AIK enrollment HTTP 400 – Intel PTT EK certificate rejected by Azure AIK service

Faisal Abdullah 0 Reputation points
2026-10-06T23:24:51+00:00

Hello,

Windows TPM AIK certificate enrollment fails server-side on my PC. The TPM reports Ready For Attestation: True, and Secure Boot is enabled in UEFI mode with standard keys.

Error (Event 87, CertificateServicesClient-CertEnroll), repeated 56 times, most recently 7 Oct 2026 01:59:

SCEP enrollment via https://INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363.microsoftaik.azure.net/templates/Aik/scep failed with HTTP 400 / 0x80190190:

"No valid TPM EK/Platform certificate provided in the TPM identity request message."

TPM: Intel PTT, firmware 600.18.1040.2765, Vendor ID ADL

EK certificate issuer: CN=CSME ADL PTT 01SVN

Serial: 74C04011F3A8221713D6C0C5D6B198B3

Thumbprint: 1E8135A54AF8EE97800C26AF7F7721E9FFA62A9D

AdditionalCertificates: {} (empty)

Windows 11 build 26200.9550, ASUS PRIME Z790-P WIFI, BIOS 1836, i9-14900KF

I ran AikCertEnrollTask as SYSTEM through schtasks, with the same result.

Please route this to the TPM attestation / Azure AIK service team and confirm:

  1. Is the Intel issuing CA for this EK chain present in the AIK service trust pool?
  2. Is this a known issue for this KeyId, and is a fix planned?

This is blocking Call of Duty Secure Attestation. Logs and TPM information are attached.

Thank you,

Faisal Abdullah

Microsoft Security | Intune | Enrollment
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.