Microsoft Pluton as Trusted Platform Module

Microsoft Pluton is a security processor that provides several hardware security capabilities. This article covers one of them: Pluton's usage as a Trusted Platform Module (TPM 2.0). For an overview of Pluton itself, see Microsoft Pluton security processor.

Microsoft Pluton as a security processor

Pluton is integrated within the SoC subsystem, and provides a flexible platform for running firmware that implements end-to-end security functionality authored and maintained by Microsoft.

Pluton also solves the major challenge of keeping its own firmware up to date across the entire PC ecosystem, by delivering firmware updates directly from Windows Update. Today customers receive updates to the firmware of their security processors from various sources, which can make it difficult for them to apply these updates.

Device manufacturers can use a discrete TPM or a firmware TPM as the system TPM, while keeping Pluton available to the system for use cases beyond the TPM.

Microsoft Pluton as Trusted Platform Module

Where Pluton is configured as the TPM, it supports the TPM 2.0 industry standard, allowing customers to immediately benefit from the enhanced security in Windows features that rely on TPM including BitLocker, Windows Hello, and System Guard.

As with other TPMs, credentials, encryption keys, and other sensitive information can't be easily extracted from Pluton even if an attacker installs malware or has complete physical possession of the device. Storing sensitive data like encryption keys securely within the Pluton processor, which is isolated from the rest of the system, helps ensure that emerging attack techniques such as speculative execution can't access key material.

To learn more about the scenarios in Windows that use the TPM, see TPM and Windows Features.

Important

Beginning with 2026 silicon, Microsoft Pluton no longer serves as the TPM on AMD and Qualcomm platforms. On these platforms, as well as on Intel, TPM 2.0 functionality is instead delivered through the vendor's firmware TPM (fTPM) or a discrete TPM.

Existing devices: Devices built on 2025 or earlier AMD and Qualcomm silicon that ship with Pluton configured as the TPM remain fully serviced and supported. This change applies only to new silicon platforms introduced in 2026 and later.

This change affects only Pluton's TPM functionality. The Pluton security processor will continue to be present and supported on existing and future Windows devices to provide a hardware isolated security environment for Windows.

Microsoft Pluton security processor