0x80090030

NTE_DEVICE_NOT_READY: TPM not ready for use

Last reviewed 2026-07-18 by the Just Software engineering team · also seen as 80090030, NTE_DEVICE_NOT_READY

What it means

0x80090030 is NTE_DEVICE_NOT_READY"The device that is required by this cryptographic provider is not ready for use." For Intune SCEP profiles that target the TPM key storage provider, this means the TPM itself is disabled, not initialised, or otherwise unusable at the moment of key generation.

Common causes

  1. TPM is disabled in UEFI/BIOS or has been cleared and not re-initialised.

  2. TPM is in lockout after too many failed authorisation attempts.

  3. TPM firmware bug — several vendors have shipped firmware updates specifically for stuck 'not ready' states.

  4. Virtual machines without a vTPM receiving a TPM-required SCEP profile.

How to fix it

  1. Run tpm.msc (or Get-Tpm) on the device: it should report ready for use. If not, the actions pane in tpm.msc offers Prepare the TPM / Clear TPM (suspend BitLocker before clearing).

  2. Check UEFI settings: TPM/security chip enabled, and on Intel platforms PTT enabled if there is no discrete TPM.

  3. Apply vendor TPM firmware updates — check the model's support page for TPM advisories.

  4. For VMs, either add a vTPM to the VM configuration or assign a profile that allows the software KSP.

An unhandled error has occurred. Reload 🗙