Yes, the Surface does have TPM and the system drive is bitlocker encrypted. What i meant was that you can use that to automatically encrypt and decrypt the encrypted sd card. You will need to manually run the bit locker command to encrypt SD card and set a password. The card will then need to be decrypted by use of that password.