The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How TPM autoboot works

Prev Next

TPM Autoboot enhances boot security by replacing static on-disk credential storage with hardware-based cryptographic verification. This process ensures that encryption keys are available only after the system's security chip verifies the integrity of the boot path.

The file containing the encryption key can only be decrypted on the system that encrypted it, and only if the boot path is unmodified from when the key was sealed. This provides two key benefits:

  1. Theft protection — It prevents unauthorized access if the drive is stolen and moved to another machine.

  2. Malware protection — It protects against boot-level malware, as any modification to the boot path will fail the integrity check.

If the integrity check fails, Drive Encryption automatically detects this and enforces PBA to ensure the system remains secure.