Hey @Niesfisch Welcome to the forums! To determine whether a device should support Full-time Windows Hello (which is only available with the Store version of Enpass), we rely on the API provided by the Microsoft. This is the only way to distinguish whether the security keys are generated by a legit Hardware TPM. There is little in the scope for any app to do in this case. Even with the external TPMs we cannot assure full-time support for Enpass until Windows Attestation API allows it.