this post was submitted on 29 Sep 2025
8 points (90.0% liked)

Windows 11

1101 readers
1 users here now

Welcome to the community for Windows 11, Microsoft's latest computer operating system.

Rules:

founded 2 years ago
MODERATORS
 

So I'm getting round to preparing my PC for Windows 11, and I just have to activate TPM 2.0. I have found it in UEFI BIOS and went to activate it and this warning came up. Where can I find/set the firmware TPM key.

I'd rather know this before activating TPM, than get caught with my pants down at a later date.

top 5 comments
sorted by: hot top controversial new old
[–] Telorand@reddthat.com 4 points 2 weeks ago (1 children)

The whole point of the TPM is that the encryption keys are securely stored on the device. There's nowhere you can "get them," and keys are set automatically.

What it looks like it's saying is that if you decide to use the optional BitLocker, the encryption keys will be stored in the TPM. If you were to replace your motherboard (or the TPM board, if it's a separate hardware device), you would only be able to recover your Windows drive if you had "the recovery key."

I've never bothered with BitLocker, but I would suspect that they'll generate a recovery key for you in the event you need to decrypt your device manually later on.

[–] LordOfLocksley@lemmy.world 2 points 2 weeks ago (2 children)

Ok thanks, so nothing for me to securely store. I'll proceed with the activation then.

[–] Telorand@reddthat.com 1 points 2 weeks ago (1 children)

If it's any consolation, I have an AMD processor with an fTPM (their version of TPM on the CPU), and I didn't have any issues upgrading to Win 11 Pro. BitLocker is optional, so if you don't plan to encrypt your drive, I wouldn't worry about it.

Most likely, they're just covering their asses in the event somebody upgrades their hardware and gets locked out of their boot drive.

[–] LordOfLocksley@lemmy.world 1 points 1 week ago

Thanks, thought it may just be a arse covering clause

[–] AlexisFR@jlai.lu 1 points 1 week ago

Can confirm, if you enable bit locker, it'll force you into saving the recovery key!