How to Fix TPM Errors After Replacing a Motherboard in Windows 11

11 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

A BitLocker recovery screen, “Your PIN is no longer available,” or “Compatible TPM cannot be found” can appear after a motherboard replacement. Your files are likely intact, but Windows doesn’t trust the new TPM yet.

Fix #1: Unlock the Drive With Your BitLocker Recovery Key

Problem: BitLocker asks for a 48-digit recovery key right after the motherboard repair.

Symptoms:

  • A blue BitLocker recovery screen appears during startup.
  • Windows asks for a 48-digit key.
  • The recovery screen shows a recovery key ID.
  • The same drive worked before the repair.

Why it happens: BitLocker tied its unlock key to the old motherboard’s Trusted Platform Module (TPM). The new board has a different TPM identity. BitLocker treats that change as a possible attack. The blue screen is alarming, but your SSD and files aren’t necessarily damaged.

A discrete TPM is a physical module on the motherboard. Replacing the board removes that module unless the repair shop moves it to a supported board. Intel PTT and AMD fTPM are built into the firmware. Replacing or resetting the board still gives Windows a new TPM identity.

  • Note the recovery key ID shown on the BitLocker screen.
  • Match the saved key to the key ID on the recovery screen.
  • Check for a printed copy, USB drive, text file, or password manager entry. Also check any other place you used when BitLocker was enabled.
  • Contact your workplace or school administrator if the organization manages the computer. The key may be in Microsoft Entra ID or another management system.
  • Enter the matching 48-digit recovery key.
BitLocker recovery screen with the key entry field highlighted
  • Back up important files as soon as Windows starts. Do this before changing TPM settings.

Verification: Save the recovery key, complete the TPM checks below, and restart once. If BitLocker asks for the key again, continue to Fix #5.

You can’t bypass BitLocker encryption. Enabling a new TPM won’t decrypt a drive that’s already locked. Without a valid recovery method, resetting or reinstalling Windows will erase the encrypted data.

Quick Diagnosis

Fix #2: Check Whether Windows Recognizes TPM 2.0

Problem: Windows starts, but you need to confirm that the new TPM is present and ready.

Symptoms:

  • BitLocker entered recovery after the repair.
  • Windows Hello stopped working.
  • Windows Security reports a security processor issue.
  • You don’t know whether the new board supports TPM 2.0.

Why it happens: The repair may have left the firmware TPM disabled. Windows may also have failed to set up the new security processor.

  • Press Windows key + R.
  • Type tpm.msc.
Run dialog with tpm.msc entered and the OK button highlighted
  • Select OK.
  • Read the Status section in TPM Management on Local Computer.
  • Confirm that it says “The TPM is ready for use.”
  • Find TPM Manufacturer Information.
  • Confirm that Specification Version is 2.0.
TPM Management on Local Computer showing “The TPM is ready for use” and Specification Version 2.0 highlighted
  • Open Windows Security > Device security.
Device security page with Security processor and Security processor details highlighted
  • Select Security processor details.
  • Review the status, manufacturer, specification, storage, and attestation fields. An attestation warning can have a separate cause. Check the quick-reference table below.
Security processor details page with TPM status plus Storage and Attestation fields highlighted without assuming both report ready

Verification: The TPM is ready when tpm.msc shows “The TPM is ready for use” and Specification Version 2.0.

Common Issues and Solutions

Fix #3: Enable TPM, Intel PTT, or AMD fTPM in UEFI

Problem: tpm.msc displays “Compatible TPM cannot be found,” or Windows Security has no Security processor section.

Symptoms:

  • Windows can’t detect a TPM.
  • The security processor section is missing.
  • BitLocker or Windows Hello fails after the repair.
  • The TPM option disappeared after a firmware reset.

Why it happens: The new board’s security processor may be disabled in its UEFI settings. UEFI is the firmware menu that controls hardware before Windows starts. Intel systems often call firmware TPM PTT. AMD systems usually call it AMD fTPM or AMD PSP fTPM.

  • Open Settings > System > Recovery.
  • Select Restart now beside Advanced startup.
Windows 11 Recovery settings with Advanced startup and Restart now highlighted
  • Select Troubleshoot > Advanced options > UEFI Firmware Settings.
Windows Recovery Environment Advanced options page with UEFI Firmware Settings highlighted and a note that availability varies by device
  • Select Restart.
  • Open the firmware menu named Security, Advanced, Trusted Computing, System Setup, or System Configuration. The label varies by manufacturer.
  • Find a setting named TPM State, Security Device Support, Security Device, Intel PTT, Intel Platform Trust Technology, AMD fTPM, AMD PSP fTPM, or Firmware TPM.
  • Set the matching option to Enabled or Firmware TPM.
Representative UEFI security page with the applicable TPM State, Security Device Support, Intel PTT, AMD fTPM, or AMD PSP fTPM option and Enabled state highlighted
  • Save the change and exit UEFI. Many systems use F10, but follow the command on your screen.
  • Run tpm.msc again after Windows starts.

Verification: TPM Management should say “The TPM is ready for use” and show Specification Version 2.0.

If the firmware has no TPM, PTT, or fTPM option, check the manufacturer’s instructions. I’d avoid changing unrelated security settings just to see what happens.

Fix #4: Recreate the Windows Hello PIN

Problem: Windows displays “Your PIN is no longer available” or says the TPM has malfunctioned.

Symptoms:

  • The old PIN is rejected after the motherboard replacement.
  • Face or fingerprint sign-in no longer works.
  • Windows asks you to set up the PIN again.
  • Password sign-in still works.

Why it happens: Windows Hello protects its sign-in keys with the TPM. The new TPM can’t open credentials protected by the old one. You’ll need a new PIN.

  • Select Sign-in options on the Windows sign-in screen.
  • Sign in with your account password or another available method.
  • Open Settings > Accounts > Sign-in options.
  • Expand PIN (Windows Hello).
  • Select I forgot my PIN, then complete the account checks.
  • If that doesn’t fix the error, select Remove and restart Windows. Then return to the same page.
  • Select Set up to create a new PIN.
Windows 11 Sign-in options showing the affected Windows Hello method and the available reset, remove, or setup control
  • Set up face or fingerprint recognition again if those methods also stopped working.

Verification: Press Windows key + L to lock the computer. Confirm that the new PIN unlocks it.

Fix #5: Rebind BitLocker to the Replacement TPM

Problem: BitLocker asks for the recovery key on every startup.

Symptoms:

  • The recovery key unlocks Windows.
  • The TPM is enabled and reports ready.
  • BitLocker returns to recovery after each restart.

Why it happens: BitLocker may still use protectors or startup checks linked to the old board. Suspending and resuming protection links its key to the replacement TPM.

This fix usually stops the repeated recovery screen. Save the recovery key first. One successful unlock doesn’t mean you won’t need it again.

  • Confirm that tpm.msc shows “The TPM is ready for use” and Specification Version 2.0.
  • Save another copy of the BitLocker recovery key before changing protection.
  • Search the Start menu for Manage BitLocker.
  • Open BitLocker Drive Encryption.
  • Find the Windows operating-system drive.
  • Select Suspend protection.
  • Confirm the suspension.
BitLocker management screen with the operating-system drive, protection state, and suspend or resume control highlighted
  • Restart Windows once.
  • Return to Manage BitLocker.
  • Select Resume protection if Windows hasn’t resumed it on its own.
  • Restart the PC twice to test automatic unlocking.

Verification: Windows should start without asking for the recovery key. BitLocker should also show that protection is on.

Fix #6: Clear the TPM Only After Securing Recovery Information

Problem: Windows detects TPM 2.0, but security processor errors continue after firmware and Windows updates.

Symptoms:

  • Windows Security reports a TPM storage or setup problem.
  • TPM errors return after restarting.
  • Windows Hello can’t be recreated even though TPM 2.0 is enabled.
  • The manufacturer recommends clearing the replacement TPM.

Why it happens: The new TPM may contain old setup data. Windows may also have failed to set it up correctly.

Clearing the TPM doesn’t erase ordinary files by itself. It removes keys stored inside the TPM. This can disable Windows Hello and block access to TPM-protected encrypted data. I’d skip this fix unless you’ve saved the recovery key and the earlier fixes failed.

  • Back up the BitLocker recovery key.
  • Back up important files.
  • Open Manage BitLocker and select Suspend protection for the Windows drive.
  • Open Windows Security > Device security > Security processor details > Security processor troubleshooting.
  • Read the warning under Clear TPM.
Security processor troubleshooting page with Clear TPM highlighted and a warning to save the BitLocker recovery key and suspend protection first
  • Select Clear TPM only after checking that your backups and recovery key work.
  • Restart the PC.
  • Approve the firmware confirmation prompt if one appears.
  • Recreate the Windows Hello PIN using Fix #4.
  • Resume BitLocker protection using Fix #5.

Verification: Check tpm.msc, Windows Hello, and BitLocker after two restarts. All three should work without recovery prompts or security processor errors.

Error Messages Quick Reference

Error or statusWhat it meansCorrect response
“Compatible TPM cannot be found”Windows can’t see an enabled, compatible TPM.Enable TPM, Intel PTT, or AMD fTPM in UEFI.
“The TPM is ready for use”Windows recognizes and has set up the TPM.Confirm Specification Version 2.0, then repair BitLocker or Hello.
“Your PIN is no longer available”The Hello credential may still be tied to the old TPM.Sign in with a password and recreate the PIN.
“The security device cannot be found”TPM is disabled, missing, or hidden by firmware.Check UEFI and install approved manufacturer firmware.
BitLocker recovery screenThe startup hardware no longer matches the trusted state.Enter the matching 48-digit recovery key.
Storage ready, Attestation not supportedTPM storage works, but the firmware may not support attestation.Update firmware; ask IT or the manufacturer if policy requires attestation.

Platform-Specific Issues

This repair problem applies to Windows 11. Apple devices don’t use Windows TPM, BitLocker, or Windows Hello, so macOS steps won’t apply.

Workplace and school computers need extra care. A new board changes the device’s TPM and hardware identity. This can break Microsoft Entra registration, Intune enrollment, Windows Hello for Business, and attestation. Contact your IT team before clearing the TPM or removing a managed device record.

Configuration Issues to Check

Fix #7: Correct Firmware and Security Configuration Mistakes

Problem: TPM errors remain even though a firmware setting appears enabled.

Symptoms:

  • The TPM setting turns off again after restart.
  • Specification Version isn’t 2.0.
  • Windows Security shows “Attestation not supported.”
  • The replacement board uses generic or old firmware.

Why it happens: The repair shop may have installed the wrong board revision. It may also have left default settings in place or skipped a required update. A TPM option that won’t stay enabled points to the board or its firmware.

  • Open Settings > System > About.
  • Record the PC model and system type.
  • Press Windows key + R, enter msinfo32, and select OK.
  • Record BIOS Version/Date and BaseBoard Product. Don’t publish the serial number.
  • Compare those details with the manufacturer’s support page for the exact model.
  • Install Windows updates from Settings > Windows Update.
  • Install only the BIOS or TPM firmware made for that exact PC or board revision.
  • Recheck the UEFI TPM setting after the update.
  • Run tpm.msc and confirm Specification Version 2.0.

Verification: The TPM setting should remain enabled after a full shutdown. Windows should keep reporting that the TPM is ready.

Don’t buy a random discrete TPM module. These modules use manufacturer-specific connectors and firmware. An incompatible module may fail or damage the hardware.

Getting Help

Return the computer to the repair shop or contact the manufacturer when:

  • UEFI has no TPM, PTT, or fTPM option after a motherboard replacement.
  • The security processor setting disappears or disables itself.
  • tpm.msc still can’t find TPM 2.0 after the correct firmware update.
  • The replacement board model doesn’t match the repaired computer.
  • TPM hardware errors return after Windows and firmware updates.
  • Attestation is required by work or school policy but remains unsupported.
  • The firmware update fails or the PC becomes unstable.

Collect these details before you call. Exact error text will save everyone a round of guessing.

  • Press Windows key + R.
  • Run tpm.msc and note the exact status and Specification Version.
  • Open Windows Security > Device security > Security processor details. Note the status.
  • Run eventvwr.msc.
  • Check Applications and Services Logs > Microsoft > Windows > TPM-WMI for recent errors.
  • Record the event ID, time, and message. Don’t share recovery keys, account details, device names, or serial numbers.

Use Microsoft’s TPM initialization documentation and the manufacturer’s support page to check the expected firmware settings.

Prevention Tips

Before a planned motherboard replacement:

  • Save the BitLocker recovery key somewhere separate from the PC.
  • Match the saved key to the current recovery key ID.
  • Back up important files to another drive or trusted cloud location.
  • Suspend BitLocker from Manage BitLocker before handing over the computer.
  • Tell the repair provider that BitLocker and Windows Hello are enabled.
  • Resume BitLocker only after Windows recognizes the replacement TPM.
  • Expect to recreate the Windows Hello PIN after the repair.
  • Never include an unredacted recovery key in a screenshot, email, support post, or repair ticket.

A saved recovery key turns the worst part of this repair into a short detour. Keep one offline copy that you can reach without the affected PC.

Wrapping Up

StepActionApplies To
1Enter the saved recovery keyBitLocker recovery screen
2Enable and verify TPM 2.0TPM missing after repair
3Recreate the PINWindows Hello failure
4Suspend and resume BitLockerRepeated recovery prompts
5Return for serviceMissing or unstable TPM hardware

Entering the recovery key and enabling the new board’s TPM fixes this problem in most cases. If recovery appears at every boot, suspend and resume BitLocker next.

A TPM option that vanishes or stays hidden after the correct update needs repair-shop attention. More Windows changes won’t fix a bad board or mismatched firmware.