Introduction
Clearing the Trusted Platform Module on Windows 10 can solve repeated BitLocker recovery prompts, Windows Hello failures, and device attestation errors, and it can prepare a PC for resale or redeployment. The action resets the TPM to a clean state, but it also removes the keys that secure logins, VPNs, Wi‑Fi, and encryption. If you act without a plan, you can lock yourself out of your data. This guide explains how to clear tpm windows 10 safely with clear steps. You will learn when a clear helps, how to prepare, and the safest methods to perform it. You will also see how to handle BitLocker before and after the operation, how to restore features, and how to fix common errors. By following this structured approach, you can restore TPM health without risking your files or access.
Understanding what the TPM is and what a clear actually does gives you the context to act with confidence. Let us start by defining the TPM and what changes when you reset it.

What Is the TPM and What Does ‘Clear TPM’ Mean in Windows 10?
The TPM is a secure cryptoprocessor that generates, stores, and protects cryptographic keys. Windows 10 uses it to bind secrets to trusted boot measurements. Features that rely on it include BitLocker, Windows Hello, certificate‑based VPN and Wi‑Fi, and device health attestation. On many PCs, the TPM is implemented in firmware as Intel PTT or AMD fTPM. Some devices ship with a discrete hardware TPM soldered on the motherboard. In all cases, Windows expects a ready, healthy TPM so it can release keys to the operating system only when the device boots in a trusted state.
When you clear tpm windows 10, you reset the TPM to a factory‑like state. The clear deletes TPM‑protected keys and resets ownership information. Your personal files, applications, and Windows itself remain untouched. However, anything that used TPM‑sealed keys must be re‑enrolled or resealed. That includes BitLocker TPM protectors, Windows Hello PIN and biometrics, and certain user or device certificates. A clear also breaks previous ownership so a new owner can take control. This is why you should approach it like a security change: back up recovery keys, export important certificates, and know how you will sign back in after the reboot.
Now that you know what clearing does, the next step is deciding whether you should do it. Not every error calls for a TPM reset, and avoiding unnecessary clears reduces risk.
When You Should—and Should Not—Clear the TPM on Windows 10
You should clear the TPM when strong signs point to corrupted TPM state or stale keys. Typical cases include repeated BitLocker recovery prompts after firmware changes, motherboard swaps, or boot setting changes; Windows Hello errors such as 0x80090016 or 0x80090034; device attestation or health failures that block secure sign‑in; or when you are transferring device ownership for resale, RMA, or internal reassignment. A clear also helps after you change boot components that alter PCR measurements and prevent the TPM from releasing keys.
Avoid clearing if you cannot confirm BitLocker recovery keys for all encrypted volumes. Do not clear a work or school device without approval, because MDM or Group Policy can block or audit TPM actions and your organization may require a specific workflow. Also consider simpler fixes before a clear: resume BitLocker, apply OEM BIOS or firmware updates, verify Secure Boot, and re‑enroll Windows Hello. If those do not fix the problem, proceed with a planned clear.
A safe clear starts with preparation. The following checks protect your data and make the process predictable. Complete them before you touch the TPM.
Pre-Checks Before You Clear the TPM on Windows 10
Careful preparation reduces the chance of lockouts and makes restoration fast. Validate BitLocker keys, export credentials, and verify who owns or manages the device. Once these steps are complete, you will be ready to check TPM status and choose a clearing method.
Confirm BitLocker status and back up recovery keys
- Open an elevated Command Prompt and run: manage-bde -status. Note which volumes are encrypted and their protection state.
- Back up each recovery key. If your organization escrows keys to Azure AD or MBAM, confirm they are present. For Azure AD joined PCs, check aka.ms/myrecoverykey with the account that owns the device.
- If keys are not escrowed, save them to a USB drive or print them from the BitLocker Control Panel. Store them offline where you can access them during boot.
- Do not skip this step. A TPM change can trigger a recovery prompt at next boot.
Export app, VPN, and Wi‑Fi certificates and note Windows Hello sign-in
- Export personal certificates used by VPN, Wi‑Fi, email, or apps using certmgr.msc under Personal > Certificates.
- Make sure you know your account passwords. You will re‑enroll Windows Hello PIN and biometrics after the clear.
- If you use FIDO security keys for work sign‑in, have them handy for re‑registration if needed.
Verify device ownership and management policies (local, Azure AD, domain)
- Determine whether the PC is local, Azure AD joined, or domain joined. Managed devices may block or log TPM clears.
- Ask IT for approval if the device is managed. Confirm where BitLocker keys are escrowed and any required steps.
- Ensure you have admin rights, AC power, a stable internet connection if policies must sync, and any BIOS or UEFI passwords required to approve firmware prompts.
With preparation complete, confirm the TPM is present and ready. This check helps you choose the best clearing path and detect firmware issues early.
How to Check TPM Status in Windows 10
Before a clear, verify that Windows sees the TPM and that it reports a healthy state. If you discover firmware problems now, you can address them before you reset anything.
Windows Security > Device security
- Open Start > Windows Security > Device security.
- Under Security processor, select Security processor details.
- Review Specification version, Manufacturer, and Status. Ready for use is ideal; Not ready suggests initialization or firmware work is needed.
TPM Management console (tpm.msc)
- Press Win+R, type tpm.msc, and press Enter.
- Check the Status pane for The TPM is ready for use. Note the manufacturer, version, and whether ownership is present.
- Look at the Actions pane to see if Clear TPM is available. If it is, you can use that route.
PowerShell: Get-Tpm and status interpretation
- Open PowerShell as admin and run: Get-Tpm.
- Review TpmPresent, TpmReady, Owned, and ManagedAuthLevel.
- If TpmReady is False or errors appear, install OEM firmware or chipset updates before clearing.
If your TPM is present and healthy or you have a plan to update firmware, choose one method to clear it. You have several options, and each works well when followed precisely.
Methods to Clear TPM in Windows 10 (Step-by-Step)
Use only one method. If one fails due to policy or firmware prompts, try another or update firmware first. Always keep your recovery keys nearby when you reboot.
Clear TPM via Windows Security
1) Open Windows Security > Device security > Security processor details > Security processor troubleshooting.
2) Select Clear TPM, read the warning about key loss, and confirm.
3) The PC restarts. Approve any firmware prompt that asks you to clear or reset the TPM.
4) After Windows starts, it initializes the TPM automatically.
Clear TPM via TPM.msc
1) Press Win+R, run tpm.msc.
2) In the Actions pane, select Clear TPM and accept the warning.
3) Restart the PC and approve the firmware confirmation.
4) Sign in and let Windows complete TPM initialization.
Clear TPM in UEFI or BIOS (Intel PTT or AMD fTPM)
1) Reboot and enter firmware setup, often with F2, F10, Del, or Esc.
2) Find Security or Advanced settings. Locate TPM, Intel PTT, or AMD fTPM.
3) Choose Clear, Reset, or Restore Factory Defaults for the TPM. Save and exit.
4) If a physical presence prompt appears on next boot, approve it to complete the clear.
PowerShell: Clear-Tpm and Initialize-Tpm
1) Open PowerShell as admin. Run Clear-Tpm.
2) If prompted, provide owner authorization or approve the firmware request.
3) After reboot, run Initialize-Tpm if needed to complete ownership and readiness.
Clearing the TPM affects BitLocker, so you must plan what to do before and after the operation. That is the next step.

If BitLocker Is Enabled—Do This Before and After You Clear TPM
BitLocker relies on TPM and boot measurements to release keys. A clear breaks the bond temporarily. Handle it carefully to avoid being stuck at a recovery screen.
Suspend BitLocker and verify protectors
- Suspend BitLocker for each encrypted volume. Use PowerShell: Suspend-BitLocker -MountPoint C: -RebootCount 1.
- Or open Control Panel > BitLocker Drive Encryption and select Suspend protection for each protected volume.
- Confirm protectors with manage-bde -protectors -get C:. Note the recovery key ID and that a TPM protector exists.
- If external drives are encrypted, unplug them before you clear and keep their keys nearby.
Reboot, resume BitLocker, and validate encryption
- After the clear, sign in and let Windows finish TPM initialization.
- Resume BitLocker: manage-bde -protectors -enable C: or use Control Panel to Resume protection.
- Confirm status with manage-bde -status. Protection should be On and Percentage Encrypted should match your policy, typically 100 percent.
Fix repeated recovery prompts and update PCR binding
- If the system asks for the recovery key on every boot, recreate the TPM protector.
- Remove and add the TPM protector: manage-bde -protectors -delete C: -Type TPM, then manage-bde -protectors -add C: -tpm.
- Ensure Secure Boot is enabled and boot order is stable so PCR measurements remain consistent across reboots.
With BitLocker stable, you can restore sign‑in features and app access. The next section covers those post‑clear tasks.

Post-Clear Tasks: Re-Initialize and Restore Access
After a clear, Windows must re‑initialize the TPM, and you need to re‑enroll features that used TPM‑sealed keys. These steps return the device to a fully functional and secure state.
Complete TPM ownership and Windows Hello re-enrollment
- Open Windows Security > Device security and confirm the TPM shows Ready for use.
- Re‑enroll Windows Hello: Settings > Accounts > Sign‑in options, then set up PIN, fingerprint, or face sign‑in again.
- If Windows Hello errors persist, remove old Hello containers from Sign‑in options and re‑create them.
Re-issue certificates, VPN, and Wi‑Fi credentials
- Import personal certificates you exported earlier. Re‑connect to secure Wi‑Fi networks that require certificate or EAP‑TLS sign‑in.
- Re‑enroll VPN profiles that depend on user or device certificates and test authentication.
- Open apps that used TPM‑backed keys and sign in again to refresh tokens.
Re-enable security features such as Secure Boot, VBS, and Credential Guard
- Confirm Secure Boot remains enabled in UEFI or BIOS after any firmware changes.
- If your organization uses virtualization‑based security or Credential Guard, verify they are active and healthy in Device Security settings.
- Check Core isolation and Memory integrity. If drivers block VBS, update or replace them and then re‑enable the feature.
If problems remain, a focused troubleshooting approach will save time. The next section lists common failures and proven fixes.
Troubleshooting Common Errors After Clearing TPM
Most issues trace back to disabled firmware settings, outdated BIOS, corrupted Windows Hello containers, or BitLocker protector mismatch. Work through these checks to isolate the cause.
Compatible TPM cannot be found or clear option is greyed out
- Enable TPM, Intel PTT, or AMD fTPM in UEFI or BIOS. Some systems ship with it disabled.
- Update BIOS or UEFI and chipset firmware from your PC manufacturer. An update can restore TPM visibility and stability.
- In Device Manager, show hidden devices, uninstall stale Trusted Platform Module entries, and scan for hardware changes.
- If the motherboard was replaced, reset firmware security settings and re‑enable Secure Boot and TPM features.
0x80090016 or 0x80090034 with Windows Hello or BitLocker
- Remove and re‑enroll Windows Hello PIN and biometrics. This recreates the user keys stored in the TPM.
- Rebuild the BitLocker TPM protector so keys are resealed to current PCRs: delete the TPM protector and add it again as shown earlier.
- Repair Windows components if needed: run sfc /scannow, then DISM /Online /Cleanup-Image /RestoreHealth.
Firmware issues with AMD fTPM or Intel PTT and how to update
- Install the latest BIOS from your OEM, which often includes TPM firmware fixes and updated Intel ME or AMD AGESA components.
- After firmware updates, clear the TPM again so Windows can initialize it with a clean state.
- Stabilize boot configuration: enable Secure Boot, disable legacy CSM, and lock boot order to prevent PCR drift.
At this point you have a healthy TPM, stable BitLocker, and restored sign‑in and app access. You can wrap up with a quick review of the process and key safeguards.
Conclusion
You can clear tpm windows 10 safely with preparation and a consistent method. Start by confirming BitLocker recovery keys, exporting certificates, and checking device policies. Verify TPM status, then use one method to clear it: Windows Security, the TPM management console, firmware settings, or PowerShell. If BitLocker is enabled, suspend it before the clear, resume it after, and recreate protectors if the system asks for recovery at every boot. Finish by re‑enrolling Windows Hello, importing certificates, and validating security features like Secure Boot, virtualization‑based security, and Credential Guard. If errors persist, update firmware, repair Windows components, and reseal BitLocker protectors. With these steps, a TPM clear becomes a clean reset of security hardware rather than a risky guess, and you regain a stable, trusted computing base for Windows 10.
Frequently Asked Questions
Will clearing the TPM on Windows 10 erase my files or BitLocker encryption?
Clearing the TPM does not delete files or turn off BitLocker. It wipes TPM keys and ownership. If BitLocker relies on TPM, the system may ask for the recovery key at next boot. Back up keys and suspend BitLocker before you clear, then resume and reseal protectors afterward.
Is it safe to clear TPM on a work or school laptop managed by Intune or Group Policy?
It can be safe if you follow policy. Managed devices often escrow BitLocker keys and may restrict TPM actions. Confirm escrow, check MDM or GPO rules, and get IT approval. Some organizations require a workflow that suspends BitLocker, clears the TPM with logs, and re‑enrolls Windows Hello and certificates.
Do I need to clear TPM when upgrading hardware, BIOS, or moving a drive to a new PC?
Not always. Many updates work without a clear. If BitLocker starts asking for recovery on every boot or Windows Hello fails after changes, a clear can help. When moving a system drive, expect at least one recovery prompt. Back up data and recovery keys, then clear the TPM on the new host and reseal BitLocker protectors if needed.
