Setting up and managing device configurations using Intune
Yes—if the Intune compliance policy has Trusted Platform Module (TPM) set to Require, the device is compliant only when Windows reports a TPM version greater than 0. If there is no TPM version on the device, Intune marks it noncompliant.
A practical check path is:
- On the device, open Windows Security > Device security.
- If Security processor is missing, the TPM may be disabled.
- If Security processor details is available, check Specification version.
- Or run tpm.msc.
- If it shows Compatible TPM cannot be found, the TPM is likely disabled in BIOS/UEFI or not being recognized.
- If TPM is disabled, enable it in firmware:
Settings > Update & Security > Recovery > Restart now > Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
In UEFI/BIOS, look under menus such as Advanced, Security, or Trusted Computing. The setting can appear as Security Device, Security Device Support, TPM State, AMD fTPM switch, AMD PSP fTPM, Intel PTT, or Intel Platform Trust Technology. - After enabling TPM, restart Windows and check again in tpm.msc or Windows Security.
If TPM is already enabled but still shows an error:
- In Windows Security > Device security, open Security processor troubleshooting to review the TPM error.
- If the message indicates firmware is needed, install the latest BIOS/TPM firmware update from the device manufacturer.
- If Windows still does not recognize the TPM on older devices, Device Manager may show it under System Devices instead of Security Devices. Uninstalling the TPM driver and rescanning hardware can cause Windows to detect it again with the Microsoft TPM driver.
Use caution with Clear TPM or resetting TPM keys, because clearing the TPM can cause data loss.