Scenario 2: Turn off or clear the TPM
This scenario covers two common tasks that administrators would perform during a reconfiguration or recycling of a TPM-equipped computer. These tasks are turning off the TPM and clearing the TPM.
Turn off the TPM
Some administrators might decide that some TPM-equipped computers in their network should be prevented from making full use of the capabilities that a TPM provides. The following procedure steps you through the process of turning off the TPM.
noteNote
A physical presence is not required to turn off the TPM if you have the TPM owner password.
To perform the following procedure, you must be logged on to a TPM-equipped computer with administrator credentials.
To turn off the TPM
Click Start, click All Programs, click Accessories, and then click Run.
Type tpm.msc in the Open box, and then press ENTER. The TPM Management console is displayed.
If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue. For more information, see Additional resources at the end of this document.
In the Actions pane, click Turn TPM Off.
In the Turn off the TPM security hardware dialog box, select a method for entering your password and turning off the TPM:
If you have the removable media onto which you saved your TPM owner password, insert it and then click I have a backup file with the TPM owner password. In the Select backup file with the TPM owner password dialog box, click Browse to locate the .tpm file saved on your removable media, click Open, and then click Turn TPM Off.
If you do not have the removable media onto which you saved your password, click I want to type the TPM owner password. In the Type your TPM owner password dialog box, enter your password (including dashes), and then click Turn TPM Off.
If you do not know your TPM owner password, click I do not have the TPM owner password, and follow the instructions provided in the dialog box and subsequent BIOS screens to turn off the TPM without entering the password.
noteNote
You can turn off the TPM or perform a limited number of TPM management tasks without entering the TPM owner password by just being present at the computer.
The status of your TPM is displayed in the Status box in the results pane.
Clear the TPM
Clearing the TPM cancels the TPM ownership and resets it to factory defaults. This should be done when a TPM-equipped client computer is recycled, or when the TPM owner has lost the TPM owner password. The following procedure steps you through the process of clearing the TPM.
noteNote
A physical presence is not required to clear the TPM, if you have the TPM owner password.
To perform the following procedure, you must be logged on to a TPM-equipped computer with administrator credentials.
To clear the TPM
Click Start, click All Programs, click Accessories, and then click Run.
Type tpm.msc in the Open box, and then press ENTER. The TPM Management console is displayed.
If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue. For more information, see Additional resources at the end of this document.
CautionCaution
Clearing the TPM resets it to factory defaults. You will lose all created keys and any data protected only by those keys.
In the Actions pane, click Clear TPM. If the TPM is turned off, turn on the TPM before clearing it. (The steps to turn on the TPM are provided in Step 1: Turn on the TPM.)
In the Clear the TPM security hardware dialog box, select a method for entering your password and clearing the TPM:
If you have the removable media onto which you saved your TPM owner password, insert it and then click I have a backup file with the TPM owner password. In the Select backup file with the TPM owner password dialog box, click Browse to locate the .tpm file saved on your removable media, click Open, and then click Clear TPM.
If you do not have the removable media onto which you saved your password, click I want to type the TPM owner password. In the Type your TPM owner password dialog box, enter your password (including dashes), and then click Clear TPM.
If you do not know your TPM owner password, click I don't have the TPM owner password, and follow the instructions provided in the dialog box and subsequent BIOS screens to clear the TPM without entering the password.
noteNote
You can clear the TPM or perform a limited number of TPM management tasks without entering the TPM owner password by just being present at the computer.
The status of your TPM is displayed in the Status box in the results pane.
https://technet.microsoft.com/...usted-platform-module-overview