Windows Hello hardware attestation

M M 0 Reputation points
2026-10-01T17:01:28.5066667+00:00

I need help diagnosing Windows Hello hardware attestation without resetting or compromising my existing Windows profile or credentials.

Environment:

  • HP OmniBook X Flip Laptop 16-as0xxx
  • Windows 11 Home 25H2, build 26200.9457
  • Intel TPM 2.0, firmware 700.20.1005.1628

Problem: During passkey registration for a local HTTPS application, I explicitly select Windows Hello. Windows completes the user-verification interaction, but registration fails in both Edge and Chrome.

The application requests direct WebAuthn attestation and requires user verification. Windows WebAuthN diagnostics show MicrosoftPlatformProvider returning attestation format "none". The application's current security policy rejects that response.

Server error:

"AttestationVerifier is not configured to handle the supplied AttestationStatement format 'none'."

Diagnostic findings:

  • Windows reports the TPM ready for storage and attestation.
  • The endorsement key is present, with one manufacturer certificate.
  • CertificateServicesClient-CertEnroll event 87 repeatedly reports: TPM_E_KEY_NOT_LOADED / 0x8029040f at _CreateAikClaim.
  • AikCertEnrollTask reports the same error code.
  • certutil.exe -user -pulse AIKEnroll returned: 0xd0000022 / 0xc0000022 STATUS_ACCESS_DENIED in both standard and administrator PowerShell attempts.
  • Windows Hello and key-isolation services are running.

Please:

  1. Determine whether this Windows/device combination supports the requested attestation, or whether a documented limitation applies.
  2. Identify the cause of the AIK enrollment errors and the access denial.
  3. Provide a supported remedy preserving my Windows profile, Hello PIN/biometrics, existing passkeys and encryption key material.

Please explain the effects before proposing TPM clearing, PIN reset, key deletion or other credential-affecting changes. I do not want to weaken the application's authentication policy to bypass the failure.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Oldest
  1. Hendrix-V 19,470 Reputation points Microsoft External Staff Moderator
    2026-10-02T04:40:47.3933333+00:00

    Hi M M,

    Thank you for providing such detailed information and diagnostic results. Based on what you've shared, Windows Hello is successfully completing user verification, but the WebAuthn registration process is returning an attestation format of "none", which your application's security policy does not accept.

    The AIK enrollment errors you identified (including TPM_E_KEY_NOT_LOADED, 0x8029040f, and STATUS_ACCESS_DENIED) are particularly relevant because AIK certificates are commonly associated with TPM-backed attestation scenarios.

    At this stage, the most appropriate next step would be to gather an official clarification from Microsoft regarding:

    • Whether the HP OmniBook X Flip 16 and its TPM configuration support the type of hardware attestation your application requires.
    • Whether the observed AIK enrollment failures are expected or indicate a configuration issue.
    • Whether there is a supported method to restore TPM attestation functionality without affecting existing Windows Hello credentials or passkeys.

    Additionally, you can consider contacting Microsoft Support for further investigation.

    Please note that this is a user-to-user support forum. Moderators, contributors including external Microsoft employees cannot directly intervene in Microsoft product features or access back-end systems. Our role is limited to providing technical guidance on reported issues, requests, or ideas.

    Given your requirement to preserve the existing Windows Hello configuration, passkeys, and encryption keys, I would recommend avoiding disruptive actions such as clearing the TPM, resetting Windows Hello, or removing credentials unless their impact is fully understood and a confirmed remediation path is available.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.