Share via

TPM is not usable PCR7 binding is not supported (SOLVED)

Tschat 35 Reputation points
2023-03-11T00:58:13.6433333+00:00

(SOLVED EXPLANATIONM BELOW)

I have the Problem that I did a fresh install of Windows 10 pro (twice) and enabled Secure Boot as well as fTPM (amd) to be Win 11 ready, but Windows still says that it doesn't recognize a tpm module. I installed the ryzen chipset drivers (because under Device Manager it said: "pci encryption/decryption controller") and under Security devices it only says: "AMD PSP 11.0".

Under System Information it says that Secure Boot State is : On

PCR7 Configuration: Binding Not Possible

Device Encryption Support: "Reasons for failed automatic device encryption: TPM is not usable, PCR7 binding is not supported, Hardware Security Test Interface failed and device is not Modern Standby, Un-allowed DMA capable bus/device(s) detected, TPM is not usable."

I'm loosing my marbles trying to just install Win 11 ffs..........! Pleas help meeee

My PC:

Mainboard: NZXT N7 B550 (Newest BIOS Ver)

CPU: Ryzen 9 5900x

RAM: 32GB 3200Mhz

GPU: RTX 3090

OS: Windows 10 pro

EXPLANATION:

Okay so as I found no real answer I started to look into another Problem that I had, my USB devices were on even after I turned the PC off. Turns out that the same setting that fixed this also fixed my PCR7 binding Problem as well as the tpm problem. I had to go to ACPI Configuration settings and change the Deep Sleep settings to "S4 and S5 enabled".

Windows for business | Windows Client for IT Pros | User experience | Other

Answer accepted by question author

  1. risolis 8,806 Reputation points
    2023-03-11T04:18:47.03+00:00

    Hello @Tschat

    Thank you for posting this concern on this community space.

    I read your case scenario description and I would like to share those links down below:

    https://answers.microsoft.com/en-us/windows/forum/all/pcr7-configuration-binding-not-possible/ba7aeb33-b1cb-459e-a3e8-c0ad0a17975f

    https://www.makeuseof.com/windows-11-pcr7-binding-not-supported/

    I hope that can be useful for you.

    Looking forward to your feedback,

    Cheers,

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    2 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Stephen Tures 0 Reputation points
    2026-04-16T18:22:21.58+00:00

    I ran into this and found it frustrating. Sleep states were enabled, TPM was owned by the OS, drivers and firmware up to date, no thunderbolt docks or (pci external?) hardware.

    What did it for me (conclusively, as I only changed one thing) was checking the BIOS with a fine toothed comb. I have an ASUS ROG motherboard, so this might help others. There were three DMA security states in one setting: Disabled, Enabled with OS (management?), and Enabled fully at boot. I'm not positive on the wording. My BIOS default has set it to the second option, sth like "Enabled with OS Management" but I flipped it to "Enabled Fully At Boot" and changed nothing else, and suddenly my DMA Protection PCR7 binding errors all went away and I've happily enabled bitlocker to auto unlock.

    Hope this helps whoever needs to heard this, but do check your BIOS carefully for DMA settings and... turn those all the way on I guess? Surprised Enabled with OS Management was default, and from the sound of the setting, you'd think that would be enough, but evidently not.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.