The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Best practices for TPM autoboot

Prev Next

When using TPM autoboot, follow these best practices:

  • Update the User-Based Policy default password to a very long, random and complex value that cannot be easily guessed.

  • Ensure the option Do not prompt for default password is unchecked.

  • Set a short expiration time for uninitialized users. Navigate to Product Settings policy under General tab, set "Expire users who don't log on" to 1 hour.

  • Enable the policy "Prevent automatic booting when the disk moves systems." This is an important safeguard that ensures the encryption key is never written to disk in cleartext, which is important during the initial TPM sealing phase and when temporary autoboot is used for patching.

  • Enable password synchronization, which automatically syncs the preboot password with the Windows login password. This helps to reduce uninitialized users. It also ensures that if PBA is ever triggered (for example, after a BIOS update), users can log in with their familiar Windows password. For more details, see Password synchronization with autoboot enabled.