Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Clear TPM via Management Console or Windows Defender Center App
  • maxresdefault 2 6
    How to create an AMI from the Command line AWS/Azure/OpenShift
  • powershell logo
    Connecting to a remote server failed and WinRM cannot process the request: Error code 0x8009030e occurred while using Kerberos authentication, and a specified logon session does not exist Scripts
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • Screenshot 2020 06 23 at 10.52.52
    How to uninstall Microsoft SQL Server on Windows Oracle/MSSQL/MySQL
  • 1 kAUgwdVYmcVgUSXiwUkObw
    Error 0x801c001d – Automatic registration failed: Failed to look up the registration service from AD Windows Server
  • vvd
    Unable to connect to Eduroam WLAN: WiFi Username remembered on MAC Mac
  • banner 1
    How to Export and remove Passwords in Firefox Backup
  • Featured image
    Tamper Protection for Microsoft Defender on Windows 10 [Part 1] Security | Vulnerability Scans and Assessment

Clear TPM via Management Console or Windows Defender Center App

Posted on 28/08/202111/12/2024 Christian By Christian No Comments on Clear TPM via Management Console or Windows Defender Center App
TPM clear procedure

In this article, we shall discuss “Clear TPM via Management Console or Windows Defender Center App”. Clearing or resetting the TPM resets it to an unowned state. After the TPM is cleared, the Windows 10 OS will automatically re-initialize it and take ownership again.  In this way, the BitLocker encryptions work without any issues. Here is a guide on how to clear, enable or disable TPM in Windows via the BIOS or UEFI. The system uses TPM functions primarily to measure system integrity and create and manage keys.

During the boot process, the TPM measures and records the loaded boot code, including firmware and operating system components. The integrity measurements can be used as evidence for how a system started and to make sure that a TPM-based key was used only when the correct software was used to boot the system.

Kindly refer to some of these related guides: How to clear, enable or disable TPM in Windows via the BIOS or UEFI, BitLocker Back Door:TPM Only: From stolen laptop to inside the company network. Here is a guide on ‘SSD TRIM: Delete files permanently without using the Recycle Bin“.

Here are some reasons for resetting the TPM

  • When preparing for a clean installation can help ensure that the new OS can fully deploy any TPM-based functionality that it includes, such as attestation. However, even if the TPM is not cleared before a new operating system is installed, most TPM functionality will probably work correctly.
  • Since there are ways to extract BitLocker keys from a TPM, it’s better to be safe to clear TPM on a device before discarding them.
  • Encrypt SSD with BitLocker and then clear the TPM module to destroy the keys. In this way, the keys cannot be recoverable. 

Microsoft advises not to clear TPM directly from UEFI. This can lead to data loss etc. This is because you may not have access to the recovery key.

Note: It is recommended to use the functionality in the operating system (such as TPM.msc) to clear the TPM.

In this way, we will not experience data loss as we saw already from our test. Here is a guide on how to backup existing and new BitLocker recovery keys to Active Directory, and BitLocker recovery keys in Active Directory.

Clearing via the TPM.msc Snap-in (Management console)

From the run dialog windows, type TPM.msc. This will open the TPM snap-in window as shown below.

Management console TPM clearing

1: You need to be an administrator on the device to be able to clear the TPM. For more information, see the following link: There was an error opening the Trusted Platform Module snap-in: You do not have permission to open the Trusted Platform Module Console.

2: Also, you could also launch the TPM management console via the MMC and select TPM Management for the Local Computer. I will demonstrate the steps in the next guide.

3: You could search for TPM.msc from the search window as shown below and click on open.

Windows Defender Center TPM clearing
From the run dialog windows, type TPM.msc. This will open the TPM snap-in window as shown below. 
- You need to be an administrator on the device to be able to clear the TPM. for more information, see the following link: There was an error opening the Trusted Platform Module snap-in: You do not have permission to open the Trusted Platform Module Console.

Also, you could also launch the TPM management console via the MMC and select TPM Management for the Local Computer. I will demonstrate the steps in the next guide. 

In the Action pane, click on Clear TPM (TPM Loschen) as shown below

TPM clear procedure

You will be notificed as shown below that your device will be restated. Click on the close button.

Management console TPM clearing

In the Window below, click on Restart as shown below.

tpm1

As you can see below, the device is restarted. As discussed in the first paragraph, starting with Windows 10, the operating system automatically initializes and takes ownership of the TPM.

This is a change from previous operating systems, where you would initialize the TPM and create an owner password.

tpmdel

Nonetheless, Windows 10, the operating system automatically initializes and takes ownership of the TPM.

Also, see how to fix your device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM. Here is how to fix “this device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker” and how to enable Bitlocker Pre-Boot Authentication via the Group Policy.

Via the Windows Defender Security Center App

To do follow these steps, follow the steps below. 
-> Click on the Start button
-> Settings 
-> Update & Security 
-> Windows Security and
-> Device security.
-> Under Security processor, select Security processor details.
-> Select Security processor troubleshooting, and then under Clear TPM, select Clear TPM.

Alternatively, you could double-click the shield icon in the Windows Defender Security Center system tray to start.

Screenshot-2021-08-28-at-15.07.23

– This will open the Windows Defender Security Center app.
– Click on Device Security.
– them, click Security processor details.
– Click Security Processor Troubleshooting and click on Clear TPM.

Screenshot-2021-08-27-at-10.44.27

You will be prompted to restart the computer. During the restart.

Screenshot-2021-08-27-at-10.45.25

Moreover, when the PC restarts, your TPM will be automatically prepared for use by Windows. In addition, This is because the operating system will automatically initialize and take ownership of the TPM again.

Why clear TPM

Preparing for a clean installation in this way helps ensure that the new operating system can fully deploy any TPM-based functionality that it includes, such as attestation.

However, even if the TPM is not cleared before a new operating system is installed, most TPM functionality will probably work correctly.

Note: Furthermore, Clearing the TPM resets it to an unowned state. After you clear the TPM, the Windows 10 operating system will automatically re-initialize it and take ownership again.

I hope you found this blog post on “Clear TPM via Management Console or Windows Defender Center App” helpful. However, Please let me know in the comment session if you have any questions.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Microsoft Windows, Windows 10, Windows Server 2016

Post navigation

Previous Post: There was an error opening the Trusted Platform Module snap-in: You do not have permission to open the Trusted Platform Module Console
Next Post: CI/CD Pipeline: Your First in Azure DevOps with ASP.Net Core

Related Posts

  • wds
    What are the differences between Lite-Touch and Zero-Touch installation? Windows
  • xcdbfg
    Folder Access Denied, you require permission from SYSTEM: Unable to delete old Windows folder Windows
  • Fix Windows Installer Service Could Not Be Accessed Error
    How to Fix the “Windows Installer Service Could Not Be Accessed” Error While Installing an Application Windows
  • Featured image BitLocker AES XTX 256
    Enable BitLocker AES-XTX 256 Encryption Security | Vulnerability Scans and Assessment
  • find my device banner
    How to Enable Find My Device on Windows 11 Windows
  • configure kerberos
    Configure Kerberos Delegation in Windows Windows

More Related Articles

wds What are the differences between Lite-Touch and Zero-Touch installation? Windows
xcdbfg Folder Access Denied, you require permission from SYSTEM: Unable to delete old Windows folder Windows
Fix Windows Installer Service Could Not Be Accessed Error How to Fix the “Windows Installer Service Could Not Be Accessed” Error While Installing an Application Windows
Featured image BitLocker AES XTX 256 Enable BitLocker AES-XTX 256 Encryption Security | Vulnerability Scans and Assessment
find my device banner How to Enable Find My Device on Windows 11 Windows
configure kerberos Configure Kerberos Delegation in Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • maxresdefault 2 6
    How to create an AMI from the Command line AWS/Azure/OpenShift
  • powershell logo
    Connecting to a remote server failed and WinRM cannot process the request: Error code 0x8009030e occurred while using Kerberos authentication, and a specified logon session does not exist Scripts
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • Screenshot 2020 06 23 at 10.52.52
    How to uninstall Microsoft SQL Server on Windows Oracle/MSSQL/MySQL
  • 1 kAUgwdVYmcVgUSXiwUkObw
    Error 0x801c001d – Automatic registration failed: Failed to look up the registration service from AD Windows Server
  • vvd
    Unable to connect to Eduroam WLAN: WiFi Username remembered on MAC Mac
  • banner 1
    How to Export and remove Passwords in Firefox Backup
  • Featured image
    Tamper Protection for Microsoft Defender on Windows 10 [Part 1] Security | Vulnerability Scans and Assessment

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,832 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.