Intel PTT AIK enrollment fails with HTTP 400 – Intel ADL EK certificate rejected by Microsoft AIK service

Timur Tursunkhujaev 0 Reputation points
2026-09-26T10:20:45.2133333+00:00

Hello,

I am experiencing a reproducible Windows 11 TPM 2.0 / AIK attestation failure on an Intel PTT system. The TPM itself is healthy and Windows reports the system as attestable, but AIK enrollment fails against the Microsoft AIK service. This prevents Call of Duty RICOCHET Secure Attestation from completing.

System configuration

  • Motherboard: MSI MAG B660M MORTAR WIFI DDR4
  • Intel PTT / firmware TPM: Enabled
  • TPM: 2.0
  • TPM manufacturer: Intel (INTC)
  • TPM model: ADL
  • BIOS: MSI 7D42v1P
  • Intel ME firmware: 16.1.42.2872
  • Windows 11 Pro 25H2
  • OS Build: 26200.9550
  • UEFI: Enabled
  • Secure Boot: Enabled

Windows Get-Tpm reports:

  • TpmPresent: True
  • TpmReady: True
  • TpmEnabled: True
  • TpmActivated: True
  • TpmOwned: True

Windows TPM-WMI attestation diagnostics report the device as Attestable.

The latest Call of Duty Secure Attestation Wizard diagnostic file shows that the AIK enrollment process reaches:

GetCACert

GetCACaps

CreateRequest

and then fails at:

SubmitRequest

with:

HTTP/1.1 400 Bad Request

{"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."}

The diagnostic reports:

EnrollStage = 220

The TPM EK certificate issuer is:

CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002701 Issuing CA

The generated Microsoft AIK authority is based on:

INTC-KeyId-7a543ff6ca11d099679c36a611f261efc15d52092

The corresponding endpoint is:

https://INTC-KeyId-7a543ff6ca11d099679c36a611f261efc15d52092.microsoftaik.azure.net/templates/Aik/scep

I also tested the exact Microsoft AIK endpoint directly over HTTPS. The service is reachable, but it has returned HTTP 404 with:

"The authority "INTC-KeyId-7a543ff6ca11d099679c36a611f261efc15d52092.microsoftaik.azure.net" does not exist."

Microsoft request ID from that test:

04ca9711-b250-4a88-b71a-68d04d366348

The RICOCHET diagnostic also contains:

x-ms-client-request-id: 58badf96-827a-4226-89d5-59e527e2610e

x-ms-request-id: 2574918c-385a-4ae5-b986-c5bfe3b1f09c

I have already updated the motherboard BIOS, Intel ME firmware and Windows to the latest available versions, and confirmed TPM 2.0 and Secure Boot functionality.

Question

Could Microsoft please confirm whether the Intel ADL PTT EK issuing CA:

ODCA 2 CSME P_ADL 00002701 Issuing CA

is currently recognized by the Microsoft AIK/attestation infrastructure?

If this issuing CA or the corresponding Intel PTT authority is not provisioned in the Microsoft AIK service, is there any supported client-side fix, or does this require Microsoft/Intel/MSI infrastructure or firmware changes?

I can provide the complete diagnostic ZIP generated by the latest Call of Duty Secure Attestation Wizard and the relevant Windows event logs if required.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. Abinesh Magudeeswaran 230 Reputation points Student Ambassador
    2026-09-27T07:23:38.2733333+00:00

    Hello Timur,

    Based on the information provided, this does not look like a basic TPM-health, Secure Boot, or Windows configuration problem.

    Your diagnostics show that:

    TPM 2.0 is present and ready.

    Intel PTT is enabled.

    Secure Boot and UEFI are enabled.

    Windows reports the TPM as capable of attestation.

    AIK enrollment reaches the Microsoft AIK service.

    The request fails specifically at SubmitRequest.

    Microsoft returns HTTP 400 with: No valid TPM EK/Platform certificate provided in the TPM identity request message.

    There are also several recent Microsoft Q&A reports involving Intel CSME/PTT and Intel ADL EK certificates with the same HTTP 400 response. One report specifically identifies an Intel ODCA 2 CSME P_ADL issuing CA and reaches the same EnrollStage = 220 / SubmitRequest failure.

    What this indicates

    The important distinction is that the TPM can be healthy locally while the Microsoft AIK service can still reject the EK certificate presented for attestation.

    Microsoft's documentation explains that Windows provisions an AIK through a Microsoft cloud service and that the AIK certificate is issued by that service. The EK/EK certificate is part of the trust relationship used during this process.

    Therefore, the HTTP 400 response does not by itself mean that your physical TPM is defective.

    About the Intel issuing CA

    I could not find a public Microsoft document confirming that:

    CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002701 Issuing CA

    is currently accepted by the Microsoft AIK service.

    That is an important distinction: the public documentation does not provide a complete public list from which we can confirm that particular Intel CA is provisioned in Microsoft's AIK infrastructure.

    The fact that your request reaches SubmitRequest and is then rejected with "No valid TPM EK/Platform certificate" is consistent with the service being unable to validate/accept the EK information supplied in the request, but the exact server-side reason cannot be determined from the client error alone.

    What I would do next

    Since you have already updated:

    motherboard BIOS,

    Intel ME firmware,

    Windows,

    TPM 2.0 configuration,

    Secure Boot,

    I would avoid repeatedly clearing the TPM or reinstalling Windows as a first response. Those actions do not establish that the Microsoft-side EK trust problem has been resolved.

    Instead, collect the following information for Microsoft support:

    TPM manufacturer: INTC
    TPM model: ADL
    EK issuer:
    CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002701 Issuing CA
    
    AIK authority:
    INTC-KeyId-7a543ff6ca11d099679c36a611f261efc15d52092
    
    HTTP status:
    400 Bad Request
    
    Response:
    No valid TPM EK/Platform certificate provided in the TPM identity request message.
    
    EnrollStage:
    220
    
    x-ms-client-request-id:
    58badf96-827a-4226-89d5-59e527e2610e
    
    x-ms-request-id:
    2574918c-385a-4ae5-b986-c5bfe3b1f09c
    

    Ask Microsoft specifically to determine whether the Intel ADL EK issuing CA and the corresponding INTC-KeyId-* authority are currently recognized by the Microsoft AIK/attestation service.

    If the service-side trust/provisioning is the problem, that is not something a normal Windows client repair, SFC/DISM operation, TPM reset, or Secure Boot change can independently fix. Similar Intel PTT reports have been escalated around this same class of AIK-service rejection.

    Also, the 404 result you obtained for the derived microsoftaik.azure.net authority is useful diagnostic evidence, but I would not independently interpret it as proof that the CA is missing. The authority naming and service behavior need to be confirmed by the Microsoft AIK/attestation team.

    So the most appropriate question for Microsoft support is:

    Can Microsoft confirm whether the Intel ADL PTT EK chain issued by ODCA 2 CSME P_ADL 00002701 Issuing CA and authority INTC-KeyId-7a543ff6... is currently provisioned and trusted by the Microsoft AIK service?

    That should allow the issue to be separated cleanly into either a client/firmware EK problem or a Microsoft AIK-service trust/provisioning problem, without unnecessarily resetting a healthy TPM.Hello Timur,

    Based on the information provided, this does not look like a basic TPM-health, Secure Boot, or Windows configuration problem.

    Your diagnostics show that:

    TPM 2.0 is present and ready.

    Intel PTT is enabled.

    Secure Boot and UEFI are enabled.

    Windows reports the TPM as capable of attestation.

    AIK enrollment reaches the Microsoft AIK service.

    The request fails specifically at SubmitRequest.

    Microsoft returns HTTP 400 with:
    No valid TPM EK/Platform certificate provided in the TPM identity request message.

    There are also several recent Microsoft Q&A reports involving Intel CSME/PTT and Intel ADL EK certificates with the same HTTP 400 response. One report specifically identifies an Intel ODCA 2 CSME P_ADL issuing CA and reaches the same EnrollStage = 220 / SubmitRequest failure.

    What this indicates

    The important distinction is that the TPM can be healthy locally while the Microsoft AIK service can still reject the EK certificate presented for attestation.

    Microsoft's documentation explains that Windows provisions an AIK through a Microsoft cloud service and that the AIK certificate is issued by that service. The EK/EK certificate is part of the trust relationship used during this process.

    Therefore, the HTTP 400 response does not by itself mean that your physical TPM is defective.

    About the Intel issuing CA

    I could not find a public Microsoft document confirming that:

    CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002701 Issuing CA

    is currently accepted by the Microsoft AIK service.

    That is an important distinction: the public documentation does not provide a complete public list from which we can confirm that particular Intel CA is provisioned in Microsoft's AIK infrastructure.

    The fact that your request reaches SubmitRequest and is then rejected with "No valid TPM EK/Platform certificate" is consistent with the service being unable to validate/accept the EK information supplied in the request, but the exact server-side reason cannot be determined from the client error alone.

    What I would do next

    Since you have already updated:

    motherboard BIOS,

    Intel ME firmware,

    Windows,

    TPM 2.0 configuration,

    Secure Boot,

    I would avoid repeatedly clearing the TPM or reinstalling Windows as a first response. Those actions do not establish that the Microsoft-side EK trust problem has been resolved.

    Instead, collect the following information for Microsoft support:

    TPM manufacturer: INTC
    TPM model: ADL
    EK issuer:
    CN=www.intel.com, OU=ODCA 2 CSME P_ADL 00002701 Issuing CA
    
    AIK authority:
    INTC-KeyId-7a543ff6ca11d099679c36a611f261efc15d52092
    
    HTTP status:
    400 Bad Request
    
    Response:
    No valid TPM EK/Platform certificate provided in the TPM identity request message.
    
    EnrollStage:
    220
    
    x-ms-client-request-id:
    58badf96-827a-4226-89d5-59e527e2610e
    
    x-ms-request-id:
    2574918c-385a-4ae5-b986-c5bfe3b1f09c
    

    Ask Microsoft specifically to determine whether the Intel ADL EK issuing CA and the corresponding INTC-KeyId-* authority are currently recognized by the Microsoft AIK/attestation service.

    If the service-side trust/provisioning is the problem, that is not something a normal Windows client repair, SFC/DISM operation, TPM reset, or Secure Boot change can independently fix. Similar Intel PTT reports have been escalated around this same class of AIK-service rejection.

    Also, the 404 result you obtained for the derived microsoftaik.azure.net authority is useful diagnostic evidence, but I would not independently interpret it as proof that the CA is missing. The authority naming and service behavior need to be confirmed by the Microsoft AIK/attestation team.

    So the most appropriate question for Microsoft support is:

    Can Microsoft confirm whether the Intel ADL PTT EK chain issued by ODCA 2 CSME P_ADL 00002701 Issuing CA and authority INTC-KeyId-7a543ff6... is currently provisioned and trusted by the Microsoft AIK service?

    That should allow the issue to be separated cleanly into either a client/firmware EK problem or a Microsoft AIK-service trust/provisioning problem, without unnecessarily resetting a healthy TPM.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.