Registering devices with Intune for management and policy enforcement
Azure AIK trust pool
Same failure on another platform.
Device: MSI Katana 17 HX, BIOS E17L7IMS.108.
TPM: Intel PTT 2.0, manufacturer version 600.18.1042.2872, spec 1.38.
EK issuer: CN=CSME ADL PTT 01SVN (NotBefore 23/06/2021, NotAfter 01/01/2050).
EK cert is present locally (certutil -tpminfo succeeds).
Windows reports the TPM ready for attestation and not vulnerable.
Latest BIOS, Intel ME firmware update, TPM clear, and installation of the public OnDie CA CSME intermediate did not help.
Call of Duty Secure Attestation Wizard fails on new attestation key generation and recommends a BIOS update.
Please add CN=CSME ADL PTT 01SVN to the Azure AIK trust pool, or confirm a timeline.