Recently we published an article that should help you confirm whether your computer is compatible with Windows 11. In that article we also indicated that the information would be updated if Microsoft made any extra changes. However, at this moment we can say with some certainty that even in Redmond they don't have a solid idea about the technical situation of their operating system. The first thing users want to know is how to enable TPM 2.0 on their computers, and today we'll do our best to explain the process, but that's just the tip of the iceberg…
"This PC can't run Windows 11"
Generic phrase if there ever was one, but it has managed to go around the world in a matter of hours. The official tool PC Health Check is the recommended way to verify if a computer is compatible with Windows 11, and a not insignificant number of users decided to hit the web to criticize the lack of technical information of that application: it shows the incompatibility message, but doesn't explain the reasons. How is the user supposed to fix the problem if they don't know where to start? Honestly, we shouldn't be surprised. It's not the first time we see something like this.
Several portals reported that Microsoft updated the tool to optimize its feedback. We tried it here at NeoTeo... and nothing. 'PC Health Check' refuses to reveal its secrets... but in practice we don't need them. Once again, the user must play detective and figure things out on their own, starting with TPM 2.0. In a previous article I said that 'TPM 2.0 will be an inconvenience for some users, but not the end of the world'. Well, the 'inconvenience' just received an upgrade to 'headache', and all potential Windows 11 users now want to know how to enable TPM 2.0 on their computers... assuming it exists.
How to enable TPM 2.0
In the best case, TPM 2.0 is already available and enabled, but it's more likely that it's disabled at the BIOS/UEFI level. Depending on the motherboard manufacturer and the platform used (Intel or AMD), the exact path may change. However, before that you must run the command 'tpm.msc'. This opens the "Trusted Platform Module (TPM) Management on the local computer". Confirm if this window (image above) shows information about the module, if its version is 2.0, and if the status indicates that it is "ready for use".
Another alternative is to visit the Device Security section in the Settings menu. The path is Settings -> Update & Security -> Windows Security -> Device Security. There you will see the "Security processor" entry, and clicking on Processor details will show its status and specifications. You may also find expressions like "Standard hardware security not supported", but we'll get to that another time.
If TPM 2.0 doesn't show up anywhere, you'll need to visit the BIOS/UEFI. Unfortunately, we can only share generic instructions:
- For Intel processors, the technology is called Platform Trust Technology or PTT
- For AMD chips, the equivalent function is called fTPM
On many motherboards, it's enough to enter the advanced mode of their BIOS/UEFI, locate the PTT/fTPM section, and set its value to Enabled/Active/On/Allowed or similar. On other models, you may also need to enter the Security section and enable the 'Hardware Security' option. Then there are boards that use completely user-unfriendly names. For example, on certain Asus boards, the correct menu is called "PCH-FW Configuration" (see the video below for more details).
Soft Floor, Hard Floor, and false negatives
Even if you've managed to enable TPM 2.0, the story doesn't end there. It's possible that 'PC Health Check' still throws the same incompatibility message with Windows 11. Suspicions point to two additional conditions: Secure Boot and CSM (BIOS mode). If for some reason Secure Boot was disabled and CSM is enabled, we can't expect the tool to respond positively. Microsoft explains this in a document called TPM Recommendations, published in November 2018:
TPM 2.0 is not supported in Legacy and CSM BIOS modes. Devices with TPM 2.0 must have their BIOS mode configured to native UEFI only. Legacy and CSM options must be disabled. For greater security, enable the Secure Boot feature.
But there are two other details: the lists of compatible processors (both available here and here), and the Soft Floor / Hard Floor duo. What is this Soft Floor / Hard Floor about?
Previously, Microsoft shared a guide to "compatibility floors" divided into two parts: hard and soft. The hard floor establishes non-negotiable requirements, like a 64-bit processor and 4GB of RAM. Meanwhile, under the soft floor were TPM 2.0 and CPU generation. It was supposed that the installer would show a warning but allow us to continue if soft floor conditions were not met. This was especially useful for TPM, as it set TPM 1.2 as an absolute minimum. So what happened?
Microsoft removed Soft Floor / Hard Floor and confirmed the minimum base of TPM 2.0. As if that weren't enough, users with relatively powerful processors continue to receive false negatives because their chips don't appear on the compatibility list. One of the most scandalous examples is the Surface Studio 2, a computer that Microsoft sells today for $3,500. That system uses a Core i7-7820HQ... and it's not on the list of compatible CPUs. Want to know if your processor is the 'culprit'? Download a copy of Win11SysCheck and run its executable with elevated privileges.
Microsoft needs to fix this
Redmond repeats old mistakes. Its massive communication failure is just what we see on the surface. There's a much more serious problem in the background, and we can explain it this way: Windows 10 has been on the market for almost six years. Beyond the criticisms, the bugs, the loss of information, and the forced updates, it has become the main operating system for 1.3 billion devices. And now that Windows 10 has reached a phase of semi-stability we can work with, Microsoft has no better idea than to split its user base in half and throw it into a storm of confusion and contradictions.
How could no one at Microsoft anticipate this? Did they fail to conceptualize the 'average computer' that uses Windows 10? What is telemetry for? What is the Insider program for? How did they not detect the most problematic points in their hardware requirements? Many questions, very few answers. Microsoft still has time, I hope they don't waste it.