Windows won’t start

TPM or Secure Boot error prevents Windows 11 from starting

Windows 11 fails to start and shows an error referencing TPM (Trusted Platform Module) or Secure Boot, meaning the security features Windows 11 relies on aren't available or aren't configured correctly.

Difficulty
Moderate
Time
20–45 minutes
DIY cost
$0
Pro cost
$80–$180

Symptoms

  • Error message specifically mentions TPM or Secure Boot
  • Appeared after a BIOS reset, motherboard battery replacement, or hardware change
  • PC previously ran Windows 11 without this issue
  • May be accompanied by a request for a BitLocker recovery key

Likely causes

  • CommonTPM disabled or reset in BIOS/UEFIA BIOS reset (including from a dead CMOS battery) can turn off or clear the TPM setting.
  • CommonSecure Boot disabled after a BIOS update or resetSimilar to TPM, this setting can revert during firmware changes.
  • PossibleTPM firmware needing an update after a motherboard/BIOS changeSome systems need matching firmware versions between TPM and BIOS.
  • PossibleBitLocker lock triggered by the TPM state changeIf BitLocker is enabled, a changed TPM state often triggers a recovery key prompt as well.
  • Less commonFaulty or failing TPM chip (on systems with a discrete TPM)A physical TPM module can fail independently of the rest of the motherboard.

What to do

  1. Enter BIOS/UEFI setup and look for a setting called TPM, PTT (Platform Trust Technology on Intel), or fTPM (on AMD), and confirm it's enabled.
  2. Check that Secure Boot is also enabled in the same BIOS/UEFI menu, since Windows 11 checks for both together.
  3. Save and exit after enabling these settings, then attempt to boot normally.
  4. If a BitLocker recovery key prompt appears as a result of the TPM state changing, use your saved recovery key (from your Microsoft account or IT department) to unlock it.
  5. If TPM/Secure Boot options aren't visible or grayed out, check whether the BIOS firmware itself needs updating from the manufacturer's site.
  6. If enabling TPM and Secure Boot doesn't resolve the error, the physical TPM module (if separate from the CPU) may need reseating or replacement.
  7. If you're unable to locate these settings or they don't stick after saving, consult your PC manufacturer's specific documentation, since menu names vary.

When to call a pro

If TPM and Secure Boot settings won't enable or don't resolve the error, and especially if you can't find your BitLocker recovery key, a technician can help without risking data loss.

Safety

Generally low risk

Generally low risk for a careful person. Stop if anything looks different from what this guide describes.

Related guides

Operator provides AI-generated troubleshooting information. It can be wrong. For safety-critical, electrical, gas, structural, medical, automotive safety, or other high-risk problems, consult a qualified professional.