Skip to content
How to Discover TPM Status across Windows Devices using Intune Inventory

How to Discover TPM Status across Windows Devices using Intune Inventory

Written By Anoop C Nair
Last Updated September 11, 2025
Posted In Intune
SHARE

Let’s discuss how to Discover TPM Status across Windows Devices using Intune Inventory. The Trusted Platform Module (TPM) is a dedicated security chip embedded in most modern Windows devices. It provides hardware-based protection for sensitive data.

Microsoft Intune collects several important properties related to the Trusted Platform Module (TPM) on Windows devices. These properties help you understand the status and details of the TPM chip.

This feature in Intune helps IT administrators by giving them centralized visibility into the TPM status across all managed Windows devices. With this data, admins can quickly verify if TPM is properly configured, activated and enabled which is essential for enabling security features like BitLocker encryption and Secure Boot.

In this post, you will find all the essential details on how to discover the TPM (Trusted Platform Module) status across Windows devices using Microsoft Intune Inventory. TPM plays a critical role in device security, supporting features like BitLocker, Secure Boot, etc.

Patch My PC

How to Discover TPM Status across Windows Devices using Intune Inventory

You can easily discover the TPM status across Windows devices using Intune Inventory by following a few simple steps in the Microsoft Intune admin center. Start by signing in with your administrator account. Once logged in, navigate to the left-hand menu and click on Devices. From there, select Manage devices and then choose the Configuration section. Next, click on Create, select New Policy, and begin setting up your profile.

PlatformProfile Type
Windows 10 and laterProperties Catalog
How to Discover TPM Status across Windows Devices using Intune Inventory – Table 1
How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.1
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.1

Basics Tab of your Intune Policy Setup

In the Basics tab of your Intune policy setup, you’ll need to provide key details to identify and describe the policy. For the Name, enter “Discover TPM Status across Windows Devices” this clearly indicates the purpose of the policy. In the Description field, you can add a brief explanation such as “How to Discover TPM Status across Windows Devices using Intune Inventory.”

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.2
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.2

Choose the Inventory Details

To choose the inventory details you want to collect, go to the full inventory property library and click on ‘Add properties to search.’ From there, browse through the available options and select the specific properties you need. Then, click the ‘+ Add properties’ link in the window that appears to include them in your policy configuration.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.3
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.3

TPM (Trusted Platform Module) Inventory in Intune

The TPM (Trusted Platform Module) inventory in Intune provides a comprehensive set of details that help assess the status and configuration of the TPM chip on Windows devices. It includes whether the TPM is Owned and Enabled, which indicates if it is active and properly configured.

TPM

  • Selected properties (9)
    • Activated
    • Enabled
    • Physical Presence Version
    • Product Name
    • Manufacturer
    • Spec Version
    • Manufacturer Id
    • Manufacturer Version
How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.4
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.4

TPM

You also get information about the Physical Presence Version, which relates to user interaction requirements for certain operations. Additional details include the Product Name of the TPM, the Manufacturer name, and the corresponding Manufacturer ID and Manufacturer Version.

  • TPM
    • Activated – Refresh every 24 hours
    • Enabled – Refresh every 24 hours
    • Manufacturer – Refresh every 24 hours
    • Manufacturer Id – Refresh every 24 hours
    • Manufacturer Version – Refresh every 24 hours
How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.5
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.5

Microsoft Intune Scope Tag

In Microsoft Intune, a scope tag is a way to logically group and control access to resources. It’s a powerful tool used in role-based access control (RBAC) to help organizations delegate management tasks while maintaining control and security.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.6
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.6

Assignments

In Microsoft Intune, assignments define which users or devices receive a specific policy. Assignments are a core part of how Intune delivers configuration, compliance, security settings, and applications to endpoints across your organization.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.7
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.7

Review + Create

The “Review + Create” page gives you a summary of all the settings and selections. This is your last chance to review everything before applying the policy or configuration. The below screenshot shows more details.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.8
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.8

Settings and Configurations

Once the policy is successfully created, a notification will appear confirming its creation. This message indicates that all your chosen settings and configurations have been applied and saved correctly. The notification is shown in the below window.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.9
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.9

End Result

To access the collected inventory data in Intune, go to Devices > Windows Devices and select the specific device you want to review. Then, under the Monitor section, click on Resource Explorer. From there, you can choose a category to view detailed hardware information, including TPM status and other device-specific data.

Starting with Intune’s September 2509 release, the Resource explorer pane will be renamed to Device inventory. This is a UI update only no changes will be made to functionality or data. The new name will appear under Devices > select a platform > select a device > Monitor, and will be visible if you have at least one corporate-owned or Windows device targeted by a properties catalog policy.

OwnedActivatedEnabledManufacturerManufacturer IdManufacturer VersionPhysical PresenceProduct NameSpec VersionLast updated
TrueTrueTrueMSFT1,297,303,1248224.786.18.31.3TPM Simulator2.0, 0, 1.3807/18/2025, 02:35:21 PM
How to Discover TPM Status across Windows Devices using Intune Inventory – Table 2
How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.10
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.10

Resource Explorer

The Trusted Platform Module (TPM) on this device is fully functional, with ownership established and both activation and enablement confirmed. It is provided by a recognized manufacturer and operates using a specific firmware version. The TPM supports physical presence requirements and is identified as a simulator model.

How to Discover TPM Status across Windows Devices using Intune Inventory - Fig.11
How to Discover TPM Status across Windows Devices using Intune Inventory – Fig.11

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read