Modern computers use one of two main firmware systems to start up and communicate with hardware: UEFI (Unified Extensible Firmware Interface) or Legacy BIOS (Basic Input/Output System). Understanding the difference between these two systems helps explain why boot settings matter and how TPM 2.0 fits into the picture.
Free Guide to Balance Exercises and Fall Prevention →
Legacy BIOS has been around since the 1980s and was the standard way computers started for decades. When you turn on a computer with Legacy BIOS, the firmware performs basic hardware checks, then looks for a bootable device like a hard drive or USB stick. Legacy BIOS uses a Master Boot Record (MBR) to store information about where the operating system is located. This system works reliably but has limitations—it can only recognize hard drives up to about 2.2 terabytes in size, and it doesn't include built-in security features.
UEFI is the newer replacement for Legacy BIOS. It was developed starting in the late 1990s and has become standard on computers manufactured in the last ten years. UEFI provides several advantages over Legacy BIOS: it supports much larger hard drives (more than 9 zettabytes), it boots faster, and it includes security features like Secure Boot. UEFI uses a GUID Partition Table (GPT) to store partition information instead of the older MBR system.
Many computers sold today actually support both UEFI and Legacy BIOS modes for backward compatibility. This is called CSM (Compatibility Support Module). However, if you want to use TPM 2.0 and Secure Boot together—which is increasingly important for security—UEFI mode is required. Legacy BIOS cannot work with TPM 2.0 or Secure Boot, even though it might be available on the same computer.
The practical difference you'll notice: UEFI firmware screens look more modern with graphics and mouse support, while Legacy BIOS is text-based and uses only the keyboard. UEFI also typically has more detailed security options available in the settings.
Practical Takeaway: Check your computer's current firmware mode by looking at your system settings. On Windows, you can open System Information and look for "BIOS Mode"—if it says UEFI, your system is ready for TPM 2.0. If it says Legacy, you may need to change this setting in firmware before enabling TPM features.
TPM stands for Trusted Platform Module, and version 2.0 is the current standard used in modern computers. A TPM 2.0 is essentially a small security chip built into your computer's motherboard (or sometimes integrated into the processor itself). Think of it as a dedicated security device whose only job is to protect sensitive information and verify that your computer hasn't been tampered with.
Learn About Shipping Protection Options Guide →
The TPM 2.0 chip stores cryptographic keys—long strings of characters used in encryption—and performs security operations directly on the chip itself. This means sensitive encryption keys never exist in your computer's main memory where they could potentially be stolen. The chip operates independently from your main processor, so even if someone gains control of your Windows operating system or other software, they cannot directly access what's stored on the TPM.
One of the main functions of TPM 2.0 is called measured boot. During the startup process, TPM 2.0 measures (creates a digital fingerprint of) each component as it loads—the UEFI firmware, bootloader, and operating system kernel. These measurements are stored in special registers called PCRs (Platform Configuration Registers). If any of these components have been changed or corrupted, the measurements won't match what's expected, alerting you to a potential problem.
TPM 2.0 also plays a key role in Windows encryption features. Windows 11 uses TPM 2.0 to store the encryption keys for BitLocker, which encrypts your hard drive. The encryption keys are sealed to the TPM, meaning the keys are locked away and can only be accessed when the TPM verifies that your computer's firmware and operating system are in their expected state. If someone removes your hard drive and tries to access it from a different computer, BitLocker encryption prevents them from reading your data because the encryption keys remain locked in the original TPM.
Different manufacturers implement TPM 2.0 in slightly different ways. Some computers have a discrete TPM chip (a separate physical chip on the motherboard), while others have the TPM integrated into the processor. Both approaches meet the TPM 2.0 specification and provide equivalent security. What matters is that TPM 2.0 is present and enabled.
Practical Takeaway: To check if your computer has TPM 2.0, open Windows PowerShell as administrator and type the command: Get-WmiObject -Namespace "root\cimv2\security\microsofttpm" -Class Win32_Tpm. If TPM 2.0 is present, you'll see information about it. If nothing appears, TPM 2.0 may not be installed or enabled in your firmware settings.
To enable TPM 2.0 and adjust boot settings, you need to enter your computer's firmware settings (often called BIOS or UEFI settings). This is different from settings within Windows—you're accessing the software that runs before Windows starts. The process is similar across most computers but has some variations depending on the manufacturer.
Make Lowes Synchrony Bank Credit Card Payments →
To enter firmware settings, you typically need to restart your computer and press a specific key during the startup process, before Windows loads. The key varies by manufacturer: common options include Delete, F2, F10, F12, or Escape. The exact key usually appears on your screen briefly during startup, showing a message like "Press F2 to enter Setup" or "Press Delete to enter BIOS." If you miss it, you can restart and try again. Some manufacturers also allow you to enter firmware settings directly from Windows by going to Settings > System > Recovery > Advanced Startup Options, then selecting "Restart Now" and choosing "Troubleshoot" > "Advanced options" > "UEFI Firmware Settings."
Once you're in the firmware settings screen, the layout varies by manufacturer. Dell computers often have a simpler, menu-driven interface. HP and Lenovo systems may have different organization. However, the basic navigation is similar everywhere: you use arrow keys to move between options and Enter to select. Look for menus related to Security, Boot, Advanced, or System Configuration—these are where TPM and boot settings typically appear.
The firmware settings contain many technical options that you shouldn't change unless you have a specific reason. For TPM 2.0 setup and boot configuration, focus on these areas: Security settings (where TPM is usually located), Boot settings (where you set the boot mode to UEFI and boot order), and System Configuration (where Secure Boot might appear). Take a photograph of important settings with your phone before making changes, so you can reference them if needed.
Most firmware settings have default values. If you make a mistake, look for an option to "Load Setup Defaults" or "Reset to Defaults." This restores the settings the computer shipped with. Before exiting firmware settings, look for a "Save and Exit" or "Exit Saving Changes" option—without explicitly saving, your changes won't be kept.
Practical Takeaway: Write down your computer's manufacturer and model number before you start. Search online for "[your model] firmware settings guide" to find manufacturer-specific instructions. Most manufacturers provide PDF guides showing the exact screens and menu locations, which makes the process much clearer than trying to figure it out on your own.
After accessing your firmware settings, you need to locate the TPM option and enable it. TPM 2.0 is sometimes disabled by default on computers, even though the hardware is present. This was historically done for compatibility reasons, but modern systems expect TPM 2.0 to be available.
Learn About TECO Energy Bill Pay Login →
The TPM option is usually found in the Security menu of your firmware settings. It may be labeled as "TPM," "Security Chip," "PTT" (Platform Trust Technology, Intel's name for integrated TPM), "PSB" (AMD's equivalent),
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.