You've clicked launch on Valorant, and Vanguard just throws up this wall: your TPM 2.0 isn't enabled, game won't start. Frustrating, right? This isn't some obscure bug that only happens to one person. I see it constantly, and the good news is it's almost always fixable in under 30 minutes if you follow this properly.
TL;DR
Valorant TPM 2.0 Windows 11 error means Secure Boot or TPM 2.0 is disabled in your BIOS. Open tpm.msc to check status, then access BIOS (Settings → Recovery → Advanced startup → UEFI Firmware Settings) and enable both Secure Boot and TPM 2.0 (or fTPM/PTT). Reboot and verify with tpm.msc again. Takes 15-25 minutes. If your motherboard has no TPM option at all, it doesn't support TPM 2.0 and you'll need a newer board.
Key Takeaways
- TPM 2.0 is a security requirement for Vanguard anti-cheat on Windows 11, not optional
- The error happens when TPM 2.0 or Secure Boot is disabled in BIOS, not Windows settings
- You need BIOS access (not Windows BIOS settings) to fix this properly
- Modern motherboards (2018+) support TPM 2.0 either as dedicated chip or firmware version (fTPM/PTT)
- Enabling these features has zero impact on gaming performance
At a Glance
- Difficulty: Easy
- Time Required: 15-30 mins
- Success Rate: 85% of users
- Requires BIOS Access: Yes
What Causes Valorant TPM 2.0 Windows 11 Error?
Here's the underlying issue: Vanguard, Valorant's anti-cheat system, doesn't trust your machine until it can verify that your hardware is genuine and hasn't been modified. TPM 2.0 is the tech that does that verification. Think of it like showing ID at a venue, except it's your motherboard proving it's legitimate.
Windows 11 actually requires TPM 2.0 at install time anyway, but having it enabled during install doesn't mean it stays enabled. You might have disabled it for overclocking, or your BIOS defaulted to it being off. Secure Boot is the same story. Both sit in your BIOS firmware, not in Windows settings, so flipping toggles in Windows won't help.
The really common culprits are straightforward: someone tweaked BIOS for performance tuning and turned TPM off without realizing, or an older system never had it enabled from the factory. Occasionally a BIOS update resets these settings to defaults, which sometimes means off. And yeah, there are older motherboards out there from before TPM 2.0 became standard, though that's getting rarer by the year.
Quick Check: Verify Your TPM and Secure Boot Status Right Now
Check TPM 2.0 Status in Windows Easy
- Open TPM Management Console
Press the Windows key on your keyboard, typetpm.msc, and press Enter. - Look for the Status Line
You should see a message that says 'The TPM is ready for use' and 'Specification Version: 2.0'. If you see 'The TPM is not ready for use' or any version other than 2.0, TPM is disabled in your BIOS. - Take a Screenshot
Grab one for reference before you go into BIOS. You'll want to know what the current state is.
Now let's check Secure Boot status, which is just as critical.
Verify Secure Boot is Enabled Easy
- Open System Information
Press Windows key, typesystem information, and open it. - Find the Secure Boot State Field
Scroll down until you see 'Secure Boot State'. It must show 'On'. Anything else (Off, Unsupported) means Secure Boot isn't active. - Note the Result
If it says 'On', Secure Boot is good. If it says 'Off', you'll need BIOS changes.
Valorant TPM 2.0 Windows 11 Intermediate Fix: Enable TPM in BIOS
This is where most people get it done. You're going to access your BIOS firmware settings and flip two switches: TPM 2.0 and Secure Boot. Sounds technical, but it's genuinely just a few clicks.
The challenge is that every motherboard manufacturer (MSI, ASUS, Gigabyte, ASRock, etc.) names menus slightly differently. But they're all looking for the same two things. I'll walk you through the typical layout, and your BIOS will be close enough that you'll find what you need.
Enter BIOS Through Windows 11 Recovery Menu Easy
- Open Settings
Press Windows key + I to open Settings. - Navigate to Recovery
Go to System → Recovery (on the left sidebar). Scroll down and click 'Advanced startup'. - Select 'Restart Now'
Click the blue 'Restart now' button. Your system will reboot into the recovery menu. - Choose Troubleshoot
You'll see options. Click 'Troubleshoot'. - Go to Advanced Options
Click 'Advanced options'. - Select UEFI Firmware Settings
Click 'UEFI Firmware Settings'. Your system will restart again and boot straight into BIOS.
Once you're in BIOS, the interface depends on your motherboard. ASUS boards tend to have a graphical BIOS with lots of tabs. MSI boards are similar. Older boards might be text-based. But they all have a Security tab or similar where TPM lives.
Enable TPM 2.0 in BIOS Easy
- Look for Security or Trusted Computing Tab
Use arrow keys to navigate (or mouse if your BIOS has a graphical interface). Most boards have a 'Security' or 'Trusted Computing' tab or menu. Click or navigate into it. - Find TPM 2.0 Option
Look for 'TPM 2.0', 'TPM Device', 'Trusted Computing', or on AMD boards 'fTPM' (firmware TPM). On Intel boards, you might see 'PTT' (Platform Trust Technology). They're all the same thing. - Set It to Enabled
Select the option, press Enter or click on it, and change it from Disabled (or Off) to Enabled (or On). - Confirm the Change
The BIOS will update the setting immediately. You'll see it change on screen.
Enable Secure Boot in BIOS Easy
- Navigate to Boot Tab
Look for a 'Boot' tab in your BIOS menu, or sometimes 'Security' again depending on your board. Secure Boot is usually under Boot. - Find Secure Boot Setting
Look for 'Secure Boot' or 'Secure Boot Control'. It might be called 'Secure Boot Mode'. - Change to Enabled
Select it and set it to Enabled or On. - Watch for Secure Boot Keys Message
Some BIOS versions will ask if you want to load default keys. Say yes. Default keys are what Windows 11 expects and they're totally safe.
Now save your changes and reboot.
Save BIOS Changes and Reboot Easy
- Press F10 or Find Save Option
Most BIOS boards use F10 to save and exit. Some boards have a 'Save' or 'Exit' menu option. Press F10 or navigate to Save Changes. - Confirm You Want to Save
BIOS will ask 'Save changes and exit?' Select Yes. - System Reboots
Your PC will restart. Windows will boot normally. This might take a few seconds longer than usual because Windows is recognizing the changes.
Once Windows is back up, let's verify that the changes stuck.
Verify Settings After Reboot Easy
- Run tpm.msc Again
Press Windows key, typetpm.msc, and open it. Verify it now shows 'The TPM is ready for use' and 'Specification Version: 2.0'. - Check System Information Again
Open System Information and confirm Secure Boot State says 'On'. - Launch Valorant and Vanguard
Start the Valorant client and let Vanguard initialize. It should load without the TPM error.
Advanced Valorant TPM 2.0 Windows 11 Fixes: Hardware and Firmware Issues
If you've done the above and Valorant still complains about TPM 2.0, or if your BIOS literally has no TPM option, there are a few deeper issues to investigate. This section covers the edge cases: hardware that doesn't support TPM, corrupted Secure Boot keys, and BIOS that needs updating.
Check for TPM Hardware Support Medium
- Enter BIOS Again
Use the same recovery method from earlier to get back into BIOS (Settings → Recovery → Advanced startup → UEFI Firmware Settings → Restart now). - Search Every Tab Carefully
Don't assume TPM is just in Security. Check Boot, Advanced, System, Chipset, Integrated Peripherals, anything that sounds relevant. Use Ctrl+F or navigate methodically through every menu. - Check Your Motherboard Manual
Search online for your motherboard model (check System Information or your receipt if unsure) and find the manual PDF. Search the manual for 'TPM' to see exactly what it's called and where it's located. - Update BIOS if TPM Still Missing
If TPM genuinely doesn't appear after checking everywhere, your BIOS might be too old. Visit your motherboard manufacturer's website (ASUS, MSI, Gigabyte, ASRock), download the latest BIOS for your exact board model, and update it. This is covered in the next solution.
Update BIOS to Latest Version Hard
- Find Your Motherboard Model
Open System Information (Windows key → 'system information'). Look for the 'System Model' or 'Board Name' field. Write it down exactly as shown (e.g., 'ASUS ROG STRIX B550-F GAMING WIFI'). - Visit Manufacturer Support Site
Go to ASUS.com, MSI.com, Gigabyte.com, or ASRock.com. Search for your board model in their support page. Find the BIOS downloads section. - Download Latest BIOS File
Download the newest BIOS file for your exact board model. It'll be a .BIN or .ROM file. Save it to a USB stick formatted as FAT32 (not NTFS). Create a folder called 'BIOS' on the stick and put the file there. - Boot Into BIOS with USB Inserted
Insert the USB stick, restart, and enter BIOS again (F2, Del, or F12 on restart depending on your board, or use the recovery method). - Find BIOS Update or Firmware Update Option
Look for 'Update BIOS', 'BIOS Flashback', 'Q-Flash', or 'USB BIOS Flasher' in your BIOS menus. Different boards name it differently, but there's always a firmware update option. - Select Your USB Drive and the BIOS File
Follow the on-screen prompts. Select the USB device, then select the BIOS file you downloaded. Confirm and let it flash. This takes 2-5 minutes. Do not power off or unplug the PC during this process. - System Reboots Automatically
After flashing, your PC will restart. The screen might go dark for longer than usual. Wait patiently. - Re-enable TPM 2.0 and Secure Boot
Go back into BIOS and enable TPM 2.0 and Secure Boot again. They may have reset to defaults after the BIOS update. Repeat the steps from the intermediate section above.
Fix Invalid Secure Boot Keys Hard
- Enter BIOS
Use Settings → Recovery → Advanced startup → UEFI Firmware Settings again. - Find Key Management Option
Look for 'Secure Boot' settings, then a submenu called 'Key Management', 'Reset to Setup Mode', or 'Load Defaults'. This varies by board. - Load Default Secure Boot Keys
Select the option to load or restore default keys. Confirm the action. This resets Secure Boot to factory defaults, which is what Windows 11 expects. - Set Platform Mode to User Mode
Some BIOS versions have a 'Platform Mode' setting near Secure Boot. Make sure it's set to 'User Mode', not 'Setup Mode'. - Enable Secure Boot
Now enable Secure Boot again (it should stick this time). - Save and Reboot
Press F10, confirm save, and reboot.
After any of these advanced fixes, verify TPM and Secure Boot again using tpm.msc and system information, then relaunch Valorant.
Preventing Valorant TPM 2.0 Windows 11 Errors Going Forward
Once you've got this sorted, there are some easy habits that prevent it from happening again.
Keep your BIOS up to date. Visit your motherboard manufacturer's website twice a year and check if there's a newer BIOS version. Updates often include TPM improvements and Secure Boot fixes. You don't need to update obsessively, but staying within 1-2 versions of the latest is sensible.
Never disable TPM 2.0 or Secure Boot for overclocking or performance tweaks. I get it, someone on a forum says disabling this or that gets you 2 extra FPS. It won't. TPM and Secure Boot have zero gaming impact. The only thing disabling them does is break Vanguard, and you lose the ability to play.
Monitor your TPM status monthly. It's paranoia-level easy: just open tpm.msc once a month and check it still shows 'ready for use'. Takes 10 seconds. If something ever disables it without your knowing, you'll catch it before trying to launch Valorant.
Keep Windows 11 fully updated. Windows Update includes security patches that can improve TPM and firmware detection. Don't delay updates; they help more than they hurt.
Backup your BIOS settings before tweaking. Many BIOS versions have a 'Save Settings to USB' or 'Profile Save' option. Use it before you make any changes. If something goes wrong, you can restore the previous configuration quickly.
Valorant TPM 2.0 Windows 11 Summary
You're probably reading this because you just want to play Valorant, and TPM 2.0 is in the way. Fair enough. The reality is simple: check TPM status using tpm.msc, enable it and Secure Boot in BIOS if they're off, reboot, and you're done. Most people finish in 15-20 minutes. If your board doesn't have TPM 2.0 in BIOS at all, update the BIOS firmware first, then enable it. Only if your motherboard is genuinely ancient (pre-2016) will hardware be the limiting factor, and that's when you're looking at a motherboard upgrade.
Vanguard's requirement for Valorant TPM 2.0 Windows 11 support exists for a reason: it keeps cheaters from running modified drivers and modified bootloaders. It's annoying to deal with once, but after you enable it, you forget about it forever. No performance hit, no hassle, just better security for the game you're playing. Enable it, relaunch, and get back to playing.

