AMD Pluton fTPM EK certificate not recognized by Azure AIK — 404 error, blocks TPM attestation

Benjy 0 Reputation points
2026-08-01T11:54:19.3766667+00:00

Hello,I am requesting that this ticket be escalated directly to the Windows Kernel Security / Azure Attestation Engineering Team.My local PC is completely locked out of security compliance features and competitive gaming networks because Microsoft’s remote Azure AIK servers are rejecting my CPU’s hardware batch with an HTTP 404 Not Found error.This is a known backend database oversight where Microsoft has failed to onboard the new Intermediate Certificate Authority (CA) for my specific processor model into the global cloud registry.My Hardware Details:Device Model: ASUS ROG Strix G16 (G614FM Gaming Laptop)Security Processor: Integrated Microsoft Pluton TPM 2.0 ModuleDiagnostic Evidence:When executing certreq -enrollaik -config “” from an elevated Command Prompt, the local TPM chip correctly initiates the cryptographic payload, but your backend Azure endpoint fails the handshake with the following exact JSON response:jsonGetCACaps: Not Found {“Message”:“The authority "msft-keyid-6cdfb473a95e6d5b9799f6ade13cf12a138372a2.microsoftaik.azure.net" does not exist.”} HTTP/1.1 404 Not Found Use code with caution.This proof shows that my physical hardware is functioning perfectly, but the remote authority URL path does not exist on Microsoft’s server end. My local system’s AdditionalCertificates cache under Get-TpmEndorsementKeyInfo is stuck at empty braces {} as a direct result.Please whitelist or upload the missing hardware signing keys for this specific AMD/ASUS Pluton processor production batch to your Azure attestation infrastructure so that the server-side validation checks can succeed.Thank you.

Microsoft Security | Intune | Enrollment
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.