فا
MSLicenseHub

TPMTrusted Platform Module

Category: general

Last reviewed by the MSLicenseHub Licensing Desk.

A Trusted Platform Module (TPM) is a specialized, tamper-resistant hardware integrated circuit—either a dedicated physical chip or a firmware-based implementation—designed to provide a hardware-based foundation for security operations. In the Microsoft ecosystem, it acts as a secure vault for cryptographic keys, digital certificates, and system measurements, ensuring that sensitive data remains protected even if the operating system is compromised or the physical storage media is removed.

Technical Integration and Functionality

The TPM serves as the "root of trust" for several core Windows security features. While its primary role is the secure generation and storage of cryptographic keys, its practical applications within Microsoft environments include:

  • BitLocker Drive Encryption: Stores the volume master key so the drive cannot be decrypted if moved to a different machine.
  • Windows Hello for Business: Protects the biometric data or PINs used for passwordless authentication.
  • Credential Guard: Isolates secrets so that only privileged system software can access them, preventing "pass-the-hash" attacks.
  • Measured Boot: Records the state of the boot chain (firmware, bootloader, and drivers) to ensure the system has not been tampered with by rootkits or malware before the OS loads.

Microsoft Licensing and System Requirements

The significance of the TPM shifted from "optional security enhancement" to "mandatory platform requirement" with the release of Windows 11. TPM version 2.0 is a strict hardware requirement for Windows 11. While Windows 10 supported TPM 1.2, Microsoft’s modern lifecycle policy necessitates TPM 2.0 for all official installations of the current operating system.

It is important to note that while the TPM is a hardware requirement, it is not a "licensed feature" that you purchase via a Volume Licensing agreement. Instead, it is a hardware prerequisite for the software to be legally and technically supported. You will not see "TPM" as a line item on a Microsoft Product Terms document or a MPSA/CSP invoice; rather, it appears in the Windows Minimum Hardware Requirements documentation referenced by those agreements.

Common Misunderstandings

  • TPM vs. BitLocker Licensing: While BitLocker requires a TPM for maximum security, the right to use BitLocker is determined by the Windows edition (Pro, Enterprise, or Education), not the presence of the chip itself.
  • Discrete vs. Firmware: A TPM does not always have to be a physical chip (dTPM); many modern CPUs include firmware-based TPMs (fTPM or Intel PTT) that satisfy Microsoft's requirements.
  • OEM vs. Retail: Because the TPM is hardware, it is intrinsically linked to the OEM (Original Equipment Manufacturer) license. If a device lacks a TPM 2.0 module, you cannot simply buy a retail Windows 11 license to bypass the requirement; the hardware itself must be compliant.

Practical Buying Advice

When procuring new hardware, ensure the specification explicitly states TPM 2.0 Enabled. Many enterprise-grade desktops and laptops ship with the TPM present but disabled in the BIOS/UEFI to comply with specific international shipping regulations. IT departments must ensure the TPM is toggled to "On" or "Enabled" during the imaging process, or Windows 11 deployment will fail. For organizations using Autopilot or Intune for deployment, a functional TPM 2.0 is essential for device attestation and automated provisioning.

Related Terms

Secure Boot A security standard that ensures a device boots using only software that is trusted by the OEM.
UEFI The modern interface between the operating system and platform firmware, which manages the TPM.
OEM License The Windows license pre-installed by the manufacturer, which is permanently tied to the specific hardware and its TPM.

Need this in a quote?

Our team translates glossary concepts into concrete licenses, part numbers and price lists.

Request a quote