The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Platform Configuration Registers (PCRs)

Prev Next

The automatic boot feature relies on the TPM "unsealing" data that is bound to specific Platform Configuration Registers (PCRs).

Understanding PCR Measurements

The PCRs 0 through 7 store measurements of the boot path components. If these components are modified, the PCR values change, and the unseal attempt fails, triggering PBA.

Any software or firmware update that changes the boot path measured by the selected PCRs will trigger PBA. This occurs because the boot path measurements have changed, which prevents the disk encryption key from being unsealed. For example, if PCR 4 is selected, PBA will be required when upgrading from Windows 10 to Windows 11 or whenever a Microsoft update modifies the UEFI bootloader.

Configurable PCRs

A major enhancement in Drive Encryption 8.1.0 and later is the ability to select which PCRs (0–7) are used to seal the encryption key.

Previously, Drive Encryption used a fixed, non-configurable set of PCRs. This new flexibility allows administrators to precisely configure the TPM autoboot policy, balancing security requirements with the need to avoid unnecessary PBA prompts caused by routine system changes.

This configurability enables the phased rollout described in the "Changing PCR Configuration Policy" section below.

Changing PCR configuration policy

A key administrative benefit is that changing the PCR configuration in the  policy does not trigger a PBA prompt. This allows for a phased rollout. For example, an administrator can initially enable TPM autoboot using a minimal set of PCRs (such as none, or only PCR 4). Later, they can add and test more restrictive PCRs (for example, PCR 7) across the environment, assessing the balance between security and TPM measurement sensitivity.