Skip to content
Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot

Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot

Written By Vidya M A
Last Updated September 20, 2022
Posted In Intune
SHARE

Intune Advisory TPM attestation error 0x81039001 with Windows Autopilot. Microsoft raised an alert (Advisory #IT431147) on the TPM Provisioning Issue with Windows Autopilot. We have seen TPM issues popping up again and again on Twitter.

Admins intermittently cannot provision Trusted Platform Module (TPM) devices via Windows Autopilot. Daniel Davila raised this issue on Twitter on 14th Sept 2022, but Microsoft confirmed that they are investigating the issue with an advisory IT431147 a few days after.

The impact is mainly for Admins because Admins won’t be able to provision TPM devices using the Windows Autopilot service. This failure occurs during the ‘Securing your hardware‘ step during Windows Autopilot pre-provisioning scenario.

Microsoft stated that it might take a few weeks to investigate and find out the latency issue with the certificate authentication. Microsoft is currently investigating the TPM attestation issues today across different tenants. You can refer to the advisory IT431147 for more details or read the below sections of this post.

Patch My PC

Update 20th Sept 8:50 AM Another Autopilot issue (IT434773). This user is not authorized to enroll. Users may be unable to perform Autopilot Enrollments within Microsoft Intune. The users may be unable to perform Autopilot Enrollments within Microsoft Intune.

Autopilot Error – This user is not authorized to enroll. You can try to do this again or contact your system administrator with error code 80180003.”

Issue: TPM Attestation Error 0x81039001 with Windows Autopilot

Let’s check the details of TPM attestation error 0x81039001 with Windows Autopilot and Intune Advisory #IT431147. First of all, Microsoft confirmed that it is an intermediate issue with the service!

Error Messages shared by Daniel on the TPM attestation error with Autopilot – HTTP/1.1 400 Bad Request and TPM attestation failed: 0x81039001. He also added that the certreq process failed during pre-provisioning but was successful during log gathering.

This failure occurs during the ‘Securing your hardware‘ step for Windows Autopilot devices deployed using self-deploying mode or pre-provisioning mode. Admins are intermittently unable to provision Trusted Platform Module (TPM) devices via Windows Autopilot.

Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot 1
Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot 1 – Thanks to Daniel Davila

Workaround | FIXTPM Attestation Error 0x81039001 with Windows Autopilot

The workaround to this issue is RETRY or Try Again, as per Microsoft Advisory. In the event provisioning fails, the recommendation from MS is to try again, as subsequent attempts to provision should be successful

A few weeks to investigate and find out the latency issue with authentication” was an interesting statement from Microsoft. Microsoft has already started investigating the issue, but it might take a long time because of the issue’s complexity!

ROOT CAUSE: Microsoft has identified that latency associated with an authentication component in the affected environment is causing Windows Autopilot to fail intermittently, resulting in intermittent pre-provisioning and self-deployment failures for TPM devices.

Microsoft is investigating to discover where this latency originates, allowing them to formulate a strategy that remediates impact. Due to the complexities of this issue, it may take a few weeks to conclude our investigation.

User ImpactCurrent StatusScope of ImpactImpacted ServiceRoot Cause
Admins are intermittently unable to provision TPM devices via Windows Autopilot.Microsoft attempts to discover where this latency originates, allowing us to formulate a strategy that remediates impact. Due to the complexities of this issue. This might take a week to complete.This event may affect your organization, and admins attempting to utilize the Windows Autopilot self-deploying or pre-provisioning modes for TPM devices may experience an impact.1. Microsoft Intune
2. Autopilot Pre-provisioning Service
3. Autopilot self-deploying
A latency associated with an authentication component
Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot – Table 1
Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot 2
Intune Advisory TPM Attestation Error 0x81039001 with Windows Autopilot 2

Author

HTMD Admin Account to provide news and latest updates on the known issue from Microsoft world. We cover Windows, Intune, Azure, AVD, and Windows 365 news.

Written by

About Author - Vidya is a computer enthusiast. She is here to share quick tips and tricks with Windows 11 or Windows 10 users. She is also keen to find solutions to day-to-day tech problems and write about them.

Discussion · 6 comments

  1. How can I see the incident in service health? Having a global admin account and cannot see the incident. If I am using a url to this incident, I am getting a blade message „I do not have permissions“
    Is there something I need to add to my account?

  2. Thank you very much for the reply!
    So the incident impacts my tenant, but it is not shown.
    Do I have the possibility to request that?

  3. to keep trying like you stated in the workaround, am i to keep on restarting the device to be sure it deploys to intune, as 12 out of 14 have deployed.

  4. How best to “retry”?
    Errors later in the OOBE seem to require a full system reset to restart the OOBE properly and that is a lengthy process.

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read