Hi M M,
Thank you for providing such detailed information and diagnostic results. Based on what you've shared, Windows Hello is successfully completing user verification, but the WebAuthn registration process is returning an attestation format of "none", which your application's security policy does not accept.
The AIK enrollment errors you identified (including TPM_E_KEY_NOT_LOADED, 0x8029040f, and STATUS_ACCESS_DENIED) are particularly relevant because AIK certificates are commonly associated with TPM-backed attestation scenarios.
At this stage, the most appropriate next step would be to gather an official clarification from Microsoft regarding:
- Whether the HP OmniBook X Flip 16 and its TPM configuration support the type of hardware attestation your application requires.
- Whether the observed AIK enrollment failures are expected or indicate a configuration issue.
- Whether there is a supported method to restore TPM attestation functionality without affecting existing Windows Hello credentials or passkeys.
Additionally, you can consider contacting Microsoft Support for further investigation.
Please note that this is a user-to-user support forum. Moderators, contributors including external Microsoft employees cannot directly intervene in Microsoft product features or access back-end systems. Our role is limited to providing technical guidance on reported issues, requests, or ideas.
Given your requirement to preserve the existing Windows Hello configuration, passkeys, and encryption keys, I would recommend avoiding disruptive actions such as clearing the TPM, resetting Windows Hello, or removing credentials unless their impact is fully understood and a confirmed remediation path is available.