DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Redmond desk6 min

How to Fix “PCR7 Not Supported” in Windows 11

PCR7 not supported usually indicates a measured-boot binding issue, not a failed TPM. Check all Device Encryption reasons, verify UEFI and Secure Boot, test without boot-time peripherals, inspect BitLocker’s PCR profile, and avoid risky TPM resets.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“PCR7 Configuration: Binding Not Possible” usually does not mean your TPM is broken. It means Windows could not bind BitLocker or automatic Device Encryption to the Secure Boot measurements it expected. Check the complete status in msinfo32 first, then verify UEFI/Secure Boot, disconnect boot-time peripherals, and inspect the active BitLocker protector before changing firmware or clearing security hardware.

What PCR7 means

A Trusted Platform Module (TPM) records measurements of firmware and early-boot components in platform configuration registers (PCRs). PCR7 represents the Secure Boot policy and signatures used to validate that boot chain. BitLocker can use those measurements to unlock automatically only when the boot environment matches the trusted configuration.

PCR7 is therefore a boot-integrity and encryption-binding profile, not a separate chip and not a requirement for Windows 11 to start. Microsoft identifies disabled Secure Boot and certain peripherals connected during boot as common causes. See Microsoft’s Device Encryption guidance.

Identify exactly what Windows is reporting

  1. Press Windows key + R, enter msinfo32, and press Enter. Run it as administrator if possible.
  2. Review BIOS Mode, Secure Boot State, PCR7 Configuration, and Automatic Device Encryption Support.
  3. For normal PCR7 binding, the key values are typically BIOS Mode: UEFI, Secure Boot State: On, and PCR7 Configuration: Bound.

The Automatic Device Encryption field may list several independent failures, including an unusable TPM, unconfigured WinRE, a failed Hardware Security Test Interface, missing Modern Standby, or unapproved DMA-capable devices. Resolve the complete list rather than treating PCR7 as the only problem. Microsoft explains these checks at support.microsoft.com.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
64GB Bootable USB Installer for Windows 11, 10 & 7 Home/Pro with WinPE Repair Tools
  • [Win OS Install or reinstall] — Boot from the USB to install or reinstall Win 11, 10, or 7 Home & Pro editions. Includes OS installations and reinstallations media plus WinPE Utility Suite.
  • [WinPE Repair & Recovery Tools] — Boot into the included WinPE utility suite to backup system and important files, troubleshoot startup problems, repair boot issues, recover data, recover Win User accounts password, and diagnose common PC problems.
  • [All-in-One PC Rescue USB] — Combines Win 11, 10, and 7 installation media with PC repair, recovery, and diagnostic tools on one bootable 64GB USB drive, helping you troubleshoot and restore a computer without needing multiple discs or downloads.
  • [Support] — Full instructions are included in packaging plus a printable copy of the instructions with troubleshooting information on the device. Also, a video “How to boot from a bootable USB drive.mp4” to help guide you through starting a PC from a USB drive. If you need help using the USB please contact us for assistance, we are here to help.
  • [Video] - If you are new to booting from a USB drive or need a refresher see our video "How to boot from USB drive" both in description and on USB device.

Check whether the drive is already protected

Open an elevated Command Prompt or PowerShell and run:

manage-bde -protectors -get %systemdrive%

PowerShell also accepts:

manage-bde -protectors -get $env:systemdrive

Under the TPM protector, a PCR7 configuration may show:

PCR Validation Profile:
    7, 11

When PCR7 binding is unavailable, Microsoft documents an alternate profile such as 0, 2, 4, 11. If BitLocker is active with that profile, the volume can still be protected; do not make risky changes merely to change the System Information label. Details are in Microsoft’s PCR7 troubleshooting article.

Fix 1: Disconnect devices present during boot

Microsoft lists some docks, specialized network interfaces, external graphics hardware, and other boot-connected peripherals as possible causes. This is a diagnostic test, not a claim that every USB device causes PCR7 failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Shut the computer down completely.
  2. Disconnect USB-C or Thunderbolt docks, external GPU enclosures, KVM switches, USB boot media, external storage, unusual PCIe hardware, and specialized network adapters.
  3. Start Windows with only essential devices attached.
  4. Open msinfo32 again and check PCR7 Configuration.
  5. If it becomes Bound, reconnect devices one at a time and reboot to identify the device that changes the result.

Fix 2: Use UEFI and enable Secure Boot

First test Secure Boot from an elevated PowerShell window:

Confirm-SecureBootUEFI

True means Secure Boot is enabled. An error saying the computer is not operating in UEFI mode usually indicates Legacy BIOS or CSM mode.

To reach firmware settings from Windows, select Settings → System → Recovery → Advanced startup → Restart now, then choose Troubleshoot → Advanced options → UEFI Firmware Settings. In the manufacturer’s firmware interface, enable UEFI boot mode, Secure Boot, and TPM or firmware TPM if those options are disabled.

Back up important files and make sure any BitLocker recovery key is available before changing firmware. Switching an existing Legacy/CSM installation to UEFI can make Windows unbootable if its partition layout and boot configuration are not compatible. After saving changes, run Confirm-SecureBootUEFI again and recheck msinfo32. If Secure Boot was already on, continue with the remaining checks; enabling it does not fix every PCR7 cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix 3: Verify the TPM, without clearing it

Press Windows key + R, enter tpm.msc, and confirm that Windows reports The TPM is ready for use. Check for TPM 2.0 where the console displays the specification version.

A ready TPM proves that Windows can communicate with it, but it does not prove that the complete firmware, Secure Boot policy, bootloader, and peripheral chain can produce PCR7 measurements. Do not clear the TPM as routine troubleshooting: clearing it can invalidate protectors and trigger BitLocker recovery.

Fix 4: Investigate dual-boot and custom boot components

Secure Boot can be visibly enabled while PCR7 remains unavailable. Potential causes include Linux or other dual-boot loaders, custom Windows boot managers, third-party preboot security software, firmware utilities inserted into the boot path, modified Secure Boot databases, and UEFI debug mode.

Microsoft notes that early-boot components signed with the UEFI CA 2011 certificate rather than the Microsoft Windows PCA 2011 certificate can prevent PCR7 binding. In that situation BitLocker may select PCRs 0, 2, 4, 11 instead of 7, 11. Do not delete a bootloader or reset Secure Boot keys blindly: those actions can make another operating system or custom signed tool unbootable.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix 5: Update BIOS, UEFI, and manufacturer firmware

  1. Identify the exact computer or motherboard model.
  2. Download firmware only from the manufacturer’s official support page.
  3. Read release notes for Secure Boot, measured-boot, TPM, DMA, or ACPI fixes.
  4. Keep reliable power connected during the update.
  5. Suspend BitLocker if Windows or the manufacturer instructs you to do so, and keep the recovery key available.

Firmware updates can correct incorrect PCR measurements, Secure Boot database problems, TPM firmware defects, DMA behavior, or inaccurate Modern Standby reporting, but they are not guaranteed to fix PCR7. Microsoft’s OEM guidance says some measured-boot defects require a manufacturer fix or support intervention: BitLocker guidance for OEMs.

Rank #2
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check other automatic-encryption prerequisites

If System Information lists another failure, PCR7 may not be the blocker that determines eligibility.

Modern Standby

Run:

powercfg /a

Some automatic Device Encryption configurations require Modern Standby. This requirement does not mean every manual BitLocker installation requires it. A Microsoft external moderator describes this distinction in this Microsoft Q&A response; treat it as community guidance rather than a universal specification.

Other listed failures

  • WinRE is not configured.
  • Unapproved DMA-capable devices are detected.
  • The Hardware Security Test Interface failed.
  • The TPM is unavailable or not initialized.
  • Firmware security settings are unsupported.

Fix the specific condition shown in Automatic Device Encryption Support; a PCR7 change alone will not clear unrelated failures.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect logs when the basic checks do not explain it

Advanced users and IT administrators can review Event Viewer → Applications and Services Logs → Microsoft → Windows → BitLocker-API, the BitLocker Management log where available, and files under C:WindowsLogsMeasuredBoot. Microsoft’s OEM documentation explains these locations and provides a TBSLogGenerator.exe procedure for detailed PCR measurements. Most consumers should use the entries to identify a firmware or boot-path fault rather than attempt to parse binary measurements themselves.

What to do if PCR7 remains “Binding Not Possible”

BitLocker is already enabled

Use the protector command above to identify the profile. If a TPM protector uses 0, 2, 4, 11, Microsoft says Windows can remain secure with that alternate measurement set. Keep the recovery key backed up and avoid unnecessary protector, TPM, or Secure Boot changes.

Windows 11 Home

Home editions may provide automatic Device Encryption only on eligible hardware and firmware. If required prerequisites cannot be met, there may be no supported way to force that specific automatic feature. A third-party encryption product has different recovery, compatibility, trust, and support implications and is not a direct PCR7 repair.

Windows 11 Pro, Enterprise, or Education

These editions generally provide BitLocker management. You may be able to enable BitLocker manually when automatic Device Encryption is unavailable, provided the rest of the configuration is suitable. Manual BitLocker is a separate workflow with separate eligibility and user choices; it is not guaranteed to make PCR7 report as bound.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to contact the manufacturer

Contact the computer or motherboard manufacturer when firmware logs indicate incorrect PCR measurements, missing or invalid Secure Boot variables, untrusted UEFI signatories, or a known platform defect; when a current firmware update does not help; or when your custom boot design must remain in place. Ask specifically about measured-boot and Secure Boot compatibility rather than requesting that the TPM be replaced.

Safety rules

  • Do not clear the TPM without a verified recovery key and a specific recovery plan.
  • Do not delete bootloaders or reset Secure Boot keys on a dual-boot or customized system without understanding the boot consequences.
  • Do not disable Secure Boot as a “fix”; it normally removes a prerequisite for PCR7-based Device Encryption.
  • Do not use registry edits to pretend that unsupported hardware has Modern Standby.
  • Do not remove BitLocker protectors or suspend protection unless you understand the recovery implications.

Frequently Asked Questions

Is PCR7 required for Windows 11?

No. PCR7 is a TPM measurement profile used by particular BitLocker and automatic Device Encryption configurations; it is not a universal Windows 11 boot requirement.

Is “Binding Not Possible” dangerous?

Not necessarily. If BitLocker is active with an alternate PCR profile, Microsoft says the system can remain secure. The practical risk is that automatic Device Encryption may be unavailable.

Can I use BitLocker without PCR7?

On supported Windows Pro, Enterprise, or Education configurations, BitLocker may use another profile such as 0, 2, 4, 11. Check the active protector before changing anything.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Will a BIOS update always fix PCR7?

No. It may correct firmware measurement or Secure Boot defects, but custom boot paths, peripherals, and hardware limitations can remain.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.