is really going to make a lot of users upset having to go the extra mile getting Windows 11 installed :( 

 

Why Microsoft why??????????????

 

 

 

 

I have the same CPU, i installed with the .dll fix, first through upgrade and then clean install, using it for my home pc and its activated and very fast

the TPM 2.0 requirement was changed at some point this afternoon

 

https://docs.microsoft.com/en-us/windows/compatibility/windows-11/#hardware-requirements

Quote

Hardware Requirements

There are new minimum hardware requirements for Windows 11. In order to run Windows 11, devices must meet the following specifications. Devices that do not meet the hard floor cannot be upgraded to Windows 11, and devices that meet the soft floor will receive a notification that upgrade is not advised.

 

Hard Floor:

CPU: Core >= 2 and Speed >= 1 GHz

System Memory: TotalPhysicalRam >= 4 GB

Storage: 64 GB

Security: TPM Version >= 1.2 and SecureBootCapable = True

Smode: Smode is false, or Smode is true and C_ossku in (0x65, 0x64, 0x63, 0x6D, 0x6F, 0x73, 0x74, 0x71)

 

Soft Floor:

Security: TPMVersion >= 2.0

CPU Generation

 

Since people are asking why use a hardware TPM vs Intel's firmware TPM... the hardware (discrete) TPM is more secure

 

Firmware TPM (CPU) has a trusted execution environment that tries to keep the TPM code from the rest of the CPU, but still is vulnerable to attacks, discrete TPM's aren't as vulnerable and execute independently of the CPU... Firmware TPM's also have the ability to get software bugs (ask Dell about their recent issue with firmware TPM's) which discrete TPM's run hardened code in a hardened environment 

 

There are actually 4 types of TPM's..

Discrete (TPM card)

Integrated TPM (Chip on motherboard)

Firmware (CPU)

Software (Emulated TPM that could use a real TPM or KMIP server for a primary TPM key, stuff like ESX Enterprise do this to provide TPM services to VM's)

  • Like 2
33 minutes ago, neufuse said:

Since people are asking why use a hardware TPM vs Intel's firmware TPM... the hardware (discrete) TPM is more secure

 

Firmware TPM (CPU) has a trusted execution environment that tries to keep the TPM code from the rest of the CPU, but still is vulnerable to attacks, discrete TPM's aren't as vulnerable and execute independently of the CPU... Firmware TPM's also have the ability to get software bugs (ask Dell about their recent issue with firmware TPM's) which discrete TPM's run hardened code in a hardened environment 

 

There are actually 4 types of TPM's..

Discrete (TPM card)

Integrated TPM (Chip on motherboard)

Firmware (CPU)

Software (Emulated TPM that could use a real TPM or KMIP server for a primary TPM key, stuff like ESX Enterprise do this to provide TPM services to VM's)

Quite interesting, thanks for the explanation, I wonder how to find out which specific type one might have.

3 hours ago, Steven P. said:

If you have a modern CPU (after Haswell, which is 4th gen) then you will most likely have it in your CPU. Most motherboard manufacturers have Trusted Computing turned off by default, this is my AORUS Z390 Pro WiFi board (which is 8th and 9th gen):

 

snag-0021.png

 

 

The TPM Module has additional hardware based encryption for your Windows install and data on the harddisks. If you have a TPM Module, then you will have to clear TPM each time you want to clean install Windows on your system. (I am still learning how it all works).

With all due respect, you are talking about an Intel CPU. With Intel's name being in the dump these days, it is safe to assume Intel PTT is not an option.

26 minutes ago, ManMountain said:

A lot of focus on TPM 2.0, but not so much on the CPU's that are not supported in Windows 11.  

 

AMD supported CPU

Intel supported CPU

wow I hadn't seen that yet, guess I should probably not be too ready to jump with my other machines

1 hour ago, Fleet Command said:

With all due respect, you are talking about an Intel CPU. With Intel's name being in the dump these days, it is safe to assume Intel PTT is not an option.

huh? Intel has had firmware TPM via PTT for generations now, and will continue to as it's standard now on both Intel and AMD (via their own firmware implementation)

1 hour ago, ManMountain said:

A lot of focus on TPM 2.0, but not so much on the CPU's that are not supported in Windows 11.  

 

AMD supported CPU

Intel supported CPU

 

 

WTF? My AMD FX-8320 is not supported? Windows can't even read my TPM state. I have a Gigabyte GA-990FXA-UD3 R5 (rev. 1.0) systemboard and no secure boot options I can see. I have tried setting Windows 8 for OS type and disabling CSM but no luck.

 

The board was a good deal at the time but there has been a total of one BIOS update for it. 🙄

 

Anyone with suggestions would be welcome.

Edited by Superuser

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Funny, but I didn't had the issue. All PC's at work are Dell and we had the culprit version of Support Assist for about 2 weeks until we got the new one. No problem at all. And for checking you can also use Dell Command Update, no need to search in windows settings. Just check the Upgrade History.
    • YES!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    • Apple are scared of their customers! They have built a brand over the years of "it just works out of the box", but that slows innovation. Samsung's master stroke was the Galaxy Ultra: "Let's cram everything into one handset, make it so stupid only real nerds will love it, some of the features will work, some won't, but the audience will have such a high tolerance they won't care". Apple has no such device and so they are constantly worrying these days about the fallout of creating a new experience that customers might not like. I know it is often cited the reason they don't build a touchscreen Mac Book is they don't want to cannibalise the the iPad market, but I think it's equally cold feet after the criticism Microsoft receive trying to make a touch compatible desktop OS
    • HandBrake 1.11.2 by Razvan Serea HandBrake is an open-source, GPL-licensed, multiplatform, multithreaded video transcoder, available for MacOS X, Linux and Windows. Handbrake can process most common multimedia files and any DVD or BluRay sources that do not contain any kind of copy protection. Here is a detailed breakdown of HandBrake’s features: Built-in Device Presets—Get started with HandBrake in seconds by choosing a profile optimized for your device, or choose a universal profile for standard or high quality conversions. Simple, easy, fast. For those that want more choice, tweak many basic and advanced options to improve your encodes. Supported Input Sources—Handbrake can process most common multimedia files and any DVD or Blu-ray sources that do not contain any kind of copy protection. Outputs: File Containers: .MP4(.M4V) and .MKV Video Encoders: H.265 (x265 and QuickSync), H.264(x264 and QuickSync), H.265 MPEG-4 and MPEG-2, VP8 and Theora Audio Encoders: AAC / HE-AAC, MP3, Flac, AC3, or Vorbis Audio Pass-thru: AC-3, E-AC3, DTS, DTS-HD, TrueHD, AAC and MP3 tracks Additional features: Title/ Chapter Selection Queue up Multiple Encodes Chapter Markers Subtitles (VobSub, Closed Captions CEA-608, SSA, SRT) Constant Quality or Average BitRate Video Encoding Support for VFR, CFR and VFR Video Filters—Deinterlacing, Decomb, Detelecine, Deblock, Grayscale, Cropping and Scaling Live Video Preview HandBrake 1.11.2 changelog: All platforms Video Fixed a crash that happened when doing a 2-pass lossless x265 encode Fixed a memory leak that happened when doing a 2-pass MPEG-4/MPEG-2/VP9/FFV1 encode Audio Updated the list of supported dithers and encoders combinations Fixed the Core Audio AAC encoder 7.1 channel layout Subtitles Fixed the VobSub palette creation in the MP4 container Build system Improved build system compatibility with older build tools Third-party libraries FFmpeg 8.0.2 (decoding and filters) SVT-AV1 4.1.0 (AV1 video encoding) Linux Added WebM MIME type to the list of the supported formats Mac Improved handling of unsupported presets Updated Sparkle automatic update library Windows Improved handling of unsupported presets Improved queue low space pause behaviour Fixed the automatic audio track name generation Fixed the summary description of HDR video Download: HandBrake 64-bit | Portable 64-bit | ~30.0 (Open Source) Download: HandBrake ARM64 | Portable Links: HandBrake Website | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • So, an article that has nothing to do with Windows 11, still gets Windows 11 in the title and a build number as the picture? Dell have a buggy build of Support Assist HP have UEFI settings that need unlocking for the secureboot cert upgrade to take place.
  • Recent Achievements

    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
    • Dedicated
      Conjor earned a badge
      Dedicated
    • Week One Done
      Windows Guy earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      493
    2. 2
      PsYcHoKiLLa
      243
    3. 3
      Steven P.
      72
    4. 4
      neufuse
      67
    5. 5
      ATLien_0
      67
  • Tell a friend

    Love Neowin? Tell a friend!