No TPM? No Windows 11 for you!


Recommended Posts

I'm about to throw in the towel myself... I have an ASRock Z370 Extreme4 with an i5 8600k 8th gen... I have everything enabled in the BIOS but still no go on the TPM requirement. The towel is going in.

 

 

20210625_231830.jpg

tpm.PNG

TMP2.PNG

 

__________________________________________++++++++++++++++++++++++++++++++++++++++_____________________________________________

 

I fixed it!!!! I found one more setting in my BIOS - Advanced/Trusted Computing --- Security Device Support - ENABLED ... FIXED!!!!!!!

 

TMPFixed.PNG

TPMFixed2.PNG

Edited by jbarcus81
  • Like 2

Got a request for how to activate Firmware TPM for the ASUS ROG STRIX Z390-H GAMING.  

 

First I am using BIOS firmware version 3002 Beta.  I've had no problems with it.

 

1.  Boot into BIOS

2.  If in EZ-Mode, F7 into Advanced Mode.

3.  Scroll down to PCH-FW Configuration and open, you'll see TPM Device Selection.

4.  Click on the drop down and select Firmware TPM.

5.  F10 to save changes and reboot PC.

6.  Check Device Manager and look for Security Devices

7.  Click to open -  it should have Trusted Platform Module 2.0 

8.  Or you can - Open run command by pressing Windows + R and type tpm.msc and hit enter.
     This command will open the Trusted management console Management.

9.  Done.

1 hour ago, SidVicious said:

On my PC the TPM is present...but my Ryzen 5 2400G is not supported.
######.

I really wonder what the reason is for requiring relatively new CPUs, what does 8th gen Intel have that 7th gen doesn't?

2 hours ago, Steven P. said:

I really wonder what the reason is for requiring relatively new CPUs, what does 8th gen Intel have that 7th gen doesn't?

I'm hardly an expert but I'd say it's most likely related to all the work they've had to do on Spectre and Meltdown and similar attacks.

On my couch computer almost everything passes except the CPU ... lol ...######! i5-7600 3.50 ghz 32GB Ram, TPM 2.0, 1TB NVME . ... but Nope can't run windows 11. It's so stupid, it's comical. 

1 minute ago, warwagon said:

Almost on my couch computer passes except the CPU ... lol ...######! i5-7600 3.50 ghz 32GB Ram, TPM 2.0, 1TB NVME . ... but Nope can't run windows 11. It's so stupid, it's comical. 

Probably blind positivity, but I'd be surprised if there isn't a very simple and easy-to-do patch even for the final version of Windows 11.

9 hours ago, Raze said:

Got a request for how to activate Firmware TPM for the ASUS ROG STRIX Z390-H GAMING.  

 

First I am using BIOS firmware version 3002 Beta.  I've had no problems with it.

 

1.  Boot into BIOS

2.  If in EZ-Mode, F7 into Advanced Mode.

3.  Scroll down to PCH-FW Configuration and open, you'll see TPM Device Selection.

4.  Click on the drop down and select Firmware TPM.

5.  F10 to save changes and reboot PC.

6.  Check Device Manager and look for Security Devices

7.  Click to open -  it should have Trusted Platform Module 2.0 

8.  Or you can - Open run command by pressing Windows + R and type tpm.msc and hit enter.
     This command will open the Trusted management console Management.

9.  Done.

The problem is that many people might have the supported CPU (i've got a 6th gen which should support PTT but doesn't pass the Windows 11 requirements) but don't even have the PCH-FW Configuration option in their Asus BIOS.   

 

It seems that even if you have the same chipset as others some board makers have left things out depending on the model, if you have one of the higher end boards you might have it, one of the base models though, might not.  

 

Anyways, I'll just stay on Windows 10 till I'm ready for a new gaming system.   Next one is going to be a smaller case, don't need another full tower.

If it's not this, it will probably be something else that get people as a whole to largely reject Win11 given Microsoft's rep over the long term. because Microsoft has a pattern of good/bad/good/bad with OS's (for a long time now (ill just start from when PC's pretty much went mainstream)) which, if the pattern holds, Win11 will be part of the 'bad' group....

 

Win98(good)/WinME(bad)/WinXP(good)/WinVista(bad)/Win7(good)/Win8(bad)/Win10(good)... Win11(bad(?)).

 

p.s. I am not counting Win2k because while it was a good OS the average person could use, it was never targeted at the common user, so I did not count it. if I did, it would have broke the pattern. also, while Vista was not bad after a while, and apparently the same with Win8, those OS's were largely rejected by the masses since people generally stuck to WinXP, and the newer OS people who moved past WinXP generally stuck with Win7 until people were forced to something newer which, to state the obvious, is the current Win10, which is the only real choice for Windows users at this point.

Put yourself in the common user. Just your average person firing up their PC they bought from Dell or wherever with decent specs maybe in the last year or two finding out they're stuck with Windows 10. The kicker for me is this average person may actually be able to upgrade but have to do some BIOS tweaks which they will have no clue how to do. I see this as a customer service nightmare for OEMs and Microsoft. I understand security is a priority but you kinda have to 'dumb it down' a bit. Hell it took me days to finally get the right settings enabled in my BIOS and I've been building and tweaking computers for 20+ years.

We're so early into this new version so who knows what they'll do.  I've been keeping track of a poll over on Windows Central asking if users systems qualify for Windows 11, and so far 44% say no, 30% say yes, with the rest in this weird "maybe" or "not sure" area.   As time passes the No's keep going up I've noticed.   I'm in the No group, no TPM and I've got a 6th gen CPU.  Also, due to some old hardware, hdds maybe?  I can't boot into windows without BIOS compatibility mode on. 

 

I've messed with different settings just to see what happens and yeah.   I'll be on Windows 10 for now, maybe I'll build a new system next year, by then MS will be on Windows 11.1 or w/e new versioning they're going to go with.

 

Or you can just upgrade from an ISO without having TPM and 8th+ gen and all this panic is for nothing, we'll see.   I say this because technically MS's own Surface Studio 2 doesn't qualify, as per their CPU lists don't know about TPM, yet I've seen posts from people who've installed 11 on it already.   

I'm wondering why so many people need a new Microsoft OS. First of all I like to remind everyone that absolutely nothing it's really free. Somehow you pay, more or less. This TPM requirement it's for security but not the way you're thinking. All the conspiracy theories are becoming so true this days. Look what data about TPM still holds on Wikipedia:

 

"Criticism

TCG has faced resistance to the deployment of this technology in some areas, where some authors see possible uses not specifically related to Trusted Computing, which may raise privacy concerns. The concerns include the abuse of remote validation of software (where the manufacturer‍—‌and not the user who owns the computer system‍—‌decides what software is allowed to run) and possible ways to follow actions taken by the user being recorded in a database, in a manner that is completely undetectable to the user.

The TrueCrypt disk encryption utility, do not support TPM. The original TrueCrypt developers were of the opinion that the exclusive purpose of the TPM is "to protect against attacks that require the attacker to have administrator privileges, or physical access to the computer". The attacker who has physical or administrative access to a computer can circumvent TPM, e.g., by installing a hardware keystroke logger, by resetting TPM, or by capturing memory contents and retrieving TPM-issued keys. As such, the condemning text goes so far as to claim that TPM is entirely redundant.

Attacks

In 2010, Christopher Tarnovsky presented an attack against TPMs at Black Hat Briefings, where he claimed to be able to extract secrets from a single TPM. He was able to do this after 6 months of work by inserting a probe and spying on an internal bus for the Infineon SLE 66 CL PC.

In 2015, as part of the Snowden revelations, it was revealed that in 2010 a US CIA team claimed at an internal conference to have carried out a differential power analysis attack against TPMs that was able to extract secrets.

In 2018, a design flaw in the TPM 2.0 specification for the static root of trust for measurement (SRTM) was reported (CVE-2018-6622). It allows an adversary to reset and forge platform configuration registers which are designed to securely hold measurements of software that are used for bootstrapping a computer. Fixing it requires hardware-specific firmware patches.[54] An attacker abuses power interrupts and TPM state restores to trick TPM into thinking that it is running on non-tampered components.

Main Trusted Boot (tboot) distributions before November 2017 are affected by a dynamic root of trust for measurement (DRTM) attack CVE-2017-16837, which affects computers running on Intel's Trusted eXecution Technology (TXT) for the boot-up routine.

In case of physical access, computers with TPM are vulnerable to cold boot attacks as long as the system is on or can be booted without a passphrase from shutdown or hibernation, which is the default setup for Windows computers with BitLocker full disk encryption."

Full article: https://en.wikipedia.org/wiki/Trusted_Platform_Module

I'm the sad owner of two PCs (one bought in mid-2017 and one in early-2018) that both have TPM 2.0 but are 7000 series Intel processors. Both say they will not run Windows 11 due to its processor requirements. Waiting for clarification on some of the speculation around supported vs. will run of course, but not holding my breath.

 

Remember Windows Vista Basic and the inability of many machines to run Aero (even machines sold post-Vista with a Basic sticker)? Something about this makes me think of that (maybe the fact that my existing PCs at the time were not going to run Aero). How about Windows 8.1 Update 3 for RT? I wonder if Microsoft will throw us some crappy bone with a Windows 10 update that brings down a few of the Windows 11 features. Either way - both Vista Basic and 8.1 Update 3 sucked :)

Mine passes all but secure boot, I go into Bios and is says secure boot enabled. Asus Z97-A MB. I'll check for a new version of BIOS but I don't think there is one that would make a difference. I know it's an old MB but hey works for my needs. BIOS ver. 2.16.1240.

Maybe then never/ever changing win10 is all I'll get until I feel like a rebuild.

On 24/06/2021 at 16:24, ManMountain said:

A lot of focus on TPM 2.0, but not so much on the CPU's that are not supported in Windows 11.  

 

AMD supported CPU

Intel supported CPU

 

 

Yeah My Core i5 - 4460 is not supported. So, I guess it doesn't matter that I also don't have TPM.  I just think it's funny that my 3.2 GHz processor isn't good enough because of its generation, but all these Celeron processors are just fine.

35 minutes ago, devHead said:

Yeah My Core i5 - 4460 is not supported. So, I guess it doesn't matter that I also don't have TPM.  I just think it's funny that my 3.2 GHz processor isn't good enough because of its generation, but all these Celeron processors are just fine.

Since the Celeron 4xxx processors listed are mostly built with the same stuff the 8th gen Core processors are, yeah, they are.

 

https://ark.intel.com/content/www/us/en/ark/products/codename/97787/products-formerly-coffee-lake.html

 

(and the others are probably fairly similar - https://ark.intel.com/content/www/us/en/ark/products/codename/83915/products-formerly-gemini-lake.html + https://ark.intel.com/content/www/us/en/ark/products/codename/126287/products-formerly-kaby-lake-r.html )

On 26/06/2021 at 20:25, Randomevent said:

I'm hardly an expert but I'd say it's most likely related to all the work they've had to do on Spectre and Meltdown and similar attacks.

You may be on to something and that would be another boost to security.

 

On 27/06/2021 at 03:56, ThaCrip said:

If it's not this, it will probably be something else that get people as a whole to largely reject Win11 given Microsoft's rep over the long term. because Microsoft has a pattern of good/bad/good/bad with OS's (for a long time now (ill just start from when PC's pretty much went mainstream)) which, if the pattern holds, Win11 will be part of the 'bad' group....

 

Win98(good)/WinME(bad)/WinXP(good)/WinVista(bad)/Win7(good)/Win8(bad)/Win10(good)... Win11(bad(?)).

 

p.s. I am not counting Win2k because while it was a good OS the average person could use, it was never targeted at the common user, so I did not count it. if I did, it would have broke the pattern. also, while Vista was not bad after a while, and apparently the same with Win8, those OS's were largely rejected by the masses since people generally stuck to WinXP, and the newer OS people who moved past WinXP generally stuck with Win7 until people were forced to something newer which, to state the obvious, is the current Win10, which is the only real choice for Windows users at this point.

Yeah, I don't see Windows 11 being largely rejected like Windows ME, Vista, and 8. Those were versions one had to pay for to upgrade which is not the case with Windows 11 so those that qualify will probably upgrade. A lot of eople would buy new machines with ME, Vista, and 8 and install the previous version of Windows. I don't see that happening at all with PCs that come with Windows 11. Windows 11 is really a minor upgrade over Windows 10 except for the laying of the ground work for better security of the platform.

 

2 hours ago, novv said:

I'm wondering why so many people need a new Microsoft OS. First of all I like to remind everyone that absolutely nothing it's really free. Somehow you pay, more or less. This TPM requirement it's for security but not the way you're thinking. All the conspiracy theories are becoming so true this days. Look what data about TPM still holds on Wikipedia:

 

"Criticism

TCG has faced resistance to the deployment of this technology in some areas, where some authors see possible uses not specifically related to Trusted Computing, which may raise privacy concerns. The concerns include the abuse of remote validation of software (where the manufacturer‍—‌and not the user who owns the computer system‍—‌decides what software is allowed to run) and possible ways to follow actions taken by the user being recorded in a database, in a manner that is completely undetectable to the user.

The TrueCrypt disk encryption utility, do not support TPM. The original TrueCrypt developers were of the opinion that the exclusive purpose of the TPM is "to protect against attacks that require the attacker to have administrator privileges, or physical access to the computer". The attacker who has physical or administrative access to a computer can circumvent TPM, e.g., by installing a hardware keystroke logger, by resetting TPM, or by capturing memory contents and retrieving TPM-issued keys. As such, the condemning text goes so far as to claim that TPM is entirely redundant.

Attacks

In 2010, Christopher Tarnovsky presented an attack against TPMs at Black Hat Briefings, where he claimed to be able to extract secrets from a single TPM. He was able to do this after 6 months of work by inserting a probe and spying on an internal bus for the Infineon SLE 66 CL PC.

In 2015, as part of the Snowden revelations, it was revealed that in 2010 a US CIA team claimed at an internal conference to have carried out a differential power analysis attack against TPMs that was able to extract secrets.

In 2018, a design flaw in the TPM 2.0 specification for the static root of trust for measurement (SRTM) was reported (CVE-2018-6622). It allows an adversary to reset and forge platform configuration registers which are designed to securely hold measurements of software that are used for bootstrapping a computer. Fixing it requires hardware-specific firmware patches.[54] An attacker abuses power interrupts and TPM state restores to trick TPM into thinking that it is running on non-tampered components.

Main Trusted Boot (tboot) distributions before November 2017 are affected by a dynamic root of trust for measurement (DRTM) attack CVE-2017-16837, which affects computers running on Intel's Trusted eXecution Technology (TXT) for the boot-up routine.

In case of physical access, computers with TPM are vulnerable to cold boot attacks as long as the system is on or can be booted without a passphrase from shutdown or hibernation, which is the default setup for Windows computers with BitLocker full disk encryption."

Full article: https://en.wikipedia.org/wiki/Trusted_Platform_Module

Thanks for that Wikipedia research. LOL No one is saying TPM means perfect security but a system with secure boot and TPM are more secure than a box without those.

Never understood the good bad thing, because it ignores some information, for example, windows 98SE was when it was actually good,  Windows 2000 - good, I know it was a separate NT product bust still, also XP wasn't regarded as great until a couple of service packs were released and despite the horrible start screen, Windows 8.1 was very stable.

  This, if released as it stands now will invoke the consumer backlash far greater than the backlash during Vista or Windows 8 era, IMHO. 

  Microsoft is making a pigheaded move and not he first one either. Instead of requiring only from the OEM's and hardware vendors that all of their future products targeted for Windows 11 come with TPM 2.0 and let the hardware switch come naturally, they are punishing, by my educated guess, more than 50% of Windows users.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Windows 11 is a big thumbs down from me. I used for a period of a few days while it was in insider and windows 10 was the main OS, and realised it wasn't for me. I am still waiting for Windows to be tolerable again, a shame as at one point I was very pro Microsoft.  
    • Classic outlook, not only does it have a much fuller feature set, it doesn't include Microsoft attempting to sync my emails from my servers to theirs. If classic outlook is ever removed from office, and the version I paid for in 2021 stops working for some reason, I'll use Thunderbird.
    • Kdenlive 26.04.2 by Razvan Serea Kdenlive is an acronym for KDE Non-Linear Video Editor. It works on GNU/Linux, Windows and BSD. Through the MLT framework, Kdenlive integrates many plugin effects for video and sound processing or creation. Furthermore Kdenlive brings a powerful titling tool, a DVD authoring (menus) solution, and can then be used as a complete studio for video creation. Kdenlive supports all of the formats supported by FFmpeg or libav (such as QuickTime, AVI, WMV, MPEG, and Flash Video, among others), and also supports 4:3 and 16:9 aspect ratios for both PAL, NTSC and various HD standards, including HDV and AVCHD. Video can also be exported to DV devices, or written to a DVD with chapters and a simple menu. Video editing features: Multi-track editing with a timeline and supports an unlimited number of video and audio tracks. A built-in title editor and tools to create, move, crop and delete video clips, audio clips, text clips and image clips. Ability to add custom effects and transitions. A wide range of effects and transitions. Audio signal processing capabilities include normalization, phase and pitch shifting, limiting, volume adjustment, reverb and equalization filters as well as others. Visual effects include options for masking, blue-screen, distortions, rotations, colour tools, blurring, obscuring and others. Configurable keyboard shortcuts and interface layouts. Rendering is done using a separate non-blocking process so it can be stopped, paused and restarted. Kdenlive also provides a script called the Kdenlive Builder Wizard (KBW) that compiles the latest developer version of the software and its main dependencies from source, to allow users to try to test new features and report problems on the bug tracker. Project files are stored in XML format. An archiving feature allows exporting a project among all assets into a single folder or compressed archive. Built-in audio mixer Kdenlive 26.04.2 changelog: Remove not needed actions from render info, fix rough size calculation for rendering. Fix clip sometimes not inserted in timeline when moving vertically in bin drag. Fix transcoding from clip properties. Cleanup render profile audio quality. Use percent based value for audio quality, and adjust the range accordingly per codec. Fixes bug #520750 Enforce even numbers for render width/height. Fixes bug #520737 Fix nightly flatpak - disable rnnoise until implemented. Fix missing initialization. Edit mediacapture.cpp. Fix document unnecessarily marked as modified on opening, triggering a backup request. Fix incorrect detection of missing and remote clips causing unwanted backups. Fixes issue #2194 Fix tests. Fix tmp files copied to wrong location when setting project folder. Fixes bug #467740 Fix color clips not selected on creation. Use QFileInfo instead of QUrl/QDir to try fixing Windows shared drives. Fixes bug #451413 Fix timeline preview incorrectly invalidated when a track with effect duration changed. Fixes bug #514541 Fix missing var. Display paths in native format in render widget. Fixes bug #520428 Simple splash: fix pressing return always triggered the same button. Minor update to simple splash. Fix unwanted clips added to timeline and cleanup. Fixes issue #2190 Minor layout improvements to welcome screen, add Quit and Open shortcuts. Fix broken welcome dialog layout in tiling compositors. (craft) Limit the number of CPU cores used during a Windows build with mingw as some .cpp files are memory intensive to build. (kde-ci) Limit the number of CPU cores used during a build as some .cpp files are memory intensive to build. (kde-ci) Cleanup old entries. Another fix for animation crash. Fix uninitialized function - crash on create animation. Another attempt to fix MacOS permissions. MacOS: fix bundle release version. Fix MacOS plist path. Fix MacOS build. Explicitely link against Qt::Core. Download: Kdenlive 26.04.2 | 128.0 MB (Open Source) Download: Standalone Executable View: Kdenlive Home page Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Here's how to watch the Xbox Games Showcase today and what to expect by Pulasthi Ariyasinghe The June games showcase week has been a packed one, with everything from major presentations like Sony and Summer Game Fest to indie-focused reveals coming in almost every day. Now, it's almost time for another big one, with Microsoft bringing its Xbox Games Showcase back later today. This is a double feature too, with a Gears of War E-Day deep dive also being attached to it. For anyone wanting to tune in online, the 2026 Xbox Games Showcase is kicking off at 10 AM PT | 1 PM ET | 6 PM BST | 7 PM CEST later today, June 7. The event will be available to watch on the official Xbox YouTube (4K 60FPS), Twitch, Facebook, Steam, Amazon Live, and other portals. Separate livestreams for American Sign Language and Audio Description will also be available. "This year marks 25 years of XBOX, and this Showcase is poised to be a true celebration, offering world premieres, new gameplay, fresh updates, and more for a swathe of projects we cannot wait to share," said Microsoft about this presentation. With a new CEO behind it that is pulling off some interesting moves, Xbox may have some surprises to reveal today. New looks at first-party games like Halo Campaign Evolved from Halo studios, Fable from Playground Games, InXile Entertainment's Clockwork Revolution, Mojang's Minecraft Dungeons II, and Call of Duty: Modern Warfare 4 from Infinity Ward are to be expected here. We may finally get to see the new Blade from Arcane Studios in action and a new Persona game from Atlus at the showcase too. Surprise announcements may also arrive from other Microsoft-owned studios like Bethesda, MachineGames, Ninja Theory, Obsidian, Rare, World's Edge, or Blizzard. Considering how every new release nowadays is staying away from November and December to avoid Grand Theft Auto VI's release, any launch dates Microsoft announces will probably skip those months as well. Once the Xbox Games Showcase ends, Microsoft will immediately kick off the Gears of War: E-Day Direct. This deep dive into the upcoming prequel from The Coalition should attach gameplay footage and perhaps a release window to the highly anticipated project.
    • People in the '50s and '60s had the same attitude, and we're still here over a half century later.
  • Recent Achievements

    • Week One Done
      Windows Guy earned a badge
      Week One Done
    • Dedicated
      Mark Spruce earned a badge
      Dedicated
    • Collaborator
      conkir earned a badge
      Collaborator
    • Rising Star
      olavinto went up a rank
      Rising Star
    • One Month Later
      lamborghiniv10 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      479
    2. 2
      PsYcHoKiLLa
      250
    3. 3
      Steven P.
      74
    4. 4
      FloatingFatMan
      69
    5. 5
      +Edouard
      69
  • Tell a friend

    Love Neowin? Tell a friend!