Registering devices with Intune for management and policy enforcement
Azure AIK enrollment returns HTTP 400 (0x80190190) for EK signed by "CSME ADL PTT 01SVN" — Intel PTT CA appears missing from AIK trust pool
My desktop fails Windows AIK certificate enrollment on every attempt, blocking TPM attestation for consumer applications.
System: MSI PRO Z790-P WIFI (Z790 chipset, Raptor Lake), TPM 2.0 via Intel PTT, Windows 11 (fully updated), Secure Boot enforcing with 2023 CA/KEK certificates deployed.
Symptom: AIK enrollment against the Microsoft AIK CA returns HTTP 400 / 0x80190190 (-2145844848) on every attempt since March 2026.
EK certificate issuer: CN=CSME ADL PTT 01SVN (NotBefore June 2021).
What I have verified/attempted client-side:
- Windows pre-attestation health (Event 1038, TPM-WMI): "Attestable - device is expected to pass attestation"; EkCertIsAvailable = true; PCRs match TCG log. Only the Windows AIK certificates never provision (all three report unavailable).
- BIOS updated to latest (A.J0, May 2026)
- CSME firmware updated 16.1.32.2473 -> 16.1.40.2765 via Intel FWUpdate; TPM cleared and re-provisioned after the update. The EK derives from the fused seed, so the EK certificate and its issuing CA are unchanged and enrollment still fails identically.
- No VPN/proxy; time synced; clean measured boot.
This appears to be the same pattern as question 5887593 (Intel ODCA/CSME intermediates missing from the Azure AIK trust pool) and the previously-resolved Infineon CA 035 gap.
Real-world impact: blocks Microsoft Azure Attestation-based verification in consumer applications (e.g., Call of Duty RICOCHET anti-cheat), which now restricts gameplay on affected systems. Activision support case filed.
Request: can Microsoft confirm whether "CSME ADL PTT 01SVN" (and sibling Intel CSME on-die CAs) are in the Azure AIK CA trust pool, and if not, add them or provide a timeline?