Trusted Platform Module - Key Attestation not working

Dave 16 Reputation points
2021-06-23T10:18:45.08+00:00

Dear Community,

I've been on this for several days now and i just can't get it to work. So my hope lies with you guys! :-)

My issue is the following:

  • I have a Intel NUC with a TPM 2.0 device.
  • I try to use Auto-Deployment with Shared Multi-user Device.
  • I imported the HWID.csv with the correct hash into MS Endpoint Manager.

When i startup the computer it goes into OOBE correctly but it stops at ... with error.

After some research it appears to be something with the TPM module.

What i've tried so far:

  • Checked for a new firmware upgrade of the TPM device. There is none.
  • Cleared TPM so many times i can't remember.
  • Bios settings set at Secure Boot
  • Played with secure boot settings, tried ALL possible settings.
  • Did every possible TPM powershell command to fiddle with TPM settings.

The weird part is this. When i go to "Settings - Security - Device Security - Security Processor", it says that storage is Ready but Attestation is 'Not Supported'. But when i go to Powershell and use the command 'Get-TpmSupportedFeature' it says 'Key Attestation'. So which is it? Is it supported or not :-S...

Does anyone have an idea how to proceed on this matter?

Windows for business Windows Client for IT Pros Devices and deployment Configure application groups
{count} votes

4 answers

Sort by: Most helpful
  1. Johan Valstar 11 Reputation points
    2022-01-27T14:48:52.167+00:00

    I have the same, I'm running now on Windows 11.

    Powershell gives:
    PS C:\Windows\System32> Get-TpmSupportedFeature
    key attestation
    PS C:\Windows\System32>

    169089-image.png

    Details of the windows version:
    Edition Windows 11 Pro
    Version 21H2
    Installed on ‎27-‎1-‎2022
    OS build 22000.469
    Experience Windows Feature Experience Pack 1000.22000.469.0

    1 person found this answer helpful.

  2. Jiang Zhang 811 Reputation points
    2021-06-25T10:32:46.547+00:00

    Hi,

    If you are facing this issue on windows machine, please provide a detailed description of your machine’ OS version? Is that a win10 or windows server 2016 or any other version?

    If it is not windows-related, based on my research, you may find a solution referring to the following link.

    https://trustedcomputinggroup.org/wp-content/uploads/TCG_IWG_DevID_v1r2_02dec2020.pdf

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Best Regards,
    Mulder Zhang

    --------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Q pvatans 1 Reputation point
    2022-03-21T18:22:37.447+00:00

    185316-screenshot-6.png

    same

    0 comments No comments

  4. paxin 0 Reputation points
    2024-05-04T12:24:28.3266667+00:00

    Screenshot 2024-05-04 154042

    Date of reporting problem: 2024-May-4th
    My System:
    Ryzen 7700 - Asus Rog Strix X670 E A Gaming - Crucial 5200 2*32Gb Ram (64Gb Total) - Ryzen iGPU
    **All Drivers and Bios Updated to the latest version

    Windows 11 Pro 23H2 - Fully up to date

    Description of problem:

    TPM security cometimes shows up with Attestation Not Supported and sometimes it disappears altogether in Device Security menu, as if there's no TPM present. This random malfunction causes random stutters while gaming 720p low graphic games.

    Tried solutions that did not work:
    Cleared TPM multiple times from tpm.msc as well as TPM troubleshooting in device desurity as well as bios. All attempts failed to resolve the issue. Aditionally, I reset bios settings, it did not solve the issue.

    My advice: people stay clear from making the mistake of buying AMD and Asus Products as well as Windows 11. I have a decade old Haswell i7 4790 PC on a Midrange Gigabyte Motherboard, it works flawlessly. AMD is very fast, but it fails where it truly matters. AMD is unstable like an experimental product that should never be marketed en masse.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.