Hello,
I am experiencing a reproducible TPM/AIK attestation problem on Windows 11 using Intel Alder Lake Platform Trust Technology (PTT).
The main symptom is that Windows is unable to complete AIK certificate enrollment. As a result, Call of Duty RICOCHET Secure Attestation fails, even though TPM 2.0 and Secure Boot both pass their local checks.
I would like to provide the complete diagnostic information because I have already performed extensive client-side troubleshooting and the failure consistently occurs at the same stage of the Microsoft AIK enrollment process.
========================
SYSTEM INFORMATION
========================
Motherboard:
MSI B760M GAMING PLUS WIFI (MS-7D99)
CPU:
Intel Core i7-12700KF
12th Gen Intel Core / Alder Lake
Operating System:
Windows 11 Pro
OS Build:
26200
BIOS:
American Megatrends International, LLC. H.A0
BIOS date: 24/08/2026
MSI BIOS package: 7D99vHA
Intel Management Engine:
16.1.42.2872
TPM:
Intel PTT
TPM 2.0
TPM Manufacturer:
INTC
TPM Model:
ADL
TPM firmware:
600.18.1042.2872
========================
TPM HEALTH STATUS
========================
Windows reports the TPM as healthy:
TpmPresent: True
TpmReady: True
TpmEnabled: True
TpmActivated: True
TpmOwned: True
LockedOut: False
LockoutCount: 0
TPM attestation capability:
Ready for Attestation: True
Capable for Attestation: True
The TPM is not reporting vulnerable firmware.
tpmtool getdeviceinformation reports:
TPM Present: True
TPM Version: 2.0
Manufacturer: Intel
VendorId: ADL
Initialized: True
Ready for Storage: True
Ready for Attestation: True
Capable for Attestation: True
Clear Required: False
Clear Possible: True
Maintenance Task Complete: True
TPM Vulnerable Firmware: False
========================
SECURE BOOT
========================
Secure Boot is enabled.
PowerShell:
Confirm-SecureBootUEFI
returns:
True
The system is running in UEFI mode.
The Microsoft 2023 Secure Boot certificate/key update events are also present in the Windows event logs.
========================
TPM EK CERTIFICATE
========================
The TPM Endorsement Key certificate is present.
Get-TpmEndorsementKeyInfo -HashAlgorithm SHA256 reports:
IsPresent: True
EK public key hash:
84f602303cfa855deea37748055e3554cffd3a159bb7778a686224ad6211d70c
EK certificate:
Subject:
TPMVersion=id:02580012, TPMModel=ADL, TPMManufacturer=id:494E5443
Issuer:
CN=CSME ADL PTT 01SVN
The EK certificate is valid until 2049.
The Intel PTT certificate chain stored/provided by the TPM contains the following hierarchy:
TPM EK
↓
CSME ADL PTT 01SVN
↓
CSME ADL SVN01 Kernel CA
↓
CSME ADL ROM CA
↓
ODCA 2 CSME P_ADL 00002226 Issuing CA
↓
ODCA CA2 CSME Intermediate CA
↓
Intel OnDie CA Root
The relevant Intel issuing CA is:
CN=www.intel.com,
OU=ODCA 2 CSME P_ADL 00002226 Issuing CA
Its Subject Key Identifier is:
34219b21f477f6c7f78a0f26b23d0430deea4363
========================
MICROSOFT AIK ENROLLMENT
========================
Windows attempts to enroll an AIK through the Microsoft AIK/SCEP service.
The enrollment reaches the Microsoft service successfully.
The process gets through:
GetCACert
GetCACaps
CreateRequest
but consistently fails at:
SubmitRequest
The server responds:
HTTP/1.1 400 Bad Request
Response:
{
"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."
}
Windows reports:
0x80190190
HTTP_E_STATUS_BAD_REQUEST
The Windows scheduled task:
\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
also consistently fails with:
2149122448
which corresponds to:
0x80190190
========================
AIK ENDPOINT
========================
The AIK authority generated for this TPM is:
INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363
The endpoint is:
https://INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363.microsoftaik.azure.net/templates/Aik/scep
========================
LATEST FAILURE
========================
The latest attempt was performed manually by starting:
AikCertEnrollTask
The corresponding CertificateServicesClient-CertEnroll Event ID 87 occurred at:
02/10/2026 22:53:38
The server response was:
SubmitDone
Submit(Request): Bad Request
{"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."}
HTTP/1.1 400 Bad Request
The latest Microsoft request ID is:
x-ms-request-id:
0ee57ca8-6f49-4870-acf3-a2f088317586
The request took approximately 2610 ms.
========================
REPEATED FAILURES
========================
This is not a one-time failure.
Multiple attempts on the same system produce exactly the same HTTP 400 response.
Examples:
02/10/2026 22:53:38
x-ms-request-id:
0ee57ca8-6f49-4870-acf3-a2f088317586
02/10/2026 22:35:37
x-ms-request-id:
e9e82a64-f062-45f2-a529-7bb4bd1f114e
02/10/2026 22:23:33
x-ms-request-id:
b59e0e7e-7669-439b-9970-a45abcbe217f
All return:
HTTP 400
"No valid TPM EK/Platform certificate provided in the TPM identity request message."
========================
WINDOWS TPM ATTESTATION
========================
Windows TPM-WMI health checks report the TPM as attestable.
The health data includes:
HealthStatus: Attestable
Required checks include:
TpmPresent: True
TpmMeetsMinimumVersion: True
TpmIsResponsive: True
EkCertIsAvailable: True
TcgLogFound: True
PcrsMatchTcgLog: True
SecureBootEnabled is also reported as True.
Windows therefore considers the TPM locally capable of attestation.
The failure appears specifically during AIK certificate enrollment.
========================
CERTIFICATE CHAIN INVESTIGATION
========================
I also investigated the Intel EK certificate chain locally.
The TPM contains Intel intermediate certificates under:
HKLM:\SYSTEM\CurrentControlSet\Services\TPM\WMI\Endorsement\IntermediateCACertStore\Certificates
The certificates correspond to:
CSME ADL ROM CA
CSME ADL SVN01 Kernel CA
CSME ADL PTT 01SVN
I also retrieved the upper Intel certificates referenced by the chain from Intel's official tsci.intel.com certificate repository:
ODCA 2 CSME P_ADL 00002226 Issuing CA
ODCA CA2 CSME Intermediate CA
OnDie CA Root
The certificate Subject/Issuer relationships and Authority Key Identifiers match throughout the hierarchy.
The EK itself is issued by:
CN=CSME ADL PTT 01SVN
which chains through the Intel CSME/ODCA hierarchy above.
========================
OTHER WINDOWS DIAGNOSTICS
========================
Windows TPM-WMI Event ID 1038 reports that pre-attestation health checks confirm the device should pass attestation.
TPM-WMI Event ID 1041 reports:
HealthStatus: Attestable
Event ID 1025 confirms that the TPM was provisioned successfully and is ready.
CAPI2 certificate validation logs were also investigated. They do not show a general Windows certificate validation failure; the Microsoft certificate chain validations observed there complete successfully.
The system is not using a WinHTTP proxy.
Windows Update is functioning normally.
========================
BIOS / FIRMWARE
========================
The motherboard BIOS has already been updated to the current MSI release.
Intel ME firmware is also current:
16.1.42.2872
The TPM firmware currently reports:
600.18.1042.2872
Therefore, this does not appear to be simply an outdated BIOS or Intel ME firmware issue.
========================
CALL OF DUTY IMPACT
========================
This AIK enrollment failure directly affects Call of Duty RICOCHET Secure Attestation.
The Call of Duty Secure Attestation diagnostic reports:
TPM 2.0: PASS
Secure Boot: PASS
However:
Attestation Requisite: NOT MET
Attempting to generate a new attestation key results in:
"New Key Failed to be generated - BIOS Firmware Update Recommended"
and:
"Your PC does not meet security requirements."
This occurs even though the BIOS/ME firmware is updated and Windows reports the TPM as capable and ready for attestation.
========================
WHAT I AM ASKING MICROSOFT TO INVESTIGATE
========================
Could you please investigate this at the Microsoft AIK/TPM attestation service level?
Specifically, I would like to know why the Microsoft AIK/SCEP service is rejecting the TPM identity request with:
"No valid TPM EK/Platform certificate provided in the TPM identity request message."
The TPM EK certificate is present, the TPM is healthy and capable of attestation, Secure Boot is enabled, and the request successfully reaches the Microsoft AIK service.
Could you please use the following request ID to inspect the server-side request?
x-ms-request-id:
0ee57ca8-6f49-4870-acf3-a2f088317586
The main question is whether the Microsoft AIK service is able to validate and accept the Intel Alder Lake PTT EK/Platform certificate chain associated with:
INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363
and:
ODCA 2 CSME P_ADL 00002226 Issuing CA
If the chain is supported and trusted by the Microsoft AIK service, please identify what specific part of the TPM identity request is being rejected.
If the Intel ADL EK/Platform certificate chain is not currently recognized by the AIK service, please confirm whether this is a Microsoft-side trust/provisioning issue and whether it has already been reported or is being addressed.
I am specifically trying to determine whether this is:
- A local TPM/EK certificate problem,
- An Intel firmware/certificate-chain compatibility issue, or
- A Microsoft AIK service-side trust/validation issue.
I would prefer not to repeatedly clear the TPM, reinstall Windows, or make further BIOS/Secure Boot changes unless there is evidence that one of those actions would address this specific SubmitRequest/HTTP 400 failure.
I can provide additional Event Viewer logs, TPM information, certificate dumps, AIK enrollment logs, or any other diagnostics required.
Thank you.