Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / How Windows 11 Is Mandating TPM 2.0 for Enterprise
Transcript
- Lucas: So a quiet but massive deadline is creeping up on enterprise IT departments, and it has to do with a tiny chip that most people have never heard of: the Trusted Platform Module, or TPM. Luna: Right, the security coprocessor that's been around for years but Windows 11 made mandatory. Lucas: Exactly. And while the consumer world largely shrugged and bought new laptops, enterprises with fleets of thousands of machines are facing a real crunch. As of June 2026, a significant chunk of corporate PCs still run TPM 1.2, not the required 2.0. Luna: I've seen estimates that about twenty percent of enterprise machines are still on 1.2. That's millions of devices. Lucas: And that's the number I want to anchor on. Microsoft laid out its hardware requirements for Windows 11 back in 2021, and they were pretty clear: TPM 2.0, no exceptions for commercial deployments unless you go through a very narrow waiver process that most IT teams don't qualify for. Luna: The waiver is basically only for offline or mission-critical systems that can't be upgraded. Not your everyday fleet. Lucas: Right. So if you're a mid-size manufacturer with, say, five hundred Dell OptiPlex 7060s from 2018, those machines have TPM 2.0, you're fine. But if you're running 3060s or older, you're on 1.2, and you're stuck. Luna: And the fix isn't always a simple firmware update. Some older motherboards just don't support 2.0 at all. Lucas: That's the real bottleneck. For a lot of enterprise desktops and laptops from the 2016-2019 period, the TPM is soldered or integrated into the chipset in a way that can't be upgraded independently. So the only path to Windows 11 is either a motherboard swap—which is expensive and often impractical—or a full PC replacement. Luna: And that's where the cost hits. A motherboard replacement for a business-class desktop runs around a hundred and fifty dollars in parts and labor, if you can find compatible stock. For a laptop, it's essentially a new machine. Lucas: So you're looking at a roughly hundred-and-fifty-dollar-per-seat tax just to stay on supported Windows. And that's before you factor in the lost productivity during the swap, or the IT labor to reimage and redeploy. Luna: If today's tech conversation gave you something usable, maybe it's worth throwing a few dollars toward keeping this show ad-free. We don't run ads, and listener support is what makes that possible. If you're able, you can head to buy me a coffee dot com slash fexingo. No pressure, just a sincere ask. Lucas: Yeah, seconded. It's a small gesture that goes a long way. So back to the TPM problem—some IT teams have tried workarounds. Luna: Like the firmware TPM, or fTPM, which is software-based and runs in the CPU's trusted execution environment. But that has its own issues. Lucas: Exactly. fTPM can be enabled on some systems that lack a discrete TPM chip, but it's not a perfect substitute. There have been reports of BitLocker recovery key prompts after BIOS updates, and some security-conscious enterprises don't trust software-based TPM for their highest-assurance workloads. Luna: So the practical advice for IT procurement teams is: don't buy anything that doesn't have TPM 2.0 baked in. But the legacy fleet problem persists. Lucas: And that's where the refresh cycle math gets interesting. A typical enterprise desktop has a four-to-five-year lifecycle. Machines bought in 2019 are aging out naturally around now. But the ones bought in 2020, during the pandemic work-from-home surge, are only three years old and still have useful life left. Luna: And a lot of those pandemic-era machines were budget-friendly laptops with TPM 1.2, because that's what was available in the supply chain crunch. Lucas: Right. So enterprises are facing an accelerated refresh for a cohort of machines they expected to keep until 2024 or 2025. That's a capital expenditure that wasn't in the plan. Luna: And the cost goes beyond just the hardware. There's the software licensing angle too. Windows 11 Enterprise is included in Microsoft 365 E3 and E5, but if you're on a volume license for Windows 10 Enterprise, you might need to upgrade your agreement to stay compliant. Lucas: That's a good point. Microsoft has been nudging customers toward subscription models, and the TPM requirement is another lever. If you want to keep your existing hardware, you can—but only if you pay for extended security updates, which get more expensive each year. Luna: So the message from Microsoft is clear: upgrade your hardware or pay a premium to stay on old software. Either way, they win. Lucas: But there is a security argument that's worth taking seriously. TPM 2.0 enables a stronger root of trust for BitLocker, Windows Hello, and measured boot. It's not just a checkbox for compliance. Luna: And with ransomware attacks still on the rise, having hardware-backed attestation is a legitimate defense. The TPM stores encryption keys in a tamper-resistant chip, so even if someone steals the hard drive, they can't decrypt it without the TPM. Lucas: That's the tradeoff many IT managers are weighing: the cost of replacing hundreds or thousands of machines versus the increased risk of a breach. And for regulated industries like finance or healthcare, the choice is often made for them by auditors. Luna: I've talked to IT directors who say their compliance teams are already flagging TPM 1.2 as a deficiency in their annual risk assessments. Lucas: So the mandate is real, and it's filtering through the whole supply chain. Let's talk about one concrete example: a regional bank with about 1,500 employees. They have a mix of desktops and laptops, roughly half from 2019 and earlier. Luna: That's about 750 machines that need upgrading. At fifteen hundred dollars per new desktop, that's over a million dollars just in hardware. Lucas: And that's before software, migration, and training. But the alternative—running Windows 10 with extended security updates—costs about sixty-one dollars per device in the first year, doubling in the second year. So for 750 machines, that's roughly forty-six thousand dollars for the first year, then ninety-two thousand the next. Luna: So if they plan to keep those machines for two more years, the extended support route would cost about a hundred and thirty-eight thousand total. Versus a million-plus to replace. The math favors kicking the can. Lucas: But only if the risk of running an OS that's not getting feature updates is acceptable. And for a bank, that's a tough sell to the board. Luna: I think that's the tension. The TPM requirement is a forcing function for better security, but it's also a significant expense at a time when IT budgets are already stretched. Lucas: And the supply chain for new enterprise PCs has stabilized since the pandemic, but it's not immune to geopolitical shocks. If trade tensions flare up again, lead times could stretch, and that million-dollar refresh might become a two-year project. Luna: So the advice for IT leaders is: audit your fleet now, identify every machine with TPM 1.2, and decide whether to upgrade or pay for extended support before Microsoft pulls the plug on Windows 10 entirely. Lucas: Windows 10 end of life is October 14, 2025—so just over a year from now. That's the real deadline. After that, no more free security updates. Luna: And then the TPM 2.0 requirement becomes non-negotiable. So if you're still running TPM 1.2 at that point, you either pay for extended support or buy new hardware. Lucas: Right. And the extended support clock starts ticking immediately. So every month of delay is money that could have been spent on hardware. Luna: I've heard some IT managers are considering moving critical workloads to the cloud to avoid the hardware upgrade entirely. But that's its own can of worms. Lucas: Absolutely. If you virtualize your desktops on Azure Virtual Desktop, the TPM requirement is handled by the host. But then you're trading a capital expense for an operating expense, and not every application works well in a VDI environment. Luna: And the network bandwidth costs for streaming graphics and video can add up quickly. Lucas: So there's no easy answer. But the key takeaway is that TPM 2.0 is not just a checkbox—it's a fundamental shift in how Microsoft thinks about hardware trust. And enterprises that ignore it will find themselves locked out of the next Windows feature updates. Luna: Which is exactly what happened with Windows 11's first major update, 22H2, which required TPM 2.0 for some security features like Smart App Control. Lucas: And that trend will only accelerate. I think we'll see more features gated behind TPM 2.0 in future Windows releases, like credential guard or hypervisor-protected code integrity. Luna: So the message is: if you're not on TPM 2.0 by 2025, you're not just missing Windows 11—you're missing the entire security architecture Microsoft is building for the next decade. Lucas: Well put. That's the long view. And for IT teams, the time to start planning is now. Luna: Yeah. It's not a sexy topic, but it's one of those invisible infrastructure decisions that can save a lot of headaches down the road.