Windows TPM AIK certificate enrollment fails against microsoftaik.azure.net with HTTP 400 / 0x80190190. The TPM EK is present, locally validated, and issued by the Intel ODCA 2 CSME MTP PCH SVN 01 PTT CA. The AIK service rejects the TPM identity with “No

CYB3R TR0N 0 Reputation points
2026-10-05T16:24:59.73+00:00

Windows TPM AIK certificate enrollment fails against microsoftaik.azure.net with HTTP 400 / 0x80190190. The TPM EK is present, locally validated, and issued by the Intel ODCA 2 CSME MTP PCH SVN 01 PTT CA. The AIK service rejects the TPM identity with “No valid TPM EK/Platform certificate provided in the TPM identity request message.”

TPM manufacturer: Intel / INTC

TPM model: MTP

TPM version: 2.0

TPM firmware: 700.19.1011.2289

TPM revision: 1.59

TPM platform identifier: 02BC0013

EK issuer:

ODCA 2 CSME MTP PCH SVN 01 PTT CA

AIK Key ID:

77b63d9f8b73f5fbbd73ace7d8fbda37a6a7865f

AIK enrollment:

TpmDiagnostics.exe EnrollWindowsAIKCert

Result:

0x80190190 / HTTP 400

Server response:

"No valid TPM EK/Platform certificate provided in the TPM identity request message."

I have verified the Intel EK chain locally.

That should prevent first-line support from sending you through the standard:

“Enable TPM / enable Secure Boot / update BIOS”

script.

Windows for home | Windows 11 | Security and privacy
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.