Windows 11 and TPM

CopySeeSewDye

Member
Joined
Dec 30, 2020
Messages
266
Reaction score
56
my os c drive is mbr, can I enable secure boot anot ? or must change it to gpt?already enabled fTPM but windows check say must enable secureboot.
You need to convert to gpt for secureboot, and also win11 will be uefi only. If you want to convert ur os drive, u can use windows inbuilt mbr2gpt tool, it has several prerequisites though, most importantly is your OS drive must not be partitioned heavily. You can use the validate command in the tool to make sure your disk meets the requirment. Make sure to do the necessary backup of your data before doing the conversion, even if the tool does not delete your data. Also make sure your hardware is uefi compatible, like the graphics card.

Documentation on prerequites:
https://docs.microsoft.com/en-us/windows/deployment/mbr-to-gpt
Walkthrough:
https://www.windowscentral.com/how-convert-mbr-disk-gpt-move-bios-uefi-windows-10
 

11.11.

Arch-Supremacy Member
Joined
Nov 11, 2020
Messages
12,068
Reaction score
36,163
You need to convert to gpt for secureboot, and also win11 will be uefi only. If you want to convert ur os drive, u can use windows inbuilt mbr2gpt tool, it has several prerequisites though, most importantly is your OS drive must not be partitioned heavily. You can use the validate command in the tool to make sure your disk meets the requirment. Make sure to do the necessary backup of your data before doing the conversion, even if the tool does not delete your data. Also make sure your hardware is uefi compatible, like the graphics card.

Documentation on prerequites:
https://docs.microsoft.com/en-us/windows/deployment/mbr-to-gpt
Walkthrough:
https://www.windowscentral.com/how-convert-mbr-disk-gpt-move-bios-uefi-windows-10[/URL
For OS drive, cannot convert to GPT unless the drive is meant for storage.
You have to reinstall Windows as MBR/Legacy Boot the file structure are different.

UEFI drive have EFI system, one partition for C drive and recovery partitions.
MBR wise is different, one partition for System reserved and one for C drive.
Both UEFI, MBR are different but I know some use CSM/Legacy to boot Windows but not only you lack
secure boot.

UEFI boot is faster as well as take advantage of newer hardware, CSM/Legacy are meant
for compatibility especially with older graphics without UEFI BIOS.
To install UEFI on some motherboard you have to hit F11/F12 for boot menu than boot
from UEFI thumbdrive.

BTW, legacy boot you will see this:

bw68o.png


UEFI boot usually is manufacturer logo example Asus than desktop.
*MSI mobo wise initial setup may show this which is normal, after Windows is install than MSI logo is shown.
tks guys, maybe need to reinstall OS using gpt to take advantage of free win11.
 

wwenze

Greater Supremacy Member
Joined
Dec 2, 2002
Messages
86,461
Reaction score
30,149
Wonder can fresh install without key or not.

Since I'm building a new com from scratch. Down to the SSD.
 

Clearnfc

Banned
Joined
Apr 10, 2019
Messages
14,093
Reaction score
3,729
No need to watch yet another long YouTube video for Win11 TPM workaround, just nice clear text and screenshots.
https://allthings.how/how-to-install-windows-11-on-legacy-bios-without-secure-boot-or-tpm-2-0/

I can tell you its not going to work, unless M$ allows it. Even if you can install, you may not be able to run it after some update... So, after your get around it, install and run.... after 1 update, you may not get to desktop again. Don't be surprise if M$ gives you a big prompt saying no TPM and refuse to boot to desktop.
 

86technie

High Supremacy Member
Joined
Jun 8, 2006
Messages
40,367
Reaction score
5,954
For now to install the unofficial Windows 11, if you want to test it is fine.
To use it for normal use, gaming etc. think better not.
Until the official Win 11 is release or if you are a MS insider subscriber.

MS will eventually block it, how they block it like previous OS which was done last time
like during Win Vista/7.
Desktop won't load, it will just black screen and it won't go any further.

Bring back memory when Win 7 was announced, people was already trying it before
it's official launch. Luckily when Win 7 was released, it was popular but later Win 8 flip.
Win 10 got pros and cons but the Win update is a headache as it may or may not break
the PC down the road.
 

Yongkit

Supremacy Member
Joined
Oct 9, 2015
Messages
5,906
Reaction score
2,494
I read in Facebook that someone highlights by enabled fTPM and bitlocker together could crippled future mobo bios update for windows 11 if not done properly.

Any of our members here have this concerns?
 

Mach3.2

Great Supremacy Member
Joined
Apr 8, 2011
Messages
72,510
Reaction score
2,488
I read in Facebook that someone highlights by enabled fTPM and bitlocker together could crippled future mobo bios update for windows 11 if not done properly.

Any of our members here have this concerns?
BIOS updates could wipe the fTPM, so you need to suspend bitlocker before updating the BIOS.

If you forget to suspend bitlocker before updating your BIOS, your computer might go into bitlocker recovery mode where you'd need to key in the 48 digit recovery key to unlock your drive, which you should have saved to your microsoft account when setting up bitlocker(or to a file), so I won't be too worried about it.

Anyway, for desktop PCs I don't really see a point to drive encryption. You're more likely to lock yourself out than prevent people from stealing data out of your stationary machine. If you're up against state sponsored actors, you're really sh!t outta luck anyway.. :o

https://docs.microsoft.com/en-us/wi...ction/bitlocker/bitlocker-recovery-guide-plan
 

Yongkit

Supremacy Member
Joined
Oct 9, 2015
Messages
5,906
Reaction score
2,494
BIOS updates could wipe the fTPM, so you need to suspend bitlocker before updating the BIOS.

If you forget to suspend bitlocker before updating your BIOS, your computer might go into bitlocker recovery mode where you'd need to key in the 48 digit recovery key to unlock your drive, which you should have saved to your microsoft account when setting up bitlocker(or to a file), so I won't be too worried about it.

Anyway, for desktop PCs I don't really see a point to drive encryption. You're more likely to lock yourself out than prevent people from stealing data out of your stationary machine. If you're up against state sponsored actors, you're really sh!t outta luck anyway.. :o

https://docs.microsoft.com/en-us/wi...ction/bitlocker/bitlocker-recovery-guide-plan

Many thanks for details explanation (y) (y) :giggle: ya I agreed the last session I used bitlocker was 5 years ago but too troublesome so I disabled it.
 

Goodshot

Great Supremacy Member
Joined
Sep 20, 2013
Messages
62,394
Reaction score
4,356
Those who want back the classic start panel after upgrade to 11 can refer here

2.26
 

LiLAsN

Master Member
Joined
Dec 14, 2008
Messages
2,700
Reaction score
510
I have a concern in regards to this FTPM issue with Windows 11. Based on the screenshot,

Does this mean that if I were to change my CPU and motherboard, I won't be able to just make Windows work like it did when upgrading from Z170+6700K to the Z390+9900K in Windows 10 where the OS will still boot up without a reinstall and with my Windows and profile the way it is?

I think this ought to be a very important information that might tip Desktop PC users from upgrading to Windows 11 if it meant that I would have to reinstall Windows in its entirety as opposed to just plopping my OS drive into the new Motherboard and CPU and still be able to boot up with everything in my OS drive intact.


205948217_10225980908737777_8015613072713054381_n.jpg
 

Mach3.2

Great Supremacy Member
Joined
Apr 8, 2011
Messages
72,510
Reaction score
2,488
I have a concern in regards to this FTPM issue with Windows 11. Based on the screenshot,

Does this mean that if I were to change my CPU and motherboard, I won't be able to just make Windows work like it did when upgrading from Z170+6700K to the Z390+9900K in Windows 10 where the OS will still boot up without a reinstall and with my Windows and profile the way it is?

I think this ought to be a very important information that might tip Desktop PC users from upgrading to Windows 11 if it meant that I would have to reinstall Windows in its entirety as opposed to just plopping my OS drive into the new Motherboard and CPU and still be able to boot up with everything in my OS drive intact.


205948217_10225980908737777_8015613072713054381_n.jpg
BIOS updates could wipe the fTPM, so you need to suspend bitlocker before updating the BIOS.

If you forget to suspend bitlocker before updating your BIOS, your computer might go into bitlocker recovery mode where you'd need to key in the 48 digit recovery key to unlock your drive, which you should have saved to your microsoft account when setting up bitlocker(or to a file), so I won't be too worried about it.

Anyway, for desktop PCs I don't really see a point to drive encryption. You're more likely to lock yourself out than prevent people from stealing data out of your stationary machine. If you're up against state sponsored actors, you're really sh!t outta luck anyway.. :o

https://docs.microsoft.com/en-us/wi...ction/bitlocker/bitlocker-recovery-guide-plan
See my previous post, it's not an issue if you remembered to suspend bitlocker before updating BIOS/change mobo/change CPU.

That's why it's really important to retain access to your 48 digit recovery key, and M$ stressed that fact when you setup bitlocker for anyone who cared to read the prompts.
 

86technie

High Supremacy Member
Joined
Jun 8, 2006
Messages
40,367
Reaction score
5,954
I have a concern in regards to this FTPM issue with Windows 11. Based on the screenshot,

Does this mean that if I were to change my CPU and motherboard, I won't be able to just make Windows work like it did when upgrading from Z170+6700K to the Z390+9900K in Windows 10 where the OS will still boot up without a reinstall and with my Windows and profile the way it is?

I think this ought to be a very important information that might tip Desktop PC users from upgrading to Windows 11 if it meant that I would have to reinstall Windows in its entirety as opposed to just plopping my OS drive into the new Motherboard and CPU and still be able to boot up with everything in my OS drive intact.


205948217_10225980908737777_8015613072713054381_n.jpg
Err.. regardless of which OS, if change motherboard.
Best to reinstall, it may work but down the road this BSOD will appear.

bad-system-config-error-featured.png


SATA controller, chipset etc. are different each generation so best to reinstall.
 

LiLAsN

Master Member
Joined
Dec 14, 2008
Messages
2,700
Reaction score
510
Err.. regardless of which OS, if change motherboard.
Best to reinstall, it may work but down the road this BSOD will appear.

bad-system-config-error-featured.png


SATA controller, chipset etc. are different each generation so best to reinstall.
Haha! No worries. Never had any problems with the OS for my case. It's been years with my Z390 and 9900K. So far, problem and error free. Got to applause Windows 10 for making changing of CPU and Motherboard without reinstallation as painless as ever.


See my previous post, it's not an issue if you remembered to suspend bitlocker before updating BIOS/change mobo/change CPU.

That's why it's really important to retain access to your 48 digit recovery key, and M$ stressed that fact when you setup bitlocker for anyone who cared to read the prompts.
My thanks! Looks like it might be a better idea to get a physical TPM key instead. Or I'll just hold the upgrade until I deem in necessary as just with the Windows 10 updates, the first in line are treated as Beta testers full of bugs that are quite severe at times. I am already running Android in emulation. And changing the colouring of an SDR game in Auto HDR is not really a good idea. So I'll wait it out until I see a safer path to upgrading to Windows 11 as more people gets their hands on it and finds a way to solve this TPM case.

Because a complete change of motherboard/CPU means the TPM key will be non-existent in the new motherboard/CPU. Thus, the issue of not being able to boot up. Not just a BIOS thing. And you are right. I don't plan to use Bitlocker. I never even did for my current OS and drives. It just makes my data loss, if any, harder or even impossible to retrieve by conventional means. And as you said, it's in our home hidden away from prying eyes. So not really of any worry.
 

86technie

High Supremacy Member
Joined
Jun 8, 2006
Messages
40,367
Reaction score
5,954
Majority of users especially for home users, don't really need TPM unless using Win 10 pro version.
To enable bitlocker and etc. Cryptographic key function used in corporate environment and I also was
surprised that Windows 11 by default need TPM.
The irony is MS have not announced what editions will Windows 11 come in.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top