TPM attestation failed

TPM key attestation failed during SCEP enrolment

Last reviewed 2026-07-18 by the Just Software engineering team · also seen as key attestation failed, tpm attestation scep

What it means

Intune SCEP profiles can require not just that the key lives in the TPM, but that the device proves it via key attestation. When the profile is set to enforce attestation and the device cannot produce an attestation the service accepts, enrolment fails even though the TPM itself may work fine for ordinary key storage.

Common causes

  1. The TPM cannot support key attestation — common with older TPM parts and certain firmware TPM implementations.

  2. The TPM lacks a usable endorsement key (EK) certificate, or the device cannot retrieve one from the vendor.

  3. TPM firmware bugs — attestation is the most demanding TPM feature and the first to break on buggy firmware.

  4. Virtual machines: vTPM attestation support varies by hypervisor and configuration.

How to fix it

  1. Confirm the requirement is intentional: in the SCEP profile, key storage provider set to require TPM with attestation fails hardware that plain TPM enrolment would pass.

  2. Update TPM firmware via the device vendor's tooling; several vendors document attestation-specific fixes.

  3. Inventory failing hardware models — if a model consistently fails, assign it a profile without the attestation requirement rather than fighting the hardware.

  4. Check tpm.msc for TPM version and readiness; TPM 2.0 with current firmware is the practical baseline for attestation.

An unhandled error has occurred. Reload 🗙