Back to Blog
Guides

TPM Ban: Endorsement Keys and TPM 2.0 Hardware Bans

Saturn TeamUpdated September 29, 2026
TPM Ban: Endorsement Keys and TPM 2.0 Hardware Bans

A TPM ban is a hardware ban built on a PC's Trusted Platform Module, the security chip that Windows 11 requires in version 2.0. Every TPM carries an endorsement key that Microsoft describes as unique to that TPM, and that key is one of the few parts of your HWID that a new account, a fresh Windows install or a cleared chip leaves exactly as it was.

Anti-cheat publishers now say this out loud. ACE's security brief of November 28, 2025 tied TPM 2.0 in Delta Force to more accurate hardware bans, and on June 24, 2026 Riot described the TPM as a form of hardware identity that a cheater can't swap out without new silicon. At least 4 anti-cheat platforms (Riot Vanguard, EA Javelin Anticheat, Anti-Cheat Expert and FACEIT) now build TPM 2.0 into their checks. Below: what the endorsement key is, which games require the chip, how to see your own key, what can and can't change it, and what a TPM spoofer does.

What Is a TPM Ban?

A TPM ban is a ban tied to your hardware, in which the PC is recognized through its TPM rather than only through the account that was caught. None of the publishers covered here uses the phrase "TPM ban" in its rules, but two have written down what the chip is for. Anti-Cheat Expert's brief for Delta Force says the TPM allows "significantly more accurate hardware bans," so a removed cheater stays removed. Riot's Vanguard On-Demand post from June 2026 goes further and walks through the logic: the endorsement key is written into the chip at the factory, so a ban on that key would force a cheater to replace the TPM, or the whole CPU, to get back in.

That is the whole appeal for an anti-cheat. An account ban stays with one account, and a Windows reinstall doesn't touch the hardware, while the endorsement key sits in the TPM's own protected storage and reads the same on every boot. Riot's article on hardware bans still doesn't list which identifiers it checks, and the other publishers covered here don't either, so a TPM ban is best read as the TPM key being one strong input among several. Riot's own games show the pattern most plainly, since Valorant hardware bans come with their own error code and their own rules on how long they last.

What Is the TPM Endorsement Key?

The TPM endorsement key (EK) is an asymmetric key pair that lives inside the TPM. Microsoft's TPM fundamentals page says the private half is never revealed or accessible outside the chip. Software can read only the public half, called EKpub, and on many chips a certificate the TPM maker issued for it, the EKcert. Microsoft notes that not every TPM ships with an EKcert. The Trusted Computing Group, which writes the TPM standard, defines how both are made.

Microsoft's TPM Key Attestation guide sums up why games care: the EK is unique for every TPM, it can identify that TPM, and it "can't be changed or removed." A certificate authority can even keep an allow list of approved devices made of nothing but SHA-256 hashes of their EKpub.

Where the TPM physically sits decides what the key is tied to. A discrete TPM (dTPM) is a small module on the motherboard, next to the board's own motherboard serial. A firmware TPM (fTPM) runs inside the processor: Intel calls it Platform Trust Technology (PTT), AMD calls it fTPM, and Riot notes it is built into every Ryzen CPU. On a PC running a firmware TPM, the TPM identity is tied to the processor, even though CPUs themselves no longer report a unique CPU serial number.

Diagram of the TPM endorsement key: a private half that never leaves the chip, a readable EKpub hashed to 64 characters, and an EKcert from the TPM maker that not every chip has.

Which Games Require TPM 2.0?

Riot, EA, Anti-Cheat Expert and FACEIT each build TPM 2.0 into the checks for at least some of their games, according to their own support pages and announcements. The rule differs by publisher:

Game or platform Anti-cheat TPM rule
Valorant, League of Legends Riot Vanguard TPM 2.0; a firmware TPM for restricted accounts
Battlefield 6 EA Javelin Anticheat TPM 2.0 must be enabled
Delta Force Anti-Cheat Expert Secure Boot and TPM 2.0 checks
FACEIT matches FACEIT Anti-Cheat TPM 2.0 on Windows 10 and 11

Riot's "Enable TPM 2.0" guide covers the VAN 9001, VAN 9003 and VAN 9090 errors and says TPM 1.2 won't satisfy Vanguard. It also draws the line between chip types: a discrete module passes the basic check, but an account hit with a Vanguard restriction needs a firmware TPM. Riot's reason, given in its June 2026 post, is that a discrete module can be swapped in a few minutes, which would make a hardware ban too cheap to dodge.

EA's help center says you need TPM 2.0 enabled to play Battlefield 6 on PC, and EA's September 2026 update on Javelin calls the requirement a new security baseline for its next titles. FACEIT asks every player on Windows 10 or 11 to turn TPM 2.0 on and expects the Attestation and Storage checks under Security processor details to read "Ready".

Screenshot of tpmtool getdeviceinformation output with the TPM Version 2.0 and Ready For Attestation lines circled, and the user folder in the command path masked.

How to Check Your TPM and Endorsement Key

Windows shows the TPM's status in two built-in places, and PowerShell can show the endorsement key itself. The publishers' own TPM guides send players to the first two:

  1. Press Windows + R, type tpm.msc and press Enter. The TPM Management window should report "The TPM is ready for use", with Specification Version 2.0.
  2. Open Windows Security, then Device security, then Security processor details. FACEIT expects both Attestation and Storage to show "Ready".
  3. For the key, open PowerShell as administrator and run Get-TpmEndorsementKeyInfo with -HashAlgorithm Sha256. Microsoft documents the result as IsPresent, PublicKey, PublicKeyHash and the manufacturer certificates, and its attestation guide runs the cmdlet from an elevated prompt.

Command Prompt has a shorter summary too. Microsoft's tpmtool getdeviceinformation prints the TPM's basic information, with lines such as TPM Version and Ready For Attestation, which is the same readiness FACEIT checks for.

The PublicKeyHash line is a 64-character SHA-256 hash of your EKpub, shown in Microsoft's example as a single long value such as 7076...a681. It is the closest thing Windows gives you to a readable "TPM ID", and it stays the same as long as the TPM does.

Can You Change Your TPM Endorsement Key?

No, you can't change the TPM endorsement key from Windows. Microsoft's attestation guide rules it out, as quoted above, and none of the TPM tools Windows ships offers a way to do it.

Clearing the TPM is the obvious first try, and it doesn't touch the key. The Clear-Tpm cmdlet, or Clear TPM under Security processor details, resets the chip to an unowned state and wipes the keys created inside it, with data loss for anything those keys protected, such as a sign-in PIN. The EK is generated from the TPM's endorsement seed, and clearing doesn't replace that seed. The TPM 2.0 command that does, TPM2_ChangeEPS, needs platform authorization, and Windows' TPM cmdlets don't include it.

That leaves hardware. A different TPM means a different EK, so the ways out of a key-based ban are a new discrete module or, on a firmware TPM, a new processor, which is exactly the cost Riot says it wants cheaters to face. Swapping parts still leaves the other identifiers behind, and what a hardware ID changer can and can't reach differs from one component to the next.

What a TPM Spoofer Changes

A TPM spoofer changes what the TPM is reported to be, not the key inside it. The tool sits between the TPM driver and the programs that ask for the public key and hands those programs a different value; a public proof of concept on GitHub does it by hooking the Windows TPM driver and randomizing public key reads. Nothing in that process reaches the chip's protected storage, so the real EK and its certificate are unchanged the moment the spoofer stops.

The hard case for any spoofer is attestation. In Microsoft's key attestation model, the device has to prove it holds the private half that belongs to an EK the verifier trusts, and a swapped public value has no matching private key inside the chip. Anti-cheats don't publish which checks they run, so no one outside can say which games rely on that proof.

Comparison of what a TPM spoofer can change, the reported public key and TPM values, and what it cannot change: the key inside the chip, its certificate, an attestation proof or a banned account.

Saturn runs on Windows PCs as a hardware ID spoofer, and its public spoof list names the TPM next to the CPU, motherboard and SMBIOS, RAM, NVMe, SSD and HDD, GPU, monitor EDID, MAC address, USB and UEFI. A spoofer such as Saturn clears the HWID ban on your PC, in one of two modes: temporary mode clears the ban while Saturn runs, with unlimited profiles to switch between, and permanent mode rewrites the reported IDs for good under a single profile. The trade-offs of picking a temporary or permanent spoofer, and the general rules on what a spoofer can and cannot change, hold for the TPM the same way they do for every other identifier. Two limits stay true either way: a banned account stays banned, and Epic, for its part, warns that tools which hide or rewrite hardware IDs can be detected and can cost an account a permanent ban. Saturn's trial is free for 24 hours, with sign-up by email and no card on file.

TPM Ban FAQ

Is a TPM ban permanent?

The length of a TPM ban is set by the publisher, not by the chip. The TPM only makes the PC recognizable; whether the ban on it lasts months, years or has no end date is the game's policy.

Does clearing the TPM remove a ban?

No. Clearing the TPM removes the keys created inside it, but Microsoft says the endorsement key can't be changed or removed, so the chip reports the same EK after a clear.

Does reinstalling Windows remove a TPM ban?

No. The endorsement key is stored in the TPM itself, on the motherboard or inside the CPU, so a new Windows install on the same hardware reads the same key.

Can a new CPU get around a TPM ban?

On a PC that uses a firmware TPM, a new processor brings a new TPM and a new endorsement key, and Riot names that as the cost of dodging a key ban. The rest of the PC's identifiers stay the same, so a new CPU alone is rarely a clean slate.

Does Saturn change the TPM endorsement key?

No tool changes the key inside the chip. Saturn changes the TPM values that software on the PC is given, which is what "spoofing the TPM" means.

Do I need TPM 2.0 to play Valorant?

Yes on Windows 11. Riot's support guide says Vanguard requires TPM 2.0, that TPM 1.2 won't do, and that accounts under a Vanguard restriction need a firmware TPM specifically.