Policy
Configure the list of blocked TPM commands
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista
This policy setting allows you to manage the Group Policy list of Trusted Platform Module (TPM) commands blocked by Windows. If you enable this policy setting, Windows will block the specified commands from being sent to the TPM on the computer. TPM commands are referenced by a command number. For example, command number 129 is TPM_OwnerReadInternalPub, and command number 170 is TPM_FieldUpgrade. To find the command number associated with each TPM command with TPM 1.2, run "tpm.msc" and navigate to the "Command Management" section. If you disable or do not configure this policy setting, only those TPM commands specified through the default or local lists may be blocked by Windows. The default list of blocked TPM commands is pre-configured by Windows. You can view the default list by running "tpm.msc", navigating to the "Command Management" section, and making visible the "On Default Block List" column. The local list of blocked TPM commands is configured outside of Group Policy by running "tpm.msc" or through scripting against the Win32_Tpm interface. See related policy settings to enforce or ignore the default and local lists of blocked TPM commands.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\SOFTWARE\Policies\Microsoft\Tpm\BlockedCommands\Enabled | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
The list of blocked TPM commands: ID BlockedCommandsList_Ordinals2 | list | HKLM\SOFTWARE\Policies\Microsoft\Tpm\BlockedCommands\List\Enabled Type REG_MULTI_SZ | List: additive |
Other policies in this category
Explore related policies at the same level.
- ComputerConfigure the level of TPM owner authorization information available to the operating systemAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerConfigure the system to clear the TPM if it is not in a ready state.At least Windows Server 2016, Windows 10 Version 1709
- ComputerConfigure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.At least Windows Server 2016, Windows 10 Version 1703
- ComputerIgnore the default list of blocked TPM commandsAt least Windows Vista
- ComputerIgnore the local list of blocked TPM commandsAt least Windows Vista
- ComputerStandard User Individual Lockout ThresholdAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerStandard User Lockout DurationAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerStandard User Total Lockout ThresholdAt least Windows Server 2012, Windows 8 or Windows RT