Trusted Platform Module (TPM) allows encryption to occur using keys sealed within the TPM, a dedicated hardware security chip. TPM is also implemented in firmware for modern tablets and devices.
Drive Encryption supports TPM 1.2 and later for its TPM autoboot features.
The TPM provides platform authentication without the need for a user to enter credentials at the Pre-Boot Authentication (PBA) screen. The system can boot directly to the Windows login screen, where user authentication occurs.