Pretty obvious place to start. The purpose of the TPM is to prevent users from running unapproved software on the device.