Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows Measured Boot records evidence about a device’s startup so the TPM and a trusted service can help determine whether Windows booted in an expected state. It measures firmware and early Windows components and records the results in TPM Platform Configuration Registers (PCRs) and a boot log. Unlike Secure Boot, Measured Boot does not itself prevent every untrusted component from running; its value is that another system can assess what happened.

Why measure the boot process?

Security software that starts with Windows may not see everything that happened before it loaded. A bootkit or altered bootloader could interfere with startup, while the running operating system might still report that the device is healthy. A remote service also needs stronger evidence than a device’s ordinary software assertion that a security setting is enabled.

Measured Boot addresses that gap by creating TPM-backed evidence about startup. A verifier can compare the evidence with an expected configuration and use the result in a device-health or access decision. Measurement is evidence, not cleanup: Measured Boot does not remove malware or automatically stop every unexpected component.

How the Windows boot-security layers differ

These technologies work together, but they have different jobs. Secure Boot and Trusted Boot provide important prevention and validation functions; Measured Boot records evidence for later assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
TPM 2.0 Security Module for Gigabyte Motherboards (12-Pin LPC), Infineon SLB9665 Chip | Compatible with GC-TPM2.0_S | Windows 11 Ready (LPC 12Pin Module)
  • 【Quality materials and easy installation】TPM 2.0 Security Module is made of high quality material and is well made for long life.It is easy to install, lightweight and compact, and its easy integration makes it a breeze to install and operate quickly.
  • 【Working environment】The TPM2.0 Security Module is compatible with GC-TPM2.0_S. Interface: LPC, TPM IC: SLB9665, Pin Connector: 12Pin.Please check compatibility before purchasing.
  • 【Reliable Work】The TPM 2.0 Module is a highly reliable cryptographic processor that brings an extra layer of security to your Windows computer. With its advanced encryption technology, you can perform secure operations such as generating, storing, and restricting the use of cryptographic keys, ensuring that your system is protected from unauthorized access.
  • 【High-quality replacement】high-quality professional use, the function is the same as the original model, stable performance, a good replacement of the original damaged old safety module.
  • 【Model Support】Each security module is tested before it leaves the factory and is 100% perfectly works well.Therefore, Please confirm that your motherboard supports TPM2.0 technology.
Technology Main role Typical result
Secure Boot Validates signatures on authorized EFI boot components. Helps prevent unauthorized or untrusted EFI components from executing.
Trusted Boot Continues integrity checks as Windows starts. Helps prevent tampered Windows components and drivers from loading.
Early Launch Anti-Malware (ELAM) Evaluates early-start drivers before ordinary antimalware services are fully active. Helps classify boot-start drivers.
Measured Boot Records cryptographic measurements of boot events. Provides evidence a local or remote verifier can assess.
TPM Provides hardware-backed registers and cryptographic operations. Protects PCR state and supports attestation evidence.

Secure Boot is not a complete firmware-security solution, and a valid measurement is not proof that all later activity is safe. Microsoft describes these as complementary parts of Windows boot security in its Windows boot process overview and Trusted Boot documentation.

What happens during measured startup?

At a high level, UEFI firmware starts the platform, Secure Boot checks authorized EFI signatures, and measurements are extended into TPM PCRs as boot proceeds. Windows Boot Manager launches the Windows loader, which loads the kernel and early-start drivers. Trusted Boot and code-integrity mechanisms continue checking Windows startup components, while ELAM evaluates early drivers. The resulting measurements and boot configuration log can then be examined by a health-attestation or other remote-attestation service.

  1. UEFI firmware begins execution and participates in recording platform measurements.
  2. Secure Boot validates authorized EFI components before execution; measurement records relevant boot state.
  3. Windows Boot Manager launches the Windows loader.
  4. The loader starts Windows components, including the kernel and boot-start drivers, with integrity checks continuing through startup.
  5. The TPM PCR values and associated event log provide evidence for later interpretation by a verifier.

The components measured can include firmware and configuration, UEFI variables and Secure Boot state, the boot manager, the Windows loader, boot-start drivers, early security components, and—where applicable—hypervisor or virtualization-based security components. There is no single event list guaranteed for every PC: firmware, Windows version, hardware, virtualization settings, and platform implementation affect the sequence. Microsoft’s Measured Boot compatibility guidance describes measurement from firmware through boot-start drivers.

TPM PCRs, measurements, and the boot log

A measurement is a cryptographic digest of a component or configuration event. A PCR is not a file containing each digest in a readable list. Instead, a new measurement is extended into the existing PCR value:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
TPM 2.0 Security Module 20-Pin LPC (2×10) for Gigabyte & ASUS Motherboards, Infineon SLB9665 Chip, GA 20-1 Pin, 2.54mm Pitch LPC Header, Windows 11 Ready, Compatible with GC-TPM2.0
  • 【Wide Compatibility – Gigabyte & ASUS】 Specifically designed for Gigabyte and ASUS desktop motherboards with a 20-1 pin (2x10 / GA 20-1) 2.54mm pitch LPC TPM header. Ideal for upgrading to TPM 2.0 on DDR4 systems. (Note: NOT compatible with 12-pin, 2x6, or 14-pin headers).
  • 【Windows 11 Readiness】 An essential hardware upgrade to meet Windows 11 security requirements. Ensure your system stays secure and up-to-date with a dedicated hardware TPM 2.0 module without replacing your entire motherboard or CPU.
  • 【Advanced Security & Encryption】 Powered by the standalone Infineon SLB9665 encryption processor. This module securely stores cryptographic keys for software like Windows BitLocker, providing a robust layer of hardware-based security for your data.
  • 【Platform Limits – No Laptops】 Optimized for Desktop motherboards from the DDR4 era (X99 series and newer). Not compatible with laptops or legacy DDR3 systems. Please verify your motherboard's header layout (2x10 pins) before ordering.
  • 【Easy Setup & BIOS Note】 Simple plug-and-play installation takes only minutes with no tools required. IMPORTANT: After installation, you MUST enable "Security Device Support" or "Intel PTT / AMD fTPM" in your BIOS settings for Windows to recognize the module.
PCR_new = Hash(PCR_old || measurement)

Because each result depends on the prior value, changing an earlier event changes the final PCR value. The boot configuration log supplies event-by-event context for interpreting those cumulative values. A PCR value by itself generally cannot tell an administrator which component changed. Microsoft explains the PCR and boot-log relationship in its Measured Boot host attestation overview.

How remote attestation turns evidence into a decision

Measured Boot is most useful operationally when a relying party evaluates the evidence. Windows or an attestation client obtains relevant TPM-backed data; a verifier can issue a fresh challenge, validate signed evidence and its provenance, check PCR values against the event log, and compare the result with policy.

  1. The platform measures startup events, extends measurements into PCRs, and records the event log.
  2. An attestation client or operating-system service obtains the evidence needed by the relying party.
  3. Where supported, the relying party supplies a fresh challenge or nonce to help prevent reuse of stale evidence.
  4. The TPM-backed mechanism signs the evidence; the verifier checks the signature, certificate or provenance information, PCRs, and log consistency.
  5. The verifier compares the result with its policy and accepts the device, restricts access, requests remediation, or reports that it could not determine health.

An attestation pass means the measured state met a defined policy or expected configuration; it does not certify that the device is free of all malware. The result is bounded by what was measured and by trust in the TPM, firmware, certificates, event log, verifier, and its policy. A vulnerable but correctly signed component may still match an expected measurement, and runtime compromise after startup is outside the narrow claim of measured boot.

Device Health Attestation and managed-device access

Windows platform-health evidence can be sent to a remote service such as Device Health Attestation. A device-management or identity system can then use the service’s result in compliance and Conditional Access decisions. In this arrangement, the attestation service is the relying party; Measured Boot is one source of evidence rather than a complete management product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS

A PC can work normally for its user yet fail attestation because TPM provisioning, firmware, certificates, the event log, or network access to the service is unavailable or does not meet policy. Microsoft describes using Device Health Attestation to help control access to high-value resources in its device-health guidance.

How Measured Boot relates to BitLocker

BitLocker and Measured Boot are separate technologies. BitLocker can use TPM-bound boot-state measurements as part of a key protector’s decision to release or withhold key material. If the boot configuration changes, the device may require the BitLocker recovery key instead of automatically unsealing the volume key. This can help protect data against some offline tampering, but it is not a guarantee against every physical attack.

Behavior depends on the protector configuration, TPM state, firmware, policy, recovery-key availability, and which measurements the protector uses. A measured event does not automatically seal every BitLocker key. Before changing firmware or system hardware, organizations should ensure recovery keys and recovery procedures are available.

Check a Windows device’s prerequisites and status

Remote attestation needs more than a command showing that a TPM exists. The practical baseline is UEFI firmware, a functioning TPM, firmware and Windows support for measured-boot logging, appropriate TPM provisioning and attestation information, and a verifier or management service if the goal is a remote health decision. Exact availability depends on device firmware, configuration, Windows edition, and service support.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Yeiwenl TPM 2.0 Module 18 Pin, TPM 2.0 Encryption Security Module for ASROCK Motherboard Compatible with Win11
  • TPM 2.0 module for ASROCK motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x9P, 18 pin security module for ASROCK
  • LPC 18 Pin for TPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASROCK

Check the TPM

In an elevated PowerShell session, run:

Get-Tpm

Review fields such as TpmPresent, TpmReady, TpmEnabled, TpmActivated, ManagedAuthLevel, ManufacturerId, and ManufacturerVersion. You can also open tpm.msc for a graphical view. These checks show local TPM status; they do not prove that an endorsement certificate is usable or that a remote attestation policy will pass.

Check Secure Boot and firmware mode

Run the following in elevated Windows PowerShell:

Confirm-SecureBootUEFI
  • True means Secure Boot is enabled.
  • False means the platform supports the check but Secure Boot is disabled.
  • A “cmdlet not supported on this platform” error can indicate legacy BIOS, unsupported Secure Boot, or that the required UEFI interface is unavailable.

The cmdlet requires a UEFI computer and administrator privileges, as Microsoft notes in the Confirm-SecureBootUEFI reference. For an inventory check, run msinfo32 and review BIOS Mode (ideally UEFI) and Secure Boot State (ideally On). Windows Security may also show status under Device security, including Secure Boot and Security processor; labels can vary by release and language. None of these local views substitutes for signed attestation evidence.

Decode logs when PCRs do not match

Microsoft documents a workflow using TBSLogGenerator.exe to decode measured-boot logs and investigate PCR changes. When troubleshooting, preserve the raw measured-boot or TCG log and PCR values alongside the Windows build, BIOS/UEFI version, TPM manufacturer and firmware version, Secure Boot state, and timing of relevant firmware, bootloader, driver, cloning, or recovery changes. The Microsoft log-decoding procedure also covers applicable Hyper-V Generation 2 virtual machines with a vTPM.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common measured-boot and attestation failures

A failed attestation is not automatically evidence of malware. Start by collecting evidence and correlating it with recent changes rather than clearing the TPM or rebuilding the device as a first response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TPM 2.0 Encryption Security Module Compatible with Remote Card 11 Upgrade LPC TPM2.0 Module 12 pin for Motherboards
  • Independent TPM Processor: The remote card encryption security module uses an independent TPM encryption processor, which is a daughter board connected to the main board.
  • High Security: The TPM securely stores an encryption key that can be created using encryption software, without which the content on the user's PC remains encrypted and protected from unauthorized access.
  • PC Architecture: TPM module system components adopts a standard PC architecture and reserves a certain amount of memory for the system, so the actual memory size will be smaller than the specified amount.
  • Scope of Application: TPM modules are suitable for GIGABYTE for 11 motherboards. Some motherboards require a TPM module inserted or an update to the latest BIOS to enable the TPM option.
  • Easy to Use: 12Pin remote card encryption security module is easy to use, no complicated procedures are required, and it can be used immediately after installation.
Symptom Areas to inspect
Secure Boot check is unsupported UEFI versus legacy BIOS mode, firmware support, and whether the PowerShell session is elevated.
TPM is present but not ready Firmware configuration, TPM initialization or provisioning, and manufacturer firmware updates.
PCR values do not match the event log Firmware or bootloader changes, a corrupted or unavailable TCG log, cloning, and the Microsoft log-decoding workflow.
TPM is ready but attestation is unavailable Endorsement-key certificate usability, attestation information, service connectivity, and service-side policy.
BitLocker requests recovery after an update Expected measurement changes, firmware changes, protector configuration, and recovery-key availability.
A virtual machine cannot attest Generation 2 and UEFI configuration, vTPM provisioning, and hypervisor or cloud-platform settings.

Other causes include Secure Boot being disabled or changed, booting from cloned or modified media, and blocked service access. Firmware or Windows updates can legitimately change measurements; the verifier needs appropriate expected-state handling. Record BIOS/UEFI, Secure Boot database or certificate, boot-manager, driver, hypervisor/VBS, and BitLocker protector changes so administrators can distinguish an expected transition from an unexplained one.

Secure Boot certificate changes are an operational consideration

Microsoft’s Secure Boot certificate guidance addresses replacement of older certificate material and updates to the trust chain. The implications depend on firmware, Windows servicing, and a device’s certificate state, so there is no single universal impact date for every PC. Certificate transition is related to boot trust, but it does not mean Measured Boot itself expires or stops working.

When Measured Boot is useful—and what it cannot do

Good fit

  • Requiring evidence of an expected boot state before granting access to sensitive resources.
  • Investigating unexpected firmware, bootloader, or early-start component changes.
  • Combining hardware-backed evidence with device compliance and zero-trust access policy.
  • Protecting TPM-bound BitLocker key release against some unexpected boot-state changes.
  • Monitoring a Windows fleet through Device Health Attestation, Intune, Azure Attestation, or a comparable service.

Not a substitute for runtime security

Measured Boot alone does not provide runtime malware detection, application control, vulnerability management, network detection and response, automatic remediation for every boot problem, or proof that Windows remains uncompromised after startup. Pairing it with Secure Boot, TPM 2.0, BitLocker, endpoint protection, application control such as App Control for Business, VBS/HVCI where compatible, device-health attestation, management compliance, and firmware update management addresses different parts of the security problem. Microsoft’s security-tool integration guidance discusses the value of layered controls.

Enterprise deployment: choose the verifier and policy first

Before treating measured-boot evidence as an access gate, decide which service will verify it, what state counts as acceptable, how legitimate updates change baselines, and what happens when a device cannot attest. Intune can manage Windows devices and feed compliance decisions into Conditional Access; Device Health Attestation or another supported verifier supplies the relevant health assessment. Azure Attestation is a distinct attestation service for supported scenarios, not an automatic replacement for standard Windows fleet compliance. Defender for Endpoint provides runtime detection and response that complements boot evidence rather than replacing it.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

At fleet scale, also plan firmware lifecycle management, certificate-transition readiness, recovery-key handling, and incident procedures. A business-PC evaluation should consider TPM 2.0 provisioning, UEFI quality, firmware-update support, certificate-transition support, attestation compatibility, BIOS-management tools, and recovery processes; no OEM is universally superior without comparative testing. Home users or small organizations that only need a local status check may not need a paid management or attestation service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.