Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The message “Your computer’s Trusted Platform Module has malfunctioned” does not automatically mean your TPM chip has failed. When the error code is 80090016 and it appears only in Outlook, Teams, Word, Excel, or Microsoft 365 activation, the usual cause is stale authentication data that no longer matches the computer’s current TPM—especially after a motherboard replacement.

Start with the least-destructive fixes: restart Windows, verify your BitLocker recovery key and password access, check TPM diagnostics, update firmware, and reset Microsoft 365 credentials. Do not clear the TPM first.

Quick fix checklist

  1. Restart the PC.
  2. Confirm that you can sign in with your Windows password, not only your PIN.
  3. Locate and verify your BitLocker recovery key.
  4. Open Windows Security → Device security → Security processor troubleshooting.
  5. Run tpm.msc and check whether the TPM is ready for use.
  6. Install Windows, BIOS/UEFI, chipset, and TPM firmware updates from Microsoft and your PC manufacturer.
  7. If only Microsoft 365 apps fail, remove stale Office credentials and reset Microsoft Web Account Manager token data.
  8. If the Windows Hello PIN fails, reset the PIN after signing in with your password.
  9. Clear the TPM only when diagnostics, Microsoft, your OEM, or IT specifically recommends it—and only after completing the safeguards below.
  10. Contact your manufacturer or IT department if the TPM remains missing, incompatible, or unusable.

What the error means

A Trusted Platform Module is a hardware-backed security component that performs cryptographic operations and protects security keys. Windows uses it for features including BitLocker drive encryption and Windows Hello. Windows 11 requires TPM 2.0 on supported systems. See Microsoft’s overview of what a TPM is.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Has malfunctioned” is a broad message. It can be caused by:

#1 Best Overall
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
  • Compatible with TPM-M R2.0
  • Chipset: Infineon SLB9665
  • PIN DEFINE:14Pin
  • Interface:LPC
  • Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.
  • Microsoft 365 tokens that no longer match the current TPM;
  • a motherboard or system-board replacement;
  • a damaged Windows Hello PIN container;
  • incompatible TPM and BIOS/UEFI firmware;
  • a TPM disabled in UEFI;
  • antivirus, VPN, proxy, or firewall interference with Microsoft Web Account Manager; or
  • a genuine TPM, firmware, or system-board problem.

The correct fix depends mainly on which application fails and whether the problem began after a hardware or firmware change.

Before you clear the TPM

Do not clear the TPM until you have located and verified your BitLocker recovery key. Clearing the TPM removes TPM-held secrets. It normally does not erase files from the drive, but it can prevent Windows from automatically unlocking a BitLocker-protected volume.

Before taking that step:

  • Make sure you know the Windows account password. A PIN alone may stop working after TPM changes.
  • Locate the BitLocker recovery key and confirm that it belongs to this computer.
  • Back up important files.
  • On a work or school device, get approval from IT first.
  • Expect Windows Hello PINs and biometric sign-in to require re-enrollment.
  • Consider certificates, virtual smart cards, Microsoft Entra registration, Intune enrollment, and other organization-managed credentials.

Microsoft warns that clearing the TPM can disable the existing Windows Hello PIN or biometrics until they are set up again. Dell also notes possible effects on BitLocker keys, virtual smart cards, measured-boot attestation, and other TPM-protected data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 1: Identify the exact failure

Write down the affected application and the complete code. Common related codes include 80090016, 80090030, and C0090016. Also note:

  • Does Windows accept the password?
  • Does the PIN fail while password sign-in works?
  • Did the issue follow a motherboard, SSD, BIOS, Windows, or device-reimage change?
  • Is BitLocker asking for recovery?
  • Does the issue affect one account or every account?

Step 2: Restart and inspect TPM diagnostics

Restart Windows once. A restart can restore temporary TPM communication or measured-boot problems, but it is not a universal solution.

Then open Windows Security → Device security → Security processor details → Security processor troubleshooting. Record the exact message. Microsoft lists different responses for messages such as:

  • A firmware update is needed for your security processor: install the manufacturer’s BIOS or TPM firmware update.
  • TPM is disabled and requires attention: enable the security device in UEFI.
  • TPM storage is not available: follow the diagnostic guidance, but clear the TPM only after protecting BitLocker and other credentials.
  • Your TPM isn’t compatible with your firmware: update BIOS/UEFI and TPM-related firmware, then contact the OEM if the mismatch remains.
  • TPM measured boot log is missing: restart first and investigate firmware or Secure Boot changes if it returns.
  • There is a problem with your TPM. Try restarting your device: restart, update firmware, and recheck the status.

Use Microsoft’s Windows Security device-security guidance for the diagnostic shown on your PC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
ASRock TPM2-S TPM Module Motherboard (V2.0)
  • Nuvoton NPCT650
  • TCG PC Client Platform TPM Profile (PTP) Specification; Family 2.0 (Trusted Platform Module Library; Family 2.0)
  • TCG PC Client Specific TPM Interface Specification (TIS), Version 1.3 (TPM Main Specification; Family 1.2 Revision 116)
  • Low Standby Power Consumption

Step 3: Check the TPM with tpm.msc

  1. Press Windows + R.
  2. Enter tpm.msc and press Enter.
  3. Check whether the console says The TPM is ready for use.
  4. Record the Specification Version, manufacturer, and firmware information.

On Windows 11, the specification should be TPM 2.0. If Windows says Compatible TPM cannot be found, the TPM may be disabled in UEFI rather than physically absent. Microsoft’s TPM 2.0 guidance explains how to check this.

Step 4: Update Windows and PC firmware

Install pending Windows updates and use the computer manufacturer’s official support site for:

  • BIOS/UEFI updates;
  • chipset drivers;
  • TPM or security-device firmware; and
  • model-specific security or system-board updates.

In UEFI, the setting may not be called “TPM.” Look for Security Device, Security Device Support, TPM State, Intel Platform Trust Technology (PTT), AMD fTPM, or AMD PSP fTPM. It may appear under Security, Advanced, or Trusted Computing. Menu names vary by manufacturer, so do not apply a BIOS path from another model blindly.

Fix path A: Outlook, Teams, Word, or Excel fail but Windows works

This is the most likely path for error 80090016. Microsoft documents it as an Office authentication and token problem in many cases, rather than proof of a defective TPM.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remove stale Office credentials

  1. Open Control Panel → Credential Manager → Windows Credentials.
  2. Remove credentials clearly associated with Microsoft Office or Microsoft 365, including relevant MicrosoftOffice16 entries.
  3. Remove or disconnect an inappropriate account if the listed account does not match the account you use.
  4. Restart the PC.
  5. Open the affected Office application and try signing in or activating again.

Do not delete unrelated credentials indiscriminately. If this is a managed computer, follow your organization’s instructions.

Reset Web Account Manager token data

Microsoft’s troubleshooting procedure also uses the Web Account Manager/BrokerPlugin data at:

%LOCALAPPDATA%PackagesMicrosoft.AAD.BrokerPlugin_cw5n1h2txyewyACTokenBrokerAccounts

The relevant token-account data may need to be deleted or reset before restarting and trying activation again. Follow the current Microsoft 365 error 80090016 procedure precisely. Do not delete the entire Windows profile, registry keys, or unrelated package folders as a shortcut.

Rank #3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
  • Compatible with:TPM2.0(MS-4462)
  • Chipset: INFINEON 9670 TPM 2.0
  • PIN DEFINE:12-1Pin
  • Interface:SPI
  • Supports:MSI Intel 400 Series and 500 Series Motherboards,MSI AMD B550 and A520 Series Motherboards,Windows 10 TPM 2.0

Microsoft also identifies antivirus, proxy, firewall, and VPN software as possible causes when they block Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy. On a personal PC, test according to your security policy; on a work device, ask IT before disabling protection.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix path B: The error began after a motherboard replacement

A replacement system board usually has a different TPM identity. The new TPM may be healthy, while Office tokens and account data remain associated with the old platform. Dell documents this scenario for Outlook 2019 and Outlook 2021.

For the affected account, logged off, Dell’s documented procedure is to rename:

C:Users<username>AppDataLocalPackagesMicrosoft.AAD.BrokerPlugin_cw5n1h2txyewy

to:

Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy.old

After restarting Outlook, sign in again when prompted. A work account may display an organizational-management or device-registration prompt.

This is not a universal TPM repair. It is a documented Dell system-board-replacement remedy; folder names can vary by Windows version and installed components. Managed devices may need to be re-registered, rejoined, or repaired by IT. See Dell’s system-board replacement guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix path C: Windows Hello PIN fails

If the password works but the PIN does not, treat it as a Windows Hello credential problem first.

  1. Sign in with the account password.
  2. Open Settings → Accounts → Sign-in options.
  3. Choose PIN (Windows Hello).
  4. Remove or reset the PIN, then create a new one.

The old PIN is not restored by clearing the TPM. A new TPM-backed PIN must be enrolled after the account and TPM are working.

Rank #4
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS

Advanced troubleshooting may involve the NGC directory:

C:WindowsServiceProfilesLocalServiceAppDataLocalMicrosoftNGC

Do not casually delete this folder or change its permissions. Dell’s procedure involves backing up or moving its contents, correcting permissions when required, and recreating the PIN. Use it only when simpler PIN reset options fail and you understand the recovery implications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix path D: Clear the TPM only when justified

Consider clearing the TPM only when Windows Security explicitly recommends it, the TPM remains unusable after firmware checks, or Microsoft, your OEM, or IT directs you to do so. For an Office-only 80090016 error, reset credentials first.

From Windows Security

  1. Open Windows Security → Device security → Security processor details → Security processor troubleshooting.
  2. Select Clear TPM.
  3. Follow the restart and firmware-confirmation prompts.

From TPM Management

  1. Press Windows + R and enter tpm.msc.
  2. Choose Clear TPM under Actions.
  3. Follow the restart and manufacturer-specific confirmation prompts.

Afterward, Windows Hello PINs and biometrics may stop working, BitLocker may request its recovery key, Microsoft 365 may require sign-in, and certificates, virtual smart cards, or device-registration credentials may need re-enrollment. Recheck tpm.msc and create a new PIN if necessary.

TPM clearing is not reversible for the old TPM-backed credentials. Microsoft’s explanation confirms that the previous credential state cannot simply be restored.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Fix path E: BitLocker or boot-time TPM errors

If BitLocker requests a recovery key after a TPM, BIOS, Secure Boot, or system-board change, use the verified recovery key. Do not guess, wipe the drive, or assume that the files were erased. Usually the encrypted data remains on the disk; Windows has lost automatic access to the TPM-backed protector.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An administrator can inspect protection status with:

Best Value
Asus TPM-SPI Trusted Platform Module (TPM)
  • Product Color: Black
  • Width: 0.6"
  • Depth: 0.5"
  • Additional Information: Interface: SPI Features: TPM IC: Nuvoton NPCT750 TPM Version: TPM 2.0 Pin Dimension: 14-1pin System Requirements: Windows® 10, UEFI OS
  • Country of Origin: Vietnam
manage-bde -status

For specific firmware or Secure Boot maintenance scenarios, Microsoft documents temporarily suspending and re-enabling protection:

manage-bde -protectors -disable C:
manage-bde -protectors -enable C:

These commands are not a generic TPM repair. Use them only when the applicable firmware-maintenance procedure calls for them and you understand the security implications.

When the TPM is probably defective

Contact the PC manufacturer or IT department when:

  • the TPM is absent from both UEFI and Windows;
  • it remains missing after the correct BIOS update and UEFI configuration;
  • Windows continues to report incompatible TPM and firmware;
  • TPM clearing or reinitialization fails;
  • the problem affects every user account;
  • TPM errors appear during boot; or
  • the system board was recently replaced and device registration or BitLocker recovery is involved.

On many laptops, the TPM is integrated into the platform or system board and is not a separately repairable consumer component. The practical solution may be OEM diagnostics, service, or another system-board replacement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows 10 and Windows 11 considerations

The menu paths above apply broadly to current Windows 10 and Windows 11 installations, but labels vary by edition, build, OEM, and firmware. Windows 11 systems require TPM 2.0 for supported installation. Windows 10 reached the end of ordinary support on October 14, 2025, although separate paid or organizational arrangements may apply. Do not assume that Windows 10 and Windows 11 have identical support or firmware behavior.

Diagnosis by symptom

Symptom Likely cause First action
Only Outlook, Teams, or Office fails Stale Microsoft 365/WAM credentials Reset Office credentials and BrokerPlugin token data
Started after motherboard replacement New TPM versus old authentication tokens Use the OEM account/token remediation procedure
PIN fails but password works Windows Hello credential mismatch Reset the PIN
TPM is disabled UEFI configuration Enable TPM, PTT, or fTPM in UEFI
Firmware update is needed BIOS/TPM mismatch Install official manufacturer firmware
BitLocker requests recovery Changed TPM or measured-boot state Use the recovery key
TPM is absent everywhere Firmware or hardware fault Contact the OEM or IT
Only VPN, proxy, firewall, or antivirus triggers it BrokerPlugin interference Test under your security policy

What not to do

  • Do not clear the TPM as the first response to an Office-only error.
  • Do not assume “malfunctioned” proves physical failure.
  • Do not use unofficial BIOS or TPM firmware downloads.
  • Do not rely on registry cleaners or paid driver-updater tools.
  • Do not delete the entire user profile or registry before trying Microsoft’s supported credential-reset steps.
  • Do not treat reinstalling Office as the primary fix.
  • Do not delete the NGC folder unless advanced troubleshooting is necessary and you have a recovery path.
  • Do not clear a managed computer’s TPM without IT approval.

Frequently Asked Questions

Does clearing the TPM delete my files?

It normally does not erase the contents of the disk, but it removes TPM-held keys. BitLocker may then require the recovery key before the encrypted files can be opened.

Can I undo clearing the TPM?

No. The old TPM-backed credentials cannot simply be restored. Windows Hello, Microsoft 365 sign-in, certificates, or device registration may need to be set up again.

Why does Outlook fail while Windows still works?

Outlook can be using stale Microsoft 365 or Web Account Manager tokens that no longer match the current TPM, while ordinary Windows sign-in continues normally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if I cannot find my BitLocker recovery key?

Stop before clearing the TPM or changing security firmware. Check the Microsoft account, organization’s IT records, printed or saved backups, and the computer manufacturer’s support process.

Should I reinstall Office?

Not first. Reset Office credentials and the relevant BrokerPlugin token data before reinstalling applications.

Can a BIOS update fix error 80090016?

It can fix a disabled, outdated, or incompatible TPM/firmware state, but it will not necessarily remove stale Microsoft 365 tokens. Update firmware and follow the appropriate authentication reset path.

Quick Recap

Bestseller No. 1
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
Compatible with TPM-M R2.0; Chipset: Infineon SLB9665; PIN DEFINE:14Pin; Interface:LPC
$24.99
SaleBestseller No. 2
ASRock TPM2-S TPM Module Motherboard (V2.0)
ASRock TPM2-S TPM Module Motherboard (V2.0)
Nuvoton NPCT650; Low Standby Power Consumption
$25.49
Bestseller No. 3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
Compatible with:TPM2.0(MS-4462); Chipset: INFINEON 9670 TPM 2.0; PIN DEFINE:12-1Pin; Interface:SPI
$24.99
Bestseller No. 4
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
TPM 2.0 module for Asus motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
$24.99
Bestseller No. 5
Asus TPM-SPI Trusted Platform Module (TPM)
Asus TPM-SPI Trusted Platform Module (TPM)
Product Color: Black; Width: 0.6"; Depth: 0.5"; Country of Origin: Vietnam
$34.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.