Windows Autopilot white-glove / self-deploy fails on Lenovo

%3CLINGO-SUB%20id%3D%22lingo-sub-2803062%22%20slang%3D%22en-US%22%3EWindows%20Autopilot%20white-glove%20%2F%20self-deploy%20fails%20on%20Lenovo%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2803062%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20have%20a%20series%20of%20Lenovo%20Notebooks%20(ThinkBook%2014%20G2%20ARE%20Laptop%20-%20Type%2020VF)%20where%20Autopilot%20white-glove%20and%20self-deployment%20fail%20during%20enrollment%20of%20the%20AIK%20certificate%20with%20a%20http%20error%20404.%3C%2FP%3E%3CP%3EHere's%20the%20logfile%3A%3C%2FP%3E%3CPRE%3E%3CFONT%20color%3D%22%23666699%22%3Ev2.0%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3ETPM-Version%3A2.0%20-Level%3A0-Revision%3A1.38-VendorID%3A'AMD%20'-Firmware%3A196650.5%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3EAMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3ECN%3DPRG-RN%2C%20O%3DAdvanced%20Micro%20Devices%2C%20S%3DCA%2C%20L%3DSanta%20Clara%2C%20C%3DUS%2C%20OU%3DEngineering%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3Ehttps%3A%2F%2FAMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net%2Ftemplates%2FAik%2Fscep%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3EGetCACaps%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3EGetCACaps%3A%20Not%20Found%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23666699%22%3E%7B%22Message%22%3A%22The%20authority%20%5C%22amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net%5C%22%20does%20not%20exist.%22%7D%3C%2FFONT%3E%3CBR%20%2F%3E%3CFONT%20color%3D%22%23FF0000%22%3E%3CSTRONG%3EHTTP%2F1.1%20404%20Not%20Found%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FPRE%3E%3CP%3ENow%20I'm%20wondering%20whether%20this%20is%20one%20of%20the%20reare%20cases%20that%20%3CA%20title%3D%22TPM%20Attestation%3A%20What%20can%20possibly%20go%20wrong%3F%22%20href%3D%22https%3A%2F%2Foofhours.com%2F2019%2F07%2F09%2Ftpm-attestation-what-can-possibly-go-wrong%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMichael%20mentions%20on%20his%20blog%3C%2FA%3E%20where%20the%20TPM%20has%20not%20been%20whitelisted%20by%20Microsoft%20(for%20whatever%20reason).%3C%2FP%3E%3CP%3ESome%20more%20details%20about%20the%20TPM%3A%3C%2FP%3E%3CPRE%3EC%3A%5CWindows%5Csystem32%26gt%3Btpmtool%20getdeviceinformation%3CBR%20%2F%3E-TPM%20Present%3A%20True%3CBR%20%2F%3E-TPM%20Version%3A%202.0%3CBR%20%2F%3E-TPM%20Manufacturer%20ID%3A%20AMD%3CBR%20%2F%3E-TPM%20Manufacturer%20Full%20Name%3A%20AMD%3CBR%20%2F%3E-TPM%20Manufacturer%20Version%3A%203.47.0.5%3CBR%20%2F%3E-PPI%20Version%3A%201.3%3CBR%20%2F%3E-Is%20Initialized%3A%20True%3CBR%20%2F%3E-Ready%20For%20Storage%3A%20True%3CBR%20%2F%3E-Ready%20For%20Attestation%3A%20True%3CBR%20%2F%3E-Is%20Capable%20For%20Attestation%3A%20True%3CBR%20%2F%3E-Clear%20Needed%20To%20Recover%3A%20False%3CBR%20%2F%3E-Clear%20Possible%3A%20True%3CBR%20%2F%3E-TPM%20Has%20Vulnerable%20Firmware%3A%20False%3CBR%20%2F%3E-PCR7%20Binding%20State%3A%202%3CBR%20%2F%3E-Maintenance%20Task%20Complete%3A%20True%3CBR%20%2F%3E-TPM%20Spec%20Version%3A%201.38%3CBR%20%2F%3E-TPM%20Errata%20Date%3A%20Friday%2C%20March%2002%2C%202018%3CBR%20%2F%3E-PC%20Client%20Version%3A%201.01%3CBR%20%2F%3E-Is%20Locked%20Out%3A%20False%3C%2FPRE%3E%3CP%3ESince%20the%20same%20configuration%20works%20like%20a%20charm%20for%20other%20notebook%20models%2C%20I%20assume%2C%20the%20reason%20somewhere%20in%20the%20TPM%20and%20not%20the%20configuration%20in%20Intune.%3C%2FP%3E%3CP%3EDoes%20anybody%20have%20more%20details%20about%20TPM%20attestation%20and%20the%20background%20infrastructure%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2803062%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAutopilot%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eself-deploy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ewhite-glove%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

Hello,

I have a series of Lenovo Notebooks (ThinkBook 14 G2 ARE Laptop - Type 20VF) where Autopilot white-glove and self-deployment fail during enrollment of the AIK certificate with a http error 404.

Here's the logfile:

v2.0
TPM-Version:2.0 -Level:0-Revision:1.38-VendorID:'AMD '-Firmware:196650.5
AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8
CN=PRG-RN, O=Advanced Micro Devices, S=CA, L=Santa Clara, C=US, OU=Engineering
https://AMD-KeyId-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net/templates/Aik/scep
GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found

Now I'm wondering whether this is one of the rare cases that Michael mentions on his blog where the TPM has not been whitelisted by Microsoft (for whatever reason).

Some more details about the TPM:

C:\Windows\system32>tpmtool getdeviceinformation
-TPM Present: True
-TPM Version: 2.0
-TPM Manufacturer ID: AMD
-TPM Manufacturer Full Name: AMD
-TPM Manufacturer Version: 3.47.0.5
-PPI Version: 1.3
-Is Initialized: True
-Ready For Storage: True
-Ready For Attestation: True
-Is Capable For Attestation: True
-Clear Needed To Recover: False
-Clear Possible: True
-TPM Has Vulnerable Firmware: False
-PCR7 Binding State: 2
-Maintenance Task Complete: True
-TPM Spec Version: 1.38
-TPM Errata Date: Friday, March 02, 2018
-PC Client Version: 1.01
-Is Locked Out: False

Since the same configuration works like a charm for other notebook models, I assume, the reason somewhere in the TPM and not the configuration in Intune.

Does anybody have more details about TPM attestation and the background infrastructure?

4 Replies
HI, which OS build is installed on the device? did you tried to reinstall it with the latest 21h2 build to see what happens?
The ISO is 21H1. Do you have an official source for 21H2? I can't find it on MSDN or MPN yet.
The error message in the UI reads now "TPM attestation timed out". Still the same 404 error in the enrollaik logfile. I'll wait for Windows 11 and try again, but I assume, it won't go away.