Windows 10 EoS: who’s missing TPM 2.0 in your estate?

Windows 10 hits end of support on 14 October 2025. If a device can’t move to Windows 11, you’re looking at Extended Security Updates or leaving users on an ageing OS. Neither is a great long-term plan.

The biggest blocker you’ll meet is TPM 2.0. Without TPM 2.0 (and Secure Boot/UEFI), upgrading to Windows 11 is not straightforward. The good news: you don’t need to go device by device or tenant by tenant in Intune. Eido surfaces this information for you in one place, as it's a property on each device.

Why TPM 2.0 matters (and why to check now)

TPM 2.0 isn’t just a box-tick. It underpins BitLocker, credential protection and Windows 11’s security model. Plenty of devices technically support it but ship with firmware TPM disabled, or need a BIOS update before they’ll report 2.0. That’s why an early sweep is worth its weight so procurement, engineering and comms can move in lockstep and you’re not scrambling next summer.

See TPM posture across every tenant without the tab-hopping

With Eido, you connect all your Intune tenants once and get an estate-wide readout. Navigate to Reports and take a look at the TPM Version and TPM Specification fields. That’s your first pass list of Windows 11 blockers.

From there, add UEFI as a column so you’re not fixing one issue only to discover another later. Save the whole thing as a segment (e.g., Win11-Blockers) so it updates as devices enrol or change state. You’ll have a single source of truth you can export for client updates, CAB meetings, and budget asks. Everything needed is on this report for TPM, with Secure Boot info coming soon.

Make a plan device owners will actually follow

Not every red flag needs new hardware. Read the list like this:

  • Enable it: Many modern machines have firmware TPM that’s simply turned off. Enable in BIOS/UEFI, switch to UEFI if needed, and you’re done.
  • Update it: Some will report an older TPM version until you apply the right BIOS/firmware package.
  • Replace it: Older kit that lacks TPM 2.0 (or fails the CPU bar) goes on the refresh list.
  • For VMs: Flip on vTPM and Secure Boot in the VM config before you upgrade the guest OS.

Eido also shows the device make and model, allowing you to see at a high level devices by make and model on our dashboards. Once you’ve identified a specific model that can’t be upgraded, you can filter on it in the Devices view. This feature is super helpful for locating devices that need to be replaced or understanding how to go about upgrading the firmware version (e.g., via Intune using Entra group membership).

Keep the list clean while you migrate

Nothing derails a project like “new” non-compliant machines appearing mid-flight. In Eido, you can set an alert for devices with TPM < 2.0 or TPM absent at a high level. While this alert isn't currently available at such granular detail, you can still route notifications for any device issues to Teams/Slack or automatically create a ServiceNow ticket. This ensures that new builds and late joiners don’t reintroduce risk while you're closing the gap.

Reporting that wins budget conversations

Stakeholders don’t want raw inventory; they want “are we safe?” and “what will it cost?”. Eido’s export gives you:

  • Total devices and % ready for Windows 11
  • A clean count of TPM 2.0 blockers, by site or department

That combination tends to unlock procurement faster than a spreadsheet of serial numbers ever will.

Common snags to avoid

Two gotchas bite most teams: assuming “TPM present” equals 2.0 (it doesn’t, check the version), and forgetting VMs(they need vTPM just like physical devices need TPM). The third is human: doing a one-off audit, fixing half the list, and moving on. Keep the segment and alerts live until your readiness number reads where you want it, then leave the alert in place to catch regressions.

TL;DR

  • Windows 10 support ends 14 Oct 2025.
  • Windows 11 needs TPM 2.0 (plus Secure Boot/UEFI).
  • Use Eido to find every device without TPM 2.0 across all Intune tenants, prioritise enable/update/replace, and keep the list clean with proactive alerts.
  • Export simple, client-ready reports that unlock budget and track progress.

See your own Intune data in action

If you’re managing multiple tenants, this is exactly the kind of cross-estate job Eido was built for. Connect your tenants, pull the encryption report view, and you’ll know how far you are from the October 2025 line.

Ready to learn more? Book your demo today!

Latest Articles

Navigating the Microsoft Intune console: What to do when results conflict (and which to believe)

Navigating the Microsoft Intune console: What to do when results conflict (and which to believe)

Read more
Windows 10 EoS: who’s missing TPM 2.0 in your estate?

Windows 10 EoS: who’s missing TPM 2.0 in your estate?

Read more
Unlocking Software Efficiency with Software Metering in Microsoft Intune

Unlocking Software Efficiency with Software Metering in Microsoft Intune

Read more
ISO27001 and ISO9001 certificate annocement

ISO27001 and ISO9001 certificate annocement

Read more
System Center Dudes Partnership Press Release

System Center Dudes Partnership Press Release

System Center Dudes and Eido are partnering to bring you the complete package for Intune

Read more
Eido is in Edinburgh for Workplace Ninjas UK 2025

Eido is in Edinburgh for Workplace Ninjas UK 2025

Eido is sponsoring Workplace Ninjas UK 2025

Read more
Join us at MMS at MOS 2025

Join us at MMS at MOS 2025

Read more
See you at Modern Endpoint Management Summit 2025

See you at Modern Endpoint Management Summit 2025

Read more
EBF Partnership Press Release

EBF Partnership Press Release

Eido Partners with EBF to Deliver Game-Changing Intune Reporting Solutions to EBF Customers.

Read more
Join us at MMS 2024 Flamingo Edition

Join us at MMS 2024 Flamingo Edition

We're thrilled to announce that Eido.cloud will be sponsoring the MMS 2024 Flamingo Edition, taking place this October in sunny Florida!

Read more
Windows 11 24H2 - What's New?

Windows 11 24H2 - What's New?

Just dived into Windows 11 Version 24H2—here's our take on the coolest new features that every sysadmin and IT pro needs to know about!

Read more
Workplace Ninjas - See you there?

Workplace Ninjas - See you there?

We are super excited to sponsor the Workplace Ninjas UK event in Manchester, focusing on Microsoft technologies. We hope to see you there!

Read more
Patch Reporting in Intune: Why It's a Big Deal

Patch Reporting in Intune: Why It's a Big Deal

Read more
Microsoft Intune: A Game-Changer for Modern IT Management

Microsoft Intune: A Game-Changer for Modern IT Management

Why IT Pro's and Managers should choose Microsoft Intune as their go-to MDM solution.

Read more
Managing Bitlocker using Microsoft Intune

Managing Bitlocker using Microsoft Intune

Deploy and manage BitLocker across your organization using Microsoft Intune, ensuring enhanced data security through encryption and key recovery.

Read more
Create and Deploy Basic Wifi profile in Microsoft Intune

Create and Deploy Basic Wifi profile in Microsoft Intune

The blog post explains how to easily set up and deploy WiFi profiles with Microsoft Intune, enabling secure and automatic network access for users and devices across an organization.

Read more

Ready to learn more? Book your demo today!