-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center.
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center.
- HP Community
- Desktops
- Business PCs, Workstations and Point of Sale Systems
- HP z840 no TPM BIOS options
Create an account on the HP Community to personalize your profile and ask a question
07-03-2021 08:54 AM - edited 07-03-2021 09:07 AM
Hi,
I have a z840 workstation with dual E5-2690v4 and 128G of memory.
I have updated the BIOS to the latest version: 02.57 Rev.A (May 27, 2021)
I don’t have the option to manage TPM in the Security section of the BIOS.
I have reset the BIOS to default settings, set up an administrator password.
Still there is no TPM management at all.
What is wrong?
Solved! Go to Solution.
Accepted Solutions
07-04-2021 11:56 AM
run the TPM query command "tpm.msc" from a powershell or cmd prompt (admin rights)
in the box that shows, look at last line TPM Mfgr Info it should show IFX version number
if not you have workstation model that was made for countries that probit crypto functions, these workstations have motherboards that lack the TPM chip you can check using the information printed on the model label of your system
https://www.gp-digital.org/world-map-of-encryption/
https://wwclassx.hpcloud.hp.com/hpi/html/pcl.html
https://support.hp.com/us-en/product/hp-z620-workstation/5225037/document/c03604435
07-03-2021 11:26 AM
covered in z840 service manual and user manual
http://h10032.www1.hp.com/ctg/Manual/c04823811.pdf
from service manual: page 28 Chapter 2 System management
TPM Embedded
Security
Allows you to control TPM once a BIOS Administrator password is set.
● TPM Device - Makes the TPM device hidden or available.
● TPM State - Makes the TPM device disabled or enabled.
● TPM Clear - Lets you clear the TPM device.
● Embedded Security Device—This option becomes available if Embedded Device is
set to Available under Device Security.
NOTE: Embedded Security Device must be set to Device Available in the Device
Security menu, and you must create a Setup Password, in order to conƭigure the
Embedded Security Device.
Embedded Security Device—(Hidden or Available) turns the Trusted Platform
Mechanism (TPM) on and oƫ. Device Hidden is the default. If this option is made
available, the following options become available:
— Reset to factory settings
— Measure boot variables/devices to PCR1
For more information on TPM go to http://technet.microsoft.com/en-us/library/
cc749022(v=ws.10).aspx.
To enable the Embedded Security Device and to access any security features
associated with the device, you must enter a setup password.
Setting a device to Available enables the operating system to access the device.
Hidden makes the device unavailable. It is disabled by the BIOS and cannot be
enabled by the operating system.
CAUTION: Choosing Reset to Factory Settings may result in signƭicant data loss.
The embedded security device is a critical component of many security schemes.
Erasing the security keys prevents access to data protected by the Embedded
Security Device.
07-03-2021 01:16 PM - edited 07-03-2021 01:21 PM
Hi,
I have read that section of the manual.
The problem is that there is no TPM option available in the BIOS as you can see in the picture above.
I have pictures of a friend's z840 BIOS menu:
Thank you
07-04-2021 11:27 AM
Hi,
I have done a factory reset using the hardware button on the motherboard.
No change.
I have downgraded the BIOS firmware to the previous version (using BIOS option, this is not working on Windows).
No change.
Removed all PCIe cards except video.
Factory reset.
No change.
On the site:
Using my z840 serial number the description gives "HP Z840 BASE MODEL WORKSTATION"
Using my friend's z840 serial number the description gives "HP Z840 WORKSTATION"
Is that mean something about some hardware difference?
Thank you.
07-04-2021 11:56 AM
run the TPM query command "tpm.msc" from a powershell or cmd prompt (admin rights)
in the box that shows, look at last line TPM Mfgr Info it should show IFX version number
if not you have workstation model that was made for countries that probit crypto functions, these workstations have motherboards that lack the TPM chip you can check using the information printed on the model label of your system
https://www.gp-digital.org/world-map-of-encryption/
https://wwclassx.hpcloud.hp.com/hpi/html/pcl.html
https://support.hp.com/us-en/product/hp-z620-workstation/5225037/document/c03604435
07-04-2021 12:17 PM - edited 07-04-2021 01:13 PM
Hi,
well I'm out of luck:
It was made for
Czech Republic
TPM is Disabled...
Is that possible to reactivate it? Where is the TPM chip on the motherboard?
Thank you very much for your help.
07-04-2021 07:14 PM - edited 07-04-2021 07:15 PM
Hi,
I tried some experiments following the explanations from this site:
https://silvenga.com/upgrading-firmware-infineon-tpm/
Upgrading the Firmware
Let's make sure TPMFactoryUpd.exe detects the TPM.
So there is a TPM chip on my z840 motherboard.
So i tried to upgrade TPM firmware:
Now to run the upgrade.
So it cannot be flash.
I will try to search further.
Thank you,