Windows 10: BSOD when enabling TPM 2.0 and Secure Boot

Discus and support BSOD when enabling TPM 2.0 and Secure Boot in Windows 10 Software and Apps to solve the problem; Hi everyone,I know that this has been a recurrent issue for some people, but I still am not sure about the answer to this problem. I will include some... Discussion in 'Windows 10 Software and Apps' started by MikaylaH02, May 6, 2024.

  1. BSOD when enabling TPM 2.0 and Secure Boot


    Hi everyone,I know that this has been a recurrent issue for some people, but I still am not sure about the answer to this problem. I will include some dump files below as well.System Background Info:Gigabyte B560 DS3H AC-Y1 MotherboardBIOS Version/Date = American Megatrends International, LLC. F4, 6/18/2021Intel Processor 11th Gen IntelR CoreTM i7-11700F @ 2.50GHz, 2496 Mhz, 8 Cores, 16 Logical ProcessorsSince Riot has started forcing users to implement Vanguard in playing LoL, I have experienced difficulties with my PC. I could not initialize Vanguard on my PC at first because I did

    :)
     
    MikaylaH02, May 6, 2024
    #1

  2. How to enable TPM

    Hi, regarding your query I suggest to link Mai official link to get better understanding about your motherboard tpm settings. Below is the link.

    MSI TPM settings
     
    Syed Ali Zamin Shah, May 6, 2024
    #2
  3. DaveM121 Win User
    TPM and Secure Boot, Is it worth a reinstall for Windows 10

    Hi Gavin,

    I am Dave, I will help you with this.

    If your motherboard supports TPM 2.0, and UEFI Boot, then yes, your system would be more secure if you enabled TPM 2/0 and Secure Boot.

    There is a way to enable them without re-installing Windows, read the link below from Microsoft on how to convert your drive from an MBR partition style to GPT, you can then enable Secure Boot and TPM.

    Of you do use this method, please backup your personal files first.

    https://docs.microsoft.com/en-us/windows/deploy...
     
    DaveM121, May 6, 2024
    #3
  4. felipe-ca Win User

    BSOD when enabling TPM 2.0 and Secure Boot

    Inaccessible Boot Device - Likely due to TPM and Secure Keys

    When I boot my custom build desktop, I'm getting Inaccessible Boot Device. I then get to WinRE and I am able to go to the command prompt and I can see the windows installation on driver D.

    I tried running

    • Startup Repair - No luck, nothing fixed, issue remains
    • cmd prompt - sfc/SCANNOW /OFFBOOTDIR=d:\ /OFFWINDIR=d:\windows [enter].
    • cmd prompt - chkdsk d: /r (answered yes to dismount)
    • Restart Options - disable driver signature enforcement
    • Restart Options - disable early launch anti-malware protection
    • Safe mode
    • playing with different settings in BIOS
    How did I get into this messy situation:

    • Win 10, tried to upgrade to Win 11. TPM was not enabled in BIOS
    • Enabled fTPM in mobo (ASUS Prime X570-Pro)
    • Win 10 was using legacy MBR. Successfully converted to GPT. Changed mobo to UEFI in compatibility mode (UEFI and Legacy OPROM, storage devices and PCIe devices in UEFI only mode). Boot Device is an NVME SSD (PCIE-4 compatible). Bitlocker was never enabled.
    • No issues so far and I was able to start Win11 installation.
    • After a few auto-reboots, at around 75% the installation failed. Inaccessible Boot Device
    • Win11 installation was successfully reverted and I was able to login to Win10
    • restarted the win11 install. same issue at aroung 75%
    • Upgraded Mobo Firmware (v2407 to v4021).
    • Win 11 installation failed again.
    • Changed bios configs and could not boot anymore
    Unfortunately I don't have the exact sequence of steps but these are the areas I played with

    • I never run the TPM module in windows after enabling TPM in the BIOS.
    • I was looking into Bios as some forum post suggested making sure SATA was set to AHCI. But I am using RAID on my SATA spinning HDDs. The system is booting from NVMe SSD
    • I noticed that Bios -> Boot -> Boot/Secure Boot -> OS Type - Was set to "Other OS" and changed it to "Windows UEFI Mode"
    • Unfortunately I don't remember if I changed any other settings at this point.
    Other things I have tried

    • Bios - Saved secured keys to USB drive and deleted existing keys (only after changing the OS type and the issue already present)
    • Bios - installed default secure boot keys
    • Bios - Restored saved secure boot keys
    • Disabled fTPM (by setting it to discrete TPM - there are no external TPM module in my setup)
    • Bios -> Advanced -> Trusted Computing -> Security Device Support - Disable
    • Bios -> Advanced -> Trusted Computing -> Disable Block Sid -> Enable (only for next boot)
    • A few combinations of the configs above, though likely not exhaustive of all combinations
    I also tried to boot from the Win 10 Installation DVD and try to repair the win10 installation, but no success. Though it is possible I could have had a a bad choice of bios settings when trying this.

    Any ideas on what I can do next? What would be the best procedure to try to recover the system?

    • fTPM enabled
    • Should I clear the Secure Boot Keys? Leave them empty or install default ones?
    • Security Device Support - Leave it enabled? there are some options such as platform hierarchy and storage hierarchy (both enabled)
    • TPM 2.0 UEFI Spec version is TCG_2 / Physical Presence Spec Version is 1.3
    • Try to repair windows with the settings above?
    • Try to re-install Win10 preserving personal files?
    Thanks,

    Felipe.
     
    felipe-ca, May 6, 2024
    #4
Thema:

BSOD when enabling TPM 2.0 and Secure Boot

Loading...
  1. BSOD when enabling TPM 2.0 and Secure Boot - Similar Threads - BSOD enabling TPM

  2. BSOD when enabling TPM 2.0 and Secure Boot

    in Windows 10 Gaming
    BSOD when enabling TPM 2.0 and Secure Boot: Hi everyone,I know that this has been a recurrent issue for some people, but I still am not sure about the answer to this problem. I will include some dump files below as well.System Background Info:Gigabyte B560 DS3H AC-Y1 MotherboardBIOS Version/Date = American Megatrends...
  3. TPM 2.0 Enabled but Secure Boot State off?

    in Windows 10 Gaming
    TPM 2.0 Enabled but Secure Boot State off?: So I am trying to install windows 11 and I'm struggling to figure out how to get secure boot enabled. I have CSM disabled and enabled secure boot in the BIOS but system information is still showing it to be off. My system is formatted GPT as well so i am struggling. Any help...
  4. TPM 2.0 Enabled but Secure Boot State off?

    in Windows 10 Software and Apps
    TPM 2.0 Enabled but Secure Boot State off?: So I am trying to install windows 11 and I'm struggling to figure out how to get secure boot enabled. I have CSM disabled and enabled secure boot in the BIOS but system information is still showing it to be off. My system is formatted GPT as well so i am struggling. Any help...
  5. TPM 2.0 Enabled but Secure Boot State off?

    in Windows 10 Installation and Upgrade
    TPM 2.0 Enabled but Secure Boot State off?: So I am trying to install windows 11 and I'm struggling to figure out how to get secure boot enabled. I have CSM disabled and enabled secure boot in the BIOS but system information is still showing it to be off. My system is formatted GPT as well so i am struggling. Any help...
  6. "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled

    in Windows 10 Software and Apps
    "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled: I am running Windows 10 v. 21H1 on ASRock X370 Extreme 4 motherboard with IntelR CoreTM i5-8400 CPU @ 2.80GHz 2.81 GHz processor. I have enabled "Secure Boot" and TPM 2.0 and wish to install Windows 11. PC Health Check says "Secure Boot" is not enabled and Windows Update says...
  7. "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled

    in Windows 10 Installation and Upgrade
    "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled: I am running Windows 10 v. 21H1 on ASRock X370 Extreme 4 motherboard with IntelR CoreTM i5-8400 CPU @ 2.80GHz 2.81 GHz processor. I have enabled "Secure Boot" and TPM 2.0 and wish to install Windows 11. PC Health Check says "Secure Boot" is not enabled and Windows Update says...
  8. "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled

    in Windows 10 Gaming
    "Secure Boot" and TPM 2.0 are both enabled; PC Health Check says "Secure Boot" is not enabled: I am running Windows 10 v. 21H1 on ASRock X370 Extreme 4 motherboard with IntelR CoreTM i5-8400 CPU @ 2.80GHz 2.81 GHz processor. I have enabled "Secure Boot" and TPM 2.0 and wish to install Windows 11. PC Health Check says "Secure Boot" is not enabled and Windows Update says...
  9. Secure boot and TPM

    in AntiVirus, Firewalls and System Security
    Secure boot and TPM: So I don't know if this is a problem or I'm just stupid, but I want to upgrade to Windows 11. The thing is that my processor isn't supported and I need to enable TPM. There's a catch tho, when I went to the BIOS it says that my "Network Boot Protocol" is set to "Legacy IPv4",...
  10. BSOD on boot when TPM is enabled (after migration to GPT/UEFI)

    in Windows 10 BSOD Crashes and Debugging
    BSOD on boot when TPM is enabled (after migration to GPT/UEFI): Hi - I wonder if anyone can help with this issue. Everything was working OK on my machine, and I had TPM enabled in BIOS. However my PC was not running in UEFI mode and my HDD was still using MBR and not GPT. I decided therefore to use mbr2gpt process to convert disk to GPT...