Registering devices with Intune for management and policy enforcement
AIK enrollment HTTP 400 – Intel PTT EK certificate rejected by Azure AIK service
Hello,
Windows TPM AIK certificate enrollment fails server-side on my PC. The TPM reports Ready For Attestation: True, and Secure Boot is enabled in UEFI mode with standard keys.
Error (Event 87, CertificateServicesClient-CertEnroll), repeated 56 times, most recently 7 Oct 2026 01:59:
SCEP enrollment via https://INTC-KeyId-34219b21f477f6c7f78a0f26b23d0430deea4363.microsoftaik.azure.net/templates/Aik/scep failed with HTTP 400 / 0x80190190:
"No valid TPM EK/Platform certificate provided in the TPM identity request message."
TPM: Intel PTT, firmware 600.18.1040.2765, Vendor ID ADL
EK certificate issuer: CN=CSME ADL PTT 01SVN
Serial: 74C04011F3A8221713D6C0C5D6B198B3
Thumbprint: 1E8135A54AF8EE97800C26AF7F7721E9FFA62A9D
AdditionalCertificates: {} (empty)
Windows 11 build 26200.9550, ASUS PRIME Z790-P WIFI, BIOS 1836, i9-14900KF
I ran AikCertEnrollTask as SYSTEM through schtasks, with the same result.
Please route this to the TPM attestation / Azure AIK service team and confirm:
- Is the Intel issuing CA for this EK chain present in the AIK service trust pool?
- Is this a known issue for this KeyId, and is a fix planned?
This is blocking Call of Duty Secure Attestation. Logs and TPM information are attached.
Thank you,
Faisal Abdullah