Windows-itpro-docs: TPM 1.2 vs 2.0

Created on 27 Jul 2018  Â·  11Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

The highlighted note says "The device must be running Windows 10 and it must support at least TPM 2.0."
The table of supported versions right below has a checkmark/cross on both TPM 1.2 and TPM 2.0.
So what is true now?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

hardware protection security

Most helpful comment

Looks like this issue can be closed

All 11 comments

The highlighted note refers to TPM 2.0 or above as a requirement for the Device Health Attestation functionality.

Here it says TPM 1.2 is supported for DHA since 1703. So my question remains: What is true now?

Verifying...

I have verified that 2.0 is required and has been since Windows 10 RS1. I have already clarified the documentation referenced in your first post and will follow up on the doc for your second post. Thank you for pointing this out.

Hang on. Getting additional details and verifying...

Hi Ed, I had an advisory case opened with our premier support in parallel. Check case 118073118689762. Feedback is: TPM1.2 and TPM 2.0 are supported for DHA in 1803. TPM 2.0 was ever since Win10 release. TPM1.2 support was added in some later release. TPM2.0 is recommended by MS though (no specific reasons given).
Advisory case answer is sufficient for me. Now if that was reflected in the docs I'd be totally happy... 😃 Thanks!

Hello again. Yep. In my conversation with the product team members, TPM 1.2 was added in 1607. I've updated both docs you had links to. The updates I made have already been applied to the second one you mentioned. https://docs.microsoft.com/en-us/windows/security/threat-protection/protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices#a-href-idhardware-reqahardware-requirements

BTW: TPM 2.0 (or later) is highly recommended because there were major security enhancements made to the design and implementation of TPM compared to 1.2. Other less important enhancements and broader industry support in 2.0 also.

@egallagh Does the X mark in Supported versions for device health attestation mean that it is supported? Or does it mean its unsupported?

X means it is supported. I will clarify that.

Looks like this issue can be closed

Was this page helpful?
0 / 5 - 0 ratings

Related issues

helloitsliam picture helloitsliam  Â·  3Comments

RAJU2529 picture RAJU2529  Â·  3Comments

arcotek-ltd picture arcotek-ltd  Â·  3Comments

SwiftOnSecurity picture SwiftOnSecurity  Â·  3Comments

zjalexander picture zjalexander  Â·  3Comments