The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use of TPM for automatic booting

Prev Next

The existing automatic booting feature creates a copy of the system's encryption key as a plain-text file in the Pre-Boot File System. With the TPM autoboot feature, Drive Encryption uses TPM to encrypt this file.

The file can only be decrypted on the system that encrypted it and only if the boot path is unmodified from when it was encrypted. This makes sure that only the specific TPM can decrypt the file, and moreover (like SecureBoot) ensures that malware has not changed the boot path. A combination of TPM encryption and boot path measurements allow the user to securely bypass Pre-Boot Authentication (PBA) through to Windows logon, where user authentication occurs.

Note

Any software update that changes the boot path, like a Microsoft update to the UEFI bootloader will result in pre-boot being displayed since the boot path has changed, and therefore the disk encryption key cannot be unsealed. For example, PBA will be shown when an Operating System is upgraded from Windows 10 to Windows 11.

Drive Encryption uses TPM Platform Configuration Registers (PCRs) 0, 2 and 4 to measure the boot path and shows the PBA when the measurements of the PCRs are modified.

Here are descriptions of the individual registers:

Platform Configuration Registers (PCRs)

Description

PCR 0

Core root-of-trust for measurement, EFI boot and run-time services, EFI drivers embedded in system ROM, ACPI static tables, embedded SMM code, and BIOS code.

PCR 2

Option ROM code.

PCR 4

Master Boot Record (MBR) code or code from other boot devices.

When autoboot is enabled, we also recommend enabling password synchronization capabilities.