Policy
Ignore the local list of blocked TPM commands
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista
This policy setting allows you to enforce or ignore the computer's local list of blocked Trusted Platform Module (TPM) commands. If you enable this policy setting, Windows will ignore the computer's local list of blocked TPM commands and will only block those TPM commands specified by Group Policy or the default list. The local list of blocked TPM commands is configured outside of Group Policy by running "tpm.msc" or through scripting against the Win32_Tpm interface. The default list of blocked TPM commands is pre-configured by Windows. See the related policy setting to configure the Group Policy list of blocked TPM commands. If you disable or do not configure this policy setting, Windows will block the TPM commands found in the local list, in addition to commands in the Group Policy and default lists of blocked TPM commands.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\TPM\BlockedCommands\IgnoreLocalList | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerConfigure the level of TPM owner authorization information available to the operating systemAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerConfigure the list of blocked TPM commandsAt least Windows Vista
- ComputerConfigure the system to clear the TPM if it is not in a ready state.At least Windows Server 2016, Windows 10 Version 1709
- ComputerConfigure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.At least Windows Server 2016, Windows 10 Version 1703
- ComputerIgnore the default list of blocked TPM commandsAt least Windows Vista
- ComputerStandard User Individual Lockout ThresholdAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerStandard User Lockout DurationAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerStandard User Total Lockout ThresholdAt least Windows Server 2012, Windows 8 or Windows RT