With Windows 11, some PCs may be left behind because of TPM, and it's causing a lot of confusion
Why is TPM a thing, and what does it mean for getting that Windows 11 upgrade later this year? Let's find out.
As we remarked a week ago, Windows 11 turned out to be much more than just a new Start menu. The new store, Android apps, Direct Storage, Auto HDR, new touch UX, and new forthcoming features, such as haptic pens, make Windows 11 a significant overhaul of the six-year-old Windows 10.
But one item we did not anticipate when it came to major Windows 11-related changes was the apparent cutoff for which PCs can get the free Windows 11 upgrade. That topic is causing a lot of confusion. Here is what we know and what we don't know about it.
Why have TPM requirements at all?
It is clear Microsoft is positioning Windows 11 as its next major OS for the upcoming decade. While it is not a clean break from Windows 10, some older PCs will not make the cut.
The big motivator here seems to be security, as Microsoft explained recently in a blog post.
TPM (Trust Platform Module) is nothing new for PCs. It goes back to the mid-2000s as an international standard for a secure cryptoprocessor. Although there are software versions, too, like fTPM, TPM is a physical hardware chip used to store encrypted information while also ensuring a secured boot environment.
In the real world, TPM allows for things like:
- BitLocker Drive Encryption
- Windows Hello PINs and biometrics
- Windows Defender System Guard (opens in new tab)
- Tamper detection of the PCs hardware
- Virtual Smart card
- Credential Guard
- Secure Boot
With TPM, BitLocker gets to store the encryption key and your Windows Hello biometrics securely. This ability is why Windows Hello is so protected. Your biometrics, like fingerprints or facial recognition data, do not go to the cloud; instead, they get hardware encrypted on your PC so that info cannot be retrieved nor reversed engineered to bypass your PC's login process.
Secure boot is becoming increasingly important, too. From Microsoft's documentation (opens in new tab):
Microsoft is drawing a line on security and saying that to use Windows 11 PCs going forward, you need to have this feature enabled.
The good news is TPM 1.2 (more on that below) goes back to 2005. TPM 2.0 goes back to 2015, and most PCs are supposed to ship with it, although that does not always seem to be the case, especially if you build your own.
I realize that this is all just techno mumbo jumbo for many consumers, but Windows PCs have had a long history of security issues. Microsoft has gone to great lengths since Windows 10 to secure its OS as much as possible, and Windows 11 takes a more rigid stance.
What is required for Windows 11?
Even the requirements for Windows 11 are a bit confusing as there are both "hard" and "soft" floors of cutoffs for the update. Many PC makers are also now giving guidance on which PCs will get it.
Update: Soon after this article was published, Microsoft removed the hard/soft floor distinction for Windows 11. The changes seem to merge the two where you can have just a 1GHz CPU, but it has to be on the supported list. TPM 1.2 is no longer mentioned.
The hard floor is what most people who have older PCs should be looking at. If your PC does not meet these standards, you cannot get Windows 11. In addition, the hard floor requires "greater or equal" to TPM 1.2, Secure Boot capable, 4GB of RAM, 64GB of storage, and at least a dual-core processor that is faster than 1GHz.
Those are hardly strict requirements for a forward-looking OS in 2021.
The soft floor requires TPM 2.0 (which started shipping in all PCs around 2016/2017) and needs specific processors. These are devices that are free to update with no caveats.
The soft floor seems to be what Microsoft's PC Health Check app is looking at and where a lot of confusion is happening.
Indeed, the more significant issue here may not be TPM requirements, but the fact that any Intel CPU older than 8th Gen does not make the cut for Windows 11. Unfortunately, that includes a lot of Surface devices, including Surface Studio 2 and Surface Pro 5. That caveat does not mean those computers can't run Windows 11; it just means Microsoft does not support them running Windows 11. It is an important distinction.
Gaming PCs and TPM: present (but not enabled)
One issue that will be hard to navigate for the entire upgrade process is that many gaming PCs have TPM on the motherboard (it is a physical chip, after all), but it is not enabled. For example, this was the case on my CLX gaming PC, which initially failed Microsoft's check for Windows 11 compatibility.
The solution was to go into the BIOS and enable secure boot and Intel Platform Trust Technology (PTT). It took 30 seconds, and my PC is now Windows 11 compliant, which is reasonable considering it is a brand new 2021, $7,500 computer!
As you can see, the problem is some PCs have the hardware, but it is not enabled. Microsoft's Health Check app does not qualify why your PC does not meet the requirements, although we have heard Microsoft will update the app soon to address that. It is also not clear that you can do a software check to see if your PC has TPM 2.0 in the event the module is present but disabled.
Here's the more significant issue: Does Microsoft want to send thousands (millions?) of people into their PC BIOS to start fiddling with security features? Again, you can see how that leaves room for a lot of problems.
At least for new PCs that sell Windows 11 pre-installed, this won't be a concern.
What happens if your PC does not have TPM 2.0 or a modern processor?
We don't know. Microsoft says (opens in new tab):
It sounds like if your computer has TPM 1.2 (which is incredibly old) and at least a 1GHz processor, you can still get Windows 11; it is just "not advised."
But what that process looks like is not known at this time. We expect Windows 11 to start rolling out in October through early 2022, like previous Windows updates. So my hunch is users can still take the Windows 11 upgrade, but there may be some warnings about it not being recommended.
To be clear, Windows 11 runs well on older hardware. It is not like older Intel 6th Gen processors cannot handle the OS — far from it. This discussion is all about security.
For those who build their gaming PCs, if your motherboard does not have TPM 2.0 you can buy the module ($30) and install it yourself. Just make sure your motherboard does not already have it since many modern motherboards do, even if it's not enabled.
Will Microsoft stick with Windows 11 requirements?
If I had to guess, Microsoft might modify some of these requirements and even the wording around Windows 11 as we advance. Right now, the scope of the "TPM problem" is not known, when it comes to how many PCs are out there with TPM in a disabled state.
Microsoft has four months to figure out how to address the issue. It could either relax requirements or let affected users take Windows 11 even after advising them against it.
In some ways, this debacle is unfortunate but not uncommon. Apple and Google routinely cut off hardware for new operating systems. My late 2017 Google Pixel 2 will not get Android 12 even though it can absolutely run it. Microsoft doing the same in the name of security is necessary to push standards forward, especially in an age of ransomware, where TPM plays one part in an increasingly growing security infrastructure.
How to check if your PC has a trusted platform module (TPM)
I think the bigger looming issue is not even TPM, but processor compatibility. Microsoft has done this in the past, but these are known as "soft blocks." For example, Windows 10 21H1 does not officially support Intel 4th Gen "Haswell" chips, but you can still run Windows 10 on those processors without issue. Microsoft appears to be doing the same here. There will be soft blocks for non-compatible CPUs, but you can still install Windows 11 on a Surface Pro 5; it just won't be "supported."
Regardless, I think it is evident that Microsoft needs to get clearer messaging around this update as there will be a lot of confusion in the future.
Windows Central Newsletter
Get the best of Windows Central in your inbox, every day!
Daniel Rubino is the Editor-in-chief of Windows Central, head reviewer, podcast co-host, and analyst. He has been covering Microsoft since 2007 when this site was called WMExperts (and later Windows Phone Central). His interests include Windows, laptops, next-gen computing, and for some reason, watches. Before all this tech stuff, he worked on a Ph.D. in linguistics, watched people sleep (for medical purposes!), and ran the projectors at movie theaters because it was fun.
Should the Surface Go pass the health checks and I should be able to install Windows 11?
- TPM chip
- Processor Model
- Secure Boot By default, TPM setting is enabled if that's on their motherboard.
On the other hand, that's precisely why I can't believe this is the requirement. There is no way MS is going to launch Windows 11 in a way that it only works on new machines and for Enterprise.... right?
My desktop PC is an HP Envy 23 Recline All-in-One that came with Windows 8 and doesn't have any TPM version at all (just UEFI/secure boot). Runs Windows 10 perfectly fine but won't be able to update to Windows 11, so why would we be happy about this?
Windows XP - successful
Windows Vista - failed
Windows 7 - successful
Windows 8,8.1 - failed
windows 10 - successful
windows 11 - failed
Not to mention the pos of the arm architecture.
There's a reason why tech websites like Windows Central are alerting people for this.
But let's wait for the final requirements to be decided. As it stands, millions of PCs won't be able to update and that can't be good news to Microsoft.
Microsoft made obsolete computers from just 3 years ago.
Also nobody changes from PC to Mac or viceversa for that reason alone...
Microsoft will Modify Windows 11 to operate on Older computers but warn folks they wont be
able to use all the features it has to offer. I want to buy or build a new Computer anyway so
it's not a big deal to me but I hope those companies that sell new Motherboards point out
which Motherboards are Windows 11 capable or not so us PC builders do not buy a dud board.
Windows 10 will get support till 2025. theres no hurry to jump Windows 11. some folks
can save up to buy a new PC or CPU/mother board combo
will modify windows 11 to operate on Older Computers. My Computer is not rated to run
windows 10 but it does. It's a refurbased PC Dell did not certify to run Windows 10 it's best to
run windows 8.1 on it which Microsoft will support for another 1 & half years. I have a disk to
put windows 8.1 on it but I wont
Laptop 1 which, according to current information, is not compatible with Windows 11. So this morning I bought a Satin Black Laptop 3 i5 256, taken from #MediaWorld (Italy) with a big discount: € 965. If then, later, Microsoft will also be able to wake up Windows 11 for laptop 1 I will be even happier!
As have been said before by other people, this is all about getting people to buy new computers, computer manufactures are in bed with Microsoft and while sales of computers went up this year, I doubt sales will stay like it for long. so if people are told they have to get a new computer to run Windows 11, that what some of them will do.
The ones with a bit more sense will say stuff it and either carry on with what they have got, or if they are a bit more knowledgable will try to get Windows 11 working on their machine. I don't like the look of Windows 11, so I can not see myself updating, I may update my computer in the next 12 months or more, but I am thinking of going to the other side and maybe getting a Mac mini, I will still keep this one.