| Previous | Next |
| TPM_E_BAD_KEY_PROPERTY | TPM_E_BAD_SCHEME |
TPM_E_BAD_MIGRATION
Technical interpretation
TPM_E_BAD_MIGRATION means the key migration attributes or migration authorization do not form a permitted TPM 1.2 migration policy.
The first producer to identify is the certified-migration, key-policy or EK administrative checkpoint. TPM 1.2 migration policy is encoded when a key is created and reinforced by signed authority tickets and source/destination bindings. Migration errors therefore require the original binary artifacts and key attributes, not only the user-visible key name.
Inputs and state to capture
Preserve these items before changing anything:
- This result and
0x80280029, the exact returning method or command, and the first nested status. - migratable and migration-authority flags, key type, parent, migrationAuth, destination data, and the command used to create the migration blob.
- Record the TPM generation, manufacturer/firmware revision, Windows build, caller identity, and TBS/provider state.
- The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.
Validate without broad changes
Run this focused check: repeat with a disposable key created explicitly for the intended migration model and a freshly generated authorization value. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.
| Stage | Pass condition |
|---|---|
| the key migration attributes or migration authorization do not form a permitted TPM 1.2 migration policy | The original command reaches the next defined state without returning it. |
| Security behavior | Verification still uses the intended TPM, authorization, locality and policy. |
| Output integrity | The object, digest, event log or state transition produced after it validates independently. |
Neighboring response codes
| Related result | Separate meaning |
|---|---|
TPM_E_MA_TICKET_SIGNATURE | Migration authority signature validation failure. |
TPM_E_MA_DESTINATION | Migration destination not authenticated. |
TPM_E_MA_SOURCE | Migration source incorrect. |
The practical distinction is that TPM_E_MA_AUTHORITY and related MA codes diagnose certified-migration participants, while this code rejects the key migration properties.
Fix and verify
The supported direction is to recreate the key or migration workflow with consistent migration attributes; nonmigratable key policy cannot be reversed after creation. Do not edit a signed ticket, migration blob or opaque private-key structure. Binary normalization, JSON conversion or base64 line handling can invalidate the authority and integrity relationships.
Technical references
- TCG: TPM 1.2 Main Specification — source for this result.
- TCG: TPM 1.2 Part 2 — Certified migration structures — source for this result.
- TCG: TPM 1.2 Part 3 — Migration commands — source for this result.
- Microsoft: How Windows uses the TPM — source for this result.
Looking for a different code? Search another status or error code.
