Hello,
I am experiencing a persistent Secure Attestation failure in Call of Duty/RICOCHET on a system using Microsoft Pluton.
The system passes the local TPM and Secure Boot checks, and Windows explicitly reports that the TPM is capable of attestation. However, AIK enrollment fails when contacting the Microsoft AIK service.
System / TPM information:
- TPM: Microsoft Pluton
Pluton.TPM.A
- TPM specification: 2.0
- TPM manufacturer: Microsoft (
MSFT)
- TPM firmware:
6.4.1.400
- TPM specification revision:
1.38
- BIOS: American Megatrends International, LLC.
- BIOS version:
N.1.40STD02
- BIOS date: May 9, 2026
- Secure Boot: Enabled
- BitLocker PCR7 binding: Bound
Windows tpmtool getdeviceinformation reports:
TPM present: True
Initialized: True
Ready for storage: True
Ready for attestation: True
Is capable of attestation: True
TPM needs clearing for recovery: False
BitLocker PCR7 binding: Bound
Windows therefore considers the Pluton TPM fully capable of attestation.
However, AIK enrollment fails at the Microsoft AIK service.
The relevant output is:
MSFT-KeyId-<PII removed>
https://MSFT-KeyId-<PII removed>.microsoftaik.azure.net/templates/Aik/scep
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"msft-keyid-<PII removed>.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
The request returns:
0x80190194
HTTP_E_STATUS_NOT_FOUND
EnrollStage = 140
Microsoft also returns the following request ID:
x-ms-request-id:
<PII removed>
The failure occurs at GetCACaps, before CreateRequest or SubmitRequest:
GetCACaps = 297ms
CreateRequest = 0ms
SubmitRequest = 0ms
The Call of Duty Secure Attestation Wizard correspondingly reports that a new authorization key could not be generated and that attestation failed, while TPM 2.0 and Secure Boot themselves pass.
I have not cleared the TPM, since the TPM is already reporting that it is fully initialized and capable of attestation.
Could you please investigate whether the following Pluton KeyId is correctly provisioned in the Microsoft AIK/attestation infrastructure?
MSFT-KeyId-<PII removed>
In particular, please check why the corresponding microsoftaik.azure.net authority returns:
404 – The authority does not exist
This appears to prevent the AIK/attestation key from being generated even though the local TPM and Secure Boot requirements are satisfied.
Please also let me know whether this is a known Microsoft Pluton AIK provisioning/attestation issue and whether a firmware update is actually required for this specific KeyId.
Thank you.