Two security features you never think about — TPM 2.0 and Secure Boot — quietly matter to gamers for two very practical reasons: they are required for Windows 11, and a growing number of competitive games with kernel-level anti-cheat now demand them to launch. If a game suddenly refuses to start with an anti-cheat error, these settings are often why.
What each feature does
TPM 2.0
A Trusted Platform Module is a small security chip (or firmware equivalent, called fTPM on AMD or PTT on Intel) that stores encryption keys and verifies system integrity. It underpins features like BitLocker drive encryption and Windows Hello. Version 2.0 is the current standard and a hard Windows 11 requirement.
Secure Boot
Secure Boot is a UEFI firmware feature that checks the digital signature of the bootloader and operating system at startup, blocking unsigned or tampered code from loading before Windows. It helps stop rootkits and, importantly for gamers, is checked by several kernel-level anti-cheat systems to ensure the system is not compromised.
| Feature | Purpose | Why gamers care |
|---|---|---|
| TPM 2.0 | Secure key storage, integrity | Windows 11 requirement |
| Secure Boot | Blocks unsigned boot code | Required by some anti-cheat |
| Both enabled | Trusted boot chain | Games launch, Win 11 installs |
Why a game won’t launch without them
Modern anti-cheat runs at the kernel level to catch cheats early, and to trust that environment it may require Secure Boot (and sometimes TPM) to be on, confirming the system booted clean. If these are disabled, the game can refuse to start or kick you with a security error. Enabling them in the laptop’s UEFI/BIOS usually fixes it. Most gaming laptops ship with both enabled by default, but they can get switched off during troubleshooting, dual-boot setups, or a BIOS reset.
How to check and enable
In Windows, run “tpm.msc” to see TPM status, and check “System Information” for Secure Boot State. To enable them, enter the UEFI/BIOS at boot (often F2, F10, or Delete), turn on fTPM/PTT and Secure Boot, and save. If you dual-boot Linux, note that Secure Boot may need extra configuration for some distributions. Back up your BitLocker recovery key before changing these, since encryption is tied to the TPM.
Common problems and safe fixes
Most people meet these features only when something breaks. A competitive game may suddenly refuse to launch after a Windows or anti-cheat update, throwing a security error because Secure Boot got disabled during earlier troubleshooting or a BIOS reset. The fix is to enter UEFI/BIOS, re-enable Secure Boot and fTPM/PTT, save, and reboot. Similarly, if Windows 11 setup complains your PC is not supported, an unenabled firmware TPM is usually the reason rather than truly missing hardware.
Change these settings carefully. If you use BitLocker or device encryption, the recovery key is tied to the TPM, so back it up before toggling anything or you can lock yourself out of your own drive. Switching from legacy BIOS to UEFI or enabling Secure Boot on an older install may require converting the disk’s partition style, so research your specific setup first. For dual-boot Linux users, some distributions need extra steps to boot with Secure Boot on. Done thoughtfully, enabling both is a one-time task that keeps Windows 11 happy and your favorite anti-cheat games launching without drama.
FAQ
Does enabling TPM or Secure Boot hurt gaming performance?
No. Both operate at boot and for security functions; they have no measurable effect on frame rates or in-game performance. They simply let Windows 11 and modern anti-cheat run.
My laptop is a few years old — does it have TPM 2.0?
Almost certainly. Essentially all gaming laptops from recent generations include firmware TPM (fTPM/PTT); it may just be disabled in BIOS. Enable it there rather than assuming the hardware lacks it.
Bottom line: TPM 2.0 and Secure Boot are set-and-forget security features required by Windows 11 and increasingly by anti-cheat. They cost you no performance, so keep both enabled — and if a competitive game throws a security error, checking these in BIOS is the first fix.