What Is a TPM? A Plain-English Guide

What is a TPM

When Windows 11 insisted that PCs have a “TPM 2.0,” a lot of people met the term for the first time and wondered what this mysterious chip actually does. It turns out to be a small but important guardian of your device’s secrets. Our GetMyPassword team explains what a TPM is and why it matters for your security.

What a TPM is
What a TPM is and why it matters.

What a TPM is

A TPM (Trusted Platform Module) is a dedicated security chip on your computer that safely stores cryptographic keys and other secrets. Instead of keeping sensitive keys in ordinary memory where malware could read them, the device hands them to the TPM, which guards them in hardware. It is a small vault built into the machine — able to perform certain security operations without ever exposing the keys it holds.

What it protects

  • Disk encryption keys — features like device encryption store their keys in the TPM, so a stolen drive stays locked.
  • Sign-in security — it backs convenient, safer logins such as a device PIN or biometric unlock.
  • Passkeys and credentials — it can hold the secret half of modern passwordless logins on the device.
  • Boot integrity — it helps verify the system started with trusted, untampered software.

Why it makes you safer

The TPM’s value is that secrets live in hardware, not in readable software. If a thief steals your laptop, your encrypted drive cannot be unlocked without the keys sealed inside the TPM — and those keys are tied to that specific machine. It also resists tampering: try to move the drive to another computer, and the protected keys do not come along. This quiet chip is a big reason a lost modern laptop is far less of a disaster than it once was.

A TPM keeps your device’s most important keys in a hardware vault, not in software a thief can read. It is why a stolen, encrypted laptop is a brick rather than an open book.

What it does not replace

A TPM secures keys on your device; it does not protect your online accounts from a weak or reused password. If someone simply logs into your email from across the world with a leaked password, the chip on your laptop never enters the picture. So treat the TPM as one strong layer and keep the others: turn on device encryption to use it, and give every account a unique password from our password generator with two-factor authentication.

Frequently asked questions

What is a TPM?

A Trusted Platform Module is a dedicated security chip that safely stores cryptographic keys and secrets in hardware, so they are not exposed in ordinary memory where malware could read them.

Why does Windows 11 require a TPM?

It raises the baseline for device security: the TPM protects disk encryption keys, supports safer sign-in like a PIN or biometrics, can hold passkeys, and helps verify the system booted with trusted software.

Does a TPM protect my online accounts?

No. A TPM secures keys on your device, but it does not stop someone logging into your accounts elsewhere with a weak or leaked password. You still need a unique password per account and two-factor authentication.

Help your friends stay safe. Share this article!