Equipment:
Model: EAX-Q170KP-B1R
BIOS version: AK17-01E
Operating System: Windows 10
TPM: Onboard Infineon SLB9665, support TPM 2.0
About TPM, there are three implementation options for TPMs:
# Discrete TPM chip as a separate component in its own semiconductor package
# Integrated TPM solution, using dedicated hardware integrated into one or more
semiconductor packages alongside, but logically separate from, other components
# Firmware TPM solution, running the TPM in firmware in a Trusted Execution mode of a
general purpose computation unit
Windows uses any compatible TPM in the same way. Microsoft does not take a position on which way a TPM should be implemented and there is a wide ecosystem of available TPM solutions, which should suit all needs.
Windows BitLocker has become a solution for Users to secure their data. The following is how to enable and disable BitLocker using the standard methods.
This article does not discuss the utilization of a USB as a TPM replacement and does not discuss Group Policy changes for advanced features. Domain level Group Policy changes and network-managed BitLocker setups are Best Effort and are out of the scope of support. Supported configurations are limited to single computers and locally managed BitLocker setups.
- Notes:
- # All Operating Systems that are configured in Legacy Boot Mode must use TPM 1.2. It is recommended the BIOS also be updated to the latest revision.
- # All Operating Systems that are configured in UEFI Boot Mode can use either TPM 1.2, or TPM 2.0. It is recommended the BIOS also be updated to the latest revision.
- # If a Windows 7 computer is configured for UEFI Boot Mode, this patch must be applied in order to use TPM 2.0: Microsoft TPM 2.0 Patch
- Importance: TPM 2.0 is not supported in Legacy and CSM Modes of the BIOS. Devices with TPM 2.0 must have their BIOS mode configured as Native UEFI only. The Legacy and Compatibility Support Module (CSM) options must be disabled. For added security Enable the Secure Boot feature.
- Installed Operating System on hardware in legacy mode will stop the OS from booting when the BIOS mode is changed to UEFI. Use the tool MBR2GPT before changing the BIOS mode which will prepare the OS and the disk to support UEFI.