October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
VGSources
PC gaming

Does Riot Vanguard Require TPM 2.0 and Secure Boot on Windows 11? The Current Answer

Riot Vanguard’s TPM 2.0 and Secure Boot checks on Windows 11 are not a new universal 2026 mandate. Here is what the restrictions mean and how to troubleshoot them safely.

By VGSources Team 6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes, for affected Windows 11 configurations—but this is not a brand-new universal 2026 mandate. Riot Vanguard has enforced TPM 2.0 and UEFI Secure Boot on relevant Windows 11 systems for years, especially in VALORANT. Newer restrictions can also require UEFI mode, VBS/HVCI, IOMMU, Exploit Protection, current firmware, or other controls listed in your specific VAN:RESTRICTION message.

Riot’s December 18, 2025 update tightened boot-security checks for systems exposed to motherboard pre-boot vulnerabilities. Its 2026 Vanguard On-Demand mode is a separate, optional operating mode with stricter Windows 11 prerequisites.

What Riot actually requires

Vanguard checks system integrity rather than relying on one identical checklist for every PC or every Riot game. VALORANT has the clearest public support documentation, and the exact restriction message on your machine is the controlling list.

Control What it means
TPM 2.0 A hardware-backed security processor. It may be a discrete chip or firmware TPM: Intel Platform Trust Technology (PTT) or AMD fTPM.
UEFI mode The modern firmware boot mode that replaces Legacy BIOS booting.
Secure Boot A UEFI feature that allows trusted, digitally signed boot software to load during startup. See Microsoft’s explanation.
VBS/HVCI Virtualization-Based Security and Hypervisor-Protected Code Integrity; HVCI appears in Windows Security as Memory integrity.
IOMMU Hardware-assisted isolation for devices and DMA access.
Exploit Protection A separate Windows security feature associated with VAN 9002.

Microsoft’s Windows 11 hardware baseline includes TPM 2.0 and Secure Boot capability, but a PC can run Windows 11 after an upgrade or installation workaround while those protections remain disabled. Vanguard’s runtime check is therefore not the same as merely passing Windows setup.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
  • Compatible with TPM-M R2.0
  • Chipset: Infineon SLB9665
  • PIN DEFINE:14Pin
  • Interface:LPC
  • Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.

Source: Microsoft Windows 11 minimum hardware requirements.

Is this a new 2026 requirement?

No. Riot’s retrospective says Vanguard introduced TPM 2.0 enforcement because Windows 11 was intended to have that security baseline, while some users installed or upgraded Windows 11 after bypassing Microsoft’s checks. That predates the 2026 On-Demand announcement.

There are three separate developments:

The established Windows 11 baseline

For relevant Vanguard configurations, TPM 2.0 and UEFI Secure Boot have been longstanding requirements. “Secure Boot capable” is not enough: Windows must normally be booted in UEFI mode with Secure Boot reported as enabled.

Source: Riot’s Vanguard retrospective.

The December 2025 pre-boot enforcement

Riot reported critical pre-boot vulnerabilities affecting some motherboard families, including advisories associated with ASUS, Gigabyte, MSI and ASRock. Code running before the operating system can create an attack surface that ordinary anti-cheat protections cannot fully cover. Affected players may receive VAN:RESTRICTION and need a BIOS or firmware update as well as security settings.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
ASRock TPM2-S TPM Module Motherboard (V2.0)
  • Nuvoton NPCT650
  • TCG PC Client Platform TPM Profile (PTP) Specification; Family 2.0 (Trusted Platform Module Library; Family 2.0)
  • TCG PC Client Specific TPM Interface Specification (TIS), Version 1.3 (TPM Main Specification; Family 1.2 Revision 116)
  • Low Standby Power Consumption

This does not mean every board from those manufacturers is affected. Model, BIOS version and the restriction message matter. A restriction is not automatically a cheating ban; it can mean Vanguard considers the configuration insufficiently trustworthy.

Source: Riot’s motherboard security update.

Optional Vanguard On-Demand in 2026

On-Demand lets Vanguard start when a Riot game launches and stop after the session instead of remaining active continuously. Riot says it requires Windows 11 version 25H2 or later, UEFI/Secure Boot, TPM 2.0, VBS/HVCI and IOMMU. Players who do not opt in can continue using Vanguard’s existing operating model.

Source: Riot Vanguard On-Demand.

Check your PC before changing firmware

Check TPM 2.0

  1. Press Windows + R.
  2. Enter tpm.msc and press Enter.
  3. Confirm that the TPM is “ready for use” and that Specification Version is 2.0.

You can also open Windows Security → Device security → Security processor details. If Windows cannot see the processor, it may be disabled in firmware or unavailable through the current BIOS.

Source: Microsoft Device security guidance.

Check UEFI and Secure Boot

  1. Press Windows + R.
  2. Enter msinfo32.
  3. Check BIOS Mode: it should say UEFI.
  4. Check Secure Boot State: it should say On.

If BIOS Mode says Legacy, do not simply switch the firmware to UEFI and enable Secure Boot. The Windows system disk may use MBR rather than GPT, and an unprepared change can prevent Windows from booting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
  • Compatible with:TPM2.0(MS-4462)
  • Chipset: INFINEON 9670 TPM 2.0
  • PIN DEFINE:12-1Pin
  • Interface:SPI
  • Supports:MSI Intel 400 Series and 500 Series Motherboards,MSI AMD B550 and A520 Series Motherboards,Windows 10 TPM 2.0

Check the other Windows controls

  • Windows Security → Device security → Core isolation: inspect Memory integrity.
  • Windows Security → App & browser control → Exploit protection: inspect system settings if your message identifies Exploit Protection.
  • Record the complete error text and code before making changes.

Fix TPM-related Vanguard errors

  1. Use msinfo32 to identify the system manufacturer, motherboard and BIOS information.
  2. Enter UEFI setup using the manufacturer’s documented key or recovery procedure.
  3. Look for names such as Intel PTT, AMD fTPM, Security Device Support, TPM Device or Trusted Computing.
  4. Enable the platform TPM, save, reboot and verify again with tpm.msc.

Menu names differ by manufacturer. Riot’s TPM 2.0 guide directs users to their PC or motherboard documentation and warns that incorrect firmware changes can cause problems.

Do not assume you need to buy a TPM module. Modern Intel and AMD systems often provide firmware TPM. A discrete module is motherboard-specific and would not fix missing UEFI, Secure Boot, VBS/HVCI, IOMMU or a vulnerable BIOS.

Enable Secure Boot safely

  1. Confirm BIOS Mode: UEFI in msinfo32.
  2. Determine whether the Windows disk is GPT or MBR.
  3. Back up important files and save your BitLocker or device-encryption recovery key.
  4. If the installation is Legacy/MBR, follow Microsoft’s or the manufacturer’s supported GPT-conversion procedure; do not guess at commands.
  5. Switch firmware to UEFI, enable Secure Boot, save and restart.
  6. Verify that msinfo32 now reports UEFI and Secure Boot State: On.

Secure Boot changes can trigger BitLocker recovery and can affect Linux, unsigned drivers, legacy operating systems or custom bootloaders. Microsoft recommends consulting the device maker because firmware interfaces and supported procedures vary.

Source: Microsoft Secure Boot guidance.

When TPM and Secure Boot already show as enabled

Those two values do not prove every Vanguard prerequisite is satisfied. Investigate these possibilities:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
  • TPM 2.0 module for Asus motherboard.
  • TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
  • LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
  • Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
  • Packing list:1x TPM 2.0 Module for ASUS
  • TPM is present but not ready, or firmware is too old to expose it correctly.
  • Secure Boot keys are missing, Windows still boots in Legacy mode, or firmware certificate handling needs an update.
  • The restriction additionally requires VBS/HVCI, IOMMU or Exploit Protection.
  • Riot has identified a motherboard pre-boot vulnerability requiring a BIOS update.
  • A dual-boot loader or unsigned boot component changes the measured boot state.
  • Vanguard needs a complete restart, Riot Client restart or reinstall after the change.
  • The PC is running an unsupported Windows Insider build.

Install BIOS files only from the motherboard or PC manufacturer. If you cannot identify the board, lack a recovery key, or are unfamiliar with firmware flashing, contact the manufacturer or a reputable repair professional rather than trying random BIOS utilities.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common Vanguard codes

Mappings can vary by game and Vanguard version, so use the current Riot message as the authority.

Message Typical direction
VAN9001 Check TPM 2.0 and related Windows 11 security state.
VAN9003 Check UEFI mode and Secure Boot.
VAN:RESTRICTION Follow the system-specific checklist shown by Vanguard; it may include firmware, IOMMU, VBS/HVCI or other controls.
VAN 9002 Check Windows Exploit Protection. Riot’s guidance is at Riot Support.
VAN: STATUS_SB_POLICY Investigate Secure Boot policy, boot-chain state, firmware and certificate updates.

What if the PC cannot meet the requirement?

  • Update the motherboard or laptop firmware through the official support page.
  • Return to an officially supported Windows configuration if Windows 11 was installed with a bypass.
  • Ask Riot Support about the exact restriction after documenting your settings and error.
  • If the CPU, motherboard or firmware lacks TPM 2.0 and UEFI support, a compatible system upgrade may be more sensible than an incompatible standalone TPM module.
  • Never use registry bypasses, HWID spoofers, cheat-evasion tools or unofficial BIOS files.

FAQ

Do I need to buy a physical TPM chip?

Usually not. Intel PTT and AMD fTPM commonly provide TPM 2.0 through firmware. A discrete module is compatible only with particular motherboards and does not solve other Vanguard checks.

Does a Vanguard restriction mean I am banned?

No. A restriction can indicate that Vanguard cannot establish the required system integrity. It is distinct from a confirmed cheating penalty, although you should follow Riot’s support process if it remains after correction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Asus TPM-SPI Trusted Platform Module (TPM)
  • Product Color: Black
  • Width: 0.6"
  • Depth: 0.5"
  • Additional Information: Interface: SPI Features: TPM IC: Nuvoton NPCT750 TPM Version: TPM 2.0 Pin Dimension: 14-1pin System Requirements: Windows® 10, UEFI OS
  • Country of Origin: Vietnam

Is Vanguard On-Demand mandatory?

No. Riot describes it as optional. It has stricter prerequisites—Windows 11 25H2 or later plus UEFI/Secure Boot, TPM 2.0, VBS/HVCI and IOMMU—while the existing Vanguard operating model remains available to users who do not enable it.

Can I keep a Linux or dual-boot setup?

Possibly, but Secure Boot and custom bootloaders can conflict with unsigned components or legacy operating systems. Check the bootloader’s signed-support options and be prepared for BitLocker recovery before changing firmware.

The Bottom Line

TPM 2.0 and Secure Boot are established Vanguard requirements for many Windows 11 gaming configurations, not a wholly new 2026 rule. Fix the exact controls named by Vanguard, verify UEFI and GPT before changing firmware, update the motherboard BIOS when required, and treat On-Demand as an optional mode with a broader security checklist.

Quick Recap

Bestseller No. 1
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
NewHail TPM2.0 Module LPC 14Pin Module with Infineon SLB9665 for ASUS Motherboard Compatible with TPM-M R2.0
Compatible with TPM-M R2.0; Chipset: Infineon SLB9665; PIN DEFINE:14Pin; Interface:LPC
$24.99
SaleBestseller No. 2
ASRock TPM2-S TPM Module Motherboard (V2.0)
ASRock TPM2-S TPM Module Motherboard (V2.0)
Nuvoton NPCT650; Low Standby Power Consumption
$25.41
Bestseller No. 3
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
NewHail TPM2.0 Module TPM SPI 12Pin Module with infineon SLB 9670 for MSI Motherboard Compatible with TPM2.0(MS-4462)
Compatible with:TPM2.0(MS-4462); Chipset: INFINEON 9670 TPM 2.0; PIN DEFINE:12-1Pin; Interface:SPI
$24.99
SaleBestseller No. 4
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
Yeiwenl TPM 2.0 Module with 14 Pin, TPM 2.0 Encryption Security Module for ASUS Motherboard Compatible with Win11
TPM 2.0 module for Asus motherboard.; TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
$23.74
Bestseller No. 5
Asus TPM-SPI Trusted Platform Module (TPM)
Asus TPM-SPI Trusted Platform Module (TPM)
Product Color: Black; Width: 0.6"; Depth: 0.5"; Country of Origin: Vietnam
$33.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from Patch Notes

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.