Intel Alder Lake PTT AIK Enrollment Failure – HTTP 400 (0x80190190) Blocking RICOCHET Secure Attestation

Lucas Kimura 5 Reputation points
2026-10-03T01:54:22.3233333+00:00

Hello,

I am experiencing a reproducible TPM/AIK attestation problem on Windows 11 using Intel Alder Lake Platform Trust Technology (PTT).

The main symptom is that Windows is unable to complete AIK certificate enrollment. As a result, Call of Duty RICOCHET Secure Attestation fails, even though TPM 2.0 and Secure Boot both pass their local checks.

I would like to provide the complete diagnostic information because I have already performed extensive client-side troubleshooting and the failure consistently occurs at the same stage of the Microsoft AIK enrollment process.

========================

SYSTEM INFORMATION

========================

Motherboard:

MSI B760M GAMING PLUS WIFI (MS-7D99)

CPU:

Intel Core i7-12700KF

12th Gen Intel Core / Alder Lake

Operating System:

Windows 11 Pro

OS Build:

26200

BIOS:

American Megatrends International, LLC. H.A0

BIOS date: 24/08/2026

MSI BIOS package: 7D99vHA

Intel Management Engine:

16.1.42.2872

TPM:

Intel PTT

TPM 2.0

TPM Manufacturer:

INTC

TPM Model:

ADL

TPM firmware:

600.18.1042.2872

========================

TPM HEALTH STATUS

========================

Windows reports the TPM as healthy:

TpmPresent: True

TpmReady: True

TpmEnabled: True

TpmActivated: True

TpmOwned: True

LockedOut: False

LockoutCount: 0

TPM attestation capability:

Ready for Attestation: True

Capable for Attestation: True

The TPM is not reporting vulnerable firmware.

tpmtool getdeviceinformation reports:

TPM Present: True

TPM Version: 2.0

Manufacturer: Intel

VendorId: ADL

Initialized: True

Ready for Storage: True

Ready for Attestation: True

Capable for Attestation: True

Clear Required: False

Clear Possible: True

Maintenance Task Complete: True

TPM Vulnerable Firmware: False

========================

SECURE BOOT

========================

Secure Boot is enabled.

PowerShell:

Confirm-SecureBootUEFI

returns:

True

The system is running in UEFI mode.

The Microsoft 2023 Secure Boot certificate/key update events are also present in the Windows event logs.

========================

TPM EK CERTIFICATE

========================

The TPM Endorsement Key certificate is present.

Get-TpmEndorsementKeyInfo -HashAlgorithm SHA256 reports:

IsPresent: True

EK public key hash:

84f602303cfa855deea37748055e3554cffd3a159bb7778a686224ad6211d70c

EK certificate:

Subject:

TPMVersion=id:02580012, TPMModel=ADL, TPMManufacturer=id:494E5443

Issuer:

CN=CSME ADL PTT 01SVN

The EK certificate is valid until 2049.

The Intel PTT certificate chain stored/provided by the TPM contains the following hierarchy:

TPM EK

↓

CSME ADL PTT 01SVN

↓

CSME ADL SVN01 Kernel CA

↓

CSME ADL ROM CA

↓

ODCA 2 CSME P_ADL 00002226 Issuing CA

↓

ODCA CA2 CSME Intermediate CA

↓

Intel OnDie CA Root

The relevant Intel issuing CA is:

CN=www.intel.com,

OU=ODCA 2 CSME P_ADL 00002226 Issuing CA

Its Subject Key Identifier is:

34219b21f477f6c7f78a0f26b23d0430deea4363

========================

MICROSOFT AIK ENROLLMENT

========================

Windows attempts to enroll an AIK through the Microsoft AIK/SCEP service.

The enrollment reaches the Microsoft service successfully.

The process gets through:

GetCACert

GetCACaps

CreateRequest

but consistently fails at:

SubmitRequest

The server responds:

HTTP/1.1 400 Bad Request

Response:

{

"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."

}

Windows reports:

0x80190190

HTTP_E_STATUS_BAD_REQUEST

The Windows scheduled task:

\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask

also consistently fails with:

2149122448

which corresponds to:

0x80190190

========================

AIK ENDPOINT

========================

The AIK authority generated for this TPM is:

INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363

The endpoint is:

https://INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363.microsoftaik.azure.net/templates/Aik/scep

========================

LATEST FAILURE

========================

The latest attempt was performed manually by starting:

AikCertEnrollTask

The corresponding CertificateServicesClient-CertEnroll Event ID 87 occurred at:

02/10/2026 22:53:38

The server response was:

SubmitDone

Submit(Request): Bad Request

{"Message":"No valid TPM EK/Platform certificate provided in the TPM identity request message."}

HTTP/1.1 400 Bad Request

The latest Microsoft request ID is:

x-ms-request-id:

0ee57ca8-6f49-4870-acf3-a2f088317586

The request took approximately 2610 ms.

========================

REPEATED FAILURES

========================

This is not a one-time failure.

Multiple attempts on the same system produce exactly the same HTTP 400 response.

Examples:

02/10/2026 22:53:38

x-ms-request-id:

0ee57ca8-6f49-4870-acf3-a2f088317586

02/10/2026 22:35:37

x-ms-request-id:

e9e82a64-f062-45f2-a529-7bb4bd1f114e

02/10/2026 22:23:33

x-ms-request-id:

b59e0e7e-7669-439b-9970-a45abcbe217f

All return:

HTTP 400

"No valid TPM EK/Platform certificate provided in the TPM identity request message."

========================

WINDOWS TPM ATTESTATION

========================

Windows TPM-WMI health checks report the TPM as attestable.

The health data includes:

HealthStatus: Attestable

Required checks include:

TpmPresent: True

TpmMeetsMinimumVersion: True

TpmIsResponsive: True

EkCertIsAvailable: True

TcgLogFound: True

PcrsMatchTcgLog: True

SecureBootEnabled is also reported as True.

Windows therefore considers the TPM locally capable of attestation.

The failure appears specifically during AIK certificate enrollment.

========================

CERTIFICATE CHAIN INVESTIGATION

========================

I also investigated the Intel EK certificate chain locally.

The TPM contains Intel intermediate certificates under:

HKLM:\SYSTEM\CurrentControlSet\Services\TPM\WMI\Endorsement\IntermediateCACertStore\Certificates

The certificates correspond to:

CSME ADL ROM CA

CSME ADL SVN01 Kernel CA

CSME ADL PTT 01SVN

I also retrieved the upper Intel certificates referenced by the chain from Intel's official tsci.intel.com certificate repository:

ODCA 2 CSME P_ADL 00002226 Issuing CA

ODCA CA2 CSME Intermediate CA

OnDie CA Root

The certificate Subject/Issuer relationships and Authority Key Identifiers match throughout the hierarchy.

The EK itself is issued by:

CN=CSME ADL PTT 01SVN

which chains through the Intel CSME/ODCA hierarchy above.

========================

OTHER WINDOWS DIAGNOSTICS

========================

Windows TPM-WMI Event ID 1038 reports that pre-attestation health checks confirm the device should pass attestation.

TPM-WMI Event ID 1041 reports:

HealthStatus: Attestable

Event ID 1025 confirms that the TPM was provisioned successfully and is ready.

CAPI2 certificate validation logs were also investigated. They do not show a general Windows certificate validation failure; the Microsoft certificate chain validations observed there complete successfully.

The system is not using a WinHTTP proxy.

Windows Update is functioning normally.

========================

BIOS / FIRMWARE

========================

The motherboard BIOS has already been updated to the current MSI release.

Intel ME firmware is also current:

16.1.42.2872

The TPM firmware currently reports:

600.18.1042.2872

Therefore, this does not appear to be simply an outdated BIOS or Intel ME firmware issue.

========================

CALL OF DUTY IMPACT

========================

This AIK enrollment failure directly affects Call of Duty RICOCHET Secure Attestation.

The Call of Duty Secure Attestation diagnostic reports:

TPM 2.0: PASS

Secure Boot: PASS

However:

Attestation Requisite: NOT MET

Attempting to generate a new attestation key results in:

"New Key Failed to be generated - BIOS Firmware Update Recommended"

and:

"Your PC does not meet security requirements."

This occurs even though the BIOS/ME firmware is updated and Windows reports the TPM as capable and ready for attestation.

========================

WHAT I AM ASKING MICROSOFT TO INVESTIGATE

========================

Could you please investigate this at the Microsoft AIK/TPM attestation service level?

Specifically, I would like to know why the Microsoft AIK/SCEP service is rejecting the TPM identity request with:

"No valid TPM EK/Platform certificate provided in the TPM identity request message."

The TPM EK certificate is present, the TPM is healthy and capable of attestation, Secure Boot is enabled, and the request successfully reaches the Microsoft AIK service.

Could you please use the following request ID to inspect the server-side request?

x-ms-request-id:

0ee57ca8-6f49-4870-acf3-a2f088317586

The main question is whether the Microsoft AIK service is able to validate and accept the Intel Alder Lake PTT EK/Platform certificate chain associated with:

INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363

and:

ODCA 2 CSME P_ADL 00002226 Issuing CA

If the chain is supported and trusted by the Microsoft AIK service, please identify what specific part of the TPM identity request is being rejected.

If the Intel ADL EK/Platform certificate chain is not currently recognized by the AIK service, please confirm whether this is a Microsoft-side trust/provisioning issue and whether it has already been reported or is being addressed.

I am specifically trying to determine whether this is:

  1. A local TPM/EK certificate problem,
  2. An Intel firmware/certificate-chain compatibility issue, or
  3. A Microsoft AIK service-side trust/validation issue.

I would prefer not to repeatedly clear the TPM, reinstall Windows, or make further BIOS/Secure Boot changes unless there is evidence that one of those actions would address this specific SubmitRequest/HTTP 400 failure.

I can provide additional Event Viewer logs, TPM information, certificate dumps, AIK enrollment logs, or any other diagnostics required.

Thank you.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. Carl-L 22,915 Reputation points Microsoft External Staff Moderator
    2026-10-03T10:13:25.2933333+00:00

    Hello Lucas Kimura,

    Welcome to Microsoft Q&A forum.

    You're not alone in this. I've seen multiple users with the same AIK issue, and as I checked with some of them, this seems like a server-side issue, which us users cannot do anything with it. The issue has been reported to the Windows engineering team in the Feedback Hub, you can find some of the entries there and also share your feedback. Judged by what I see here, I believe that the issue might need more than one side to resolve.

    Thank you for your understanding.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.