win11 requires TPM 2.0, is this a deal breaker?

Discussion in 'Windows 11' started by god_paul, Jun 25, 2021.

  1. sutt359

    sutt359 MDL Novice

    Apr 11, 2011
    5
    1
    0
    Just tried turning off TPM then flashing didn't find it as expected.

    Then did turned on but disabled same issue blocked by TPM fw policy
     
  2. toyo

    toyo MDL Senior Member

    Aug 14, 2009
    472
    313
    10
    #142 toyo, Jul 7, 2021
    Last edited: Jul 7, 2021
    Installed 11 in a VMware VM (UEFI+Secure Boot enabled), it went fine without TPM and without VBS being enabled. Encrypted the machine and added a TPM from VMWare, VBS still inactive, although the TPM initialization seems to take a lot of time.
    If things remain like this (which might not be the case in later builds), it's mostly fine.
    But the essential (at this time, in this build) is that VBS is not automatically enabled. At least not for VM. Not planning to install it on my PC yet.
    Oh and 11 is quite fast, reboots way faster than 10 at least on VM, and seems to have no issues with HDD thrashing like 10 VMs. Somewhat promising.
     
  3. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,419
    11,688
    240
    Vm installs do not have any hardware check beyond available ram and disk space. There is a specific bypass in the setup process that detects virtual machines and voids out any hardware checks.
     
  4. wutno

    wutno MDL Novice

    Dec 6, 2014
    25
    14
    0
    I don't necessarily mind VBS, my issue is I used devices with drivers that haven't been updated since 2013 and aren't supported if using VBS.
     
  5. Cipher

    Cipher MDL Member

    May 31, 2008
    129
    37
    10
    #146 Cipher, Jul 12, 2021
    Last edited: Jul 12, 2021
    I see the TPM requirement as a gift to be honest.
    As you now have a BIOS level selectable option that should block the automatic update from W10 to W11.

    So thanks Microsoft... that is exactly very handy. :)

    /Now watch motherboard makers start enabling the fTPM option by default and remove the ability to change it with their new BIOS updates lol.
     
  6. acer-5100

    acer-5100 MDL Guru

    Dec 8, 2018
    4,003
    2,923
    150
    #147 acer-5100, Jul 12, 2021
    Last edited: Jul 12, 2021
    Yeah the troian horse was a gift as well.

    Both donations share the same purpose :D

    Jokes aside you can have the same effect using native VHDs, which have an huge pile of advantages over the old school installations on physical partitions, but don't like in place upgrades (If you want to upgrade you need to mount them in Hyper-V /VMware using a second system, which can be running on native VHDs as well)
     
  7. acer-5100

    acer-5100 MDL Guru

    Dec 8, 2018
    4,003
    2,923
    150
    Yeah...

    I remember a TV series episode from some years ago where a criminal wasn't on security cameras because they were broken.

    One of the younger CIA agent came quickly with a video footage of the scene

    The older agent's boss asked "how did you get that?", the agent replied "social networks... people are doing our job, for free" o_O
     
  8. ciscokid

    ciscokid MDL Senior Member

    Jun 3, 2007
    331
    79
    10
    Any way to emulate TPM and mod the bios like back when we used to mod the bios to add SLIC? I'm not an expert on this but could this be an option for us poor folks who can't buy a new computer just because Microsoft says so?
     
  9. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,768
    7,710
    210
    TPM is a complete crypto chip. Hardly can be emulated, if at all. Plus, it must be available from the very start, as it controls the boot process.

    SLIC was only a non-critical table in the firmware. Not comparable.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,074
    397
    60
    On W11 by-default and on W10 with the memory integrity option enabled, game FPS seems fine, but I notice a significant I/O performance drop (compared to a W10 install with mitigations disabled). Game loading screens are longer, the worst one being about 10 seconds longer. But that's seemingly the only issue I notice.

    I don't imagine the impact will be that significant, at least on the most recent hardware architectures (Ampere, RDNA2, etc). Hasn't Xbox been doing this for a while now?

    If that memory integrity option on W10 does the same performance impact as W11, then game FPS was overall fine. While I/O takes a hit, I wonder if faster I/O can be returned with DirectStorage?
     
  11. toyo

    toyo MDL Senior Member

    Aug 14, 2009
    472
    313
    10
    Are Memory Integrity and VBS activated by default in Windows 11? Can you disable them if yes?
     
  12. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,074
    397
    60
    I don't believe they were enabled by-default back in 22000.100; I've always left SVM (secure virtual machine) CPU option disabled in firmware and I don't think those features would work or enable without that.
     
  13. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,074
    397
    60
    I don't believe they were enabled by-default back in 22000.100; I've always left SVM (secure virtual machine) CPU option disabled in firmware and I don't think those features would work or enable without that.
     
  14. jul12

    jul12 MDL Member

    Jan 28, 2011
    127
    10
    10
    It is mistake to need TPM to install Windows 11 and encrypt filesystem!
     
  15. evan968

    evan968 MDL Novice

    Feb 10, 2019
    4
    2
    0
    You don't need TPM to encrypt file system. You can configure Bitlocker not to use TPM or use 3rd party encryption software.
     
  16. bjf2000

    bjf2000 MDL Expert

    Apr 11, 2008
    1,101
    199
    60