| Previous | Next |
| TPM_E_DELEGATE_FAMILY | TPM_E_TRANSPORT_NOTEXCLUSIVE |
TPM_E_DELEGATE_ADMIN
Technical interpretation
TPM_E_DELEGATE_ADMIN (0x8028004D) belongs to TPM 1.2 resources, delegation and contexts. This result means the TPM 1.2 delegation table is not in a state that permits the requested administrative modification.
Condition to preserve: The documented condition is “Delegation table management not enabled.” A comparison run should change that state, not an unrelated component setting.
The first producer to identify is the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. TBS can virtualize finite TPM resources, but a saved TPM context and a TBS virtual handle are not durable application IDs. Their validity depends on resource type, owning client context, TPM lifecycle and the exact save/load history.
Keep the result value 0x8028004D attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.
Inputs and state to capture
- Producer: the TPM resource, context or delegation manager, sometimes mediated by TBS virtualization.
- Rejected invariant: the TPM 1.2 delegation table is not in a state that permits the requested administrative modification.
- What to capture: delegation administration enablement, owner authorization, table state, family and row identifiers, and prior lock commands.
- Safe comparison: perform a read-only delegation query, then test administration in a freshly provisioned disposable environment.
Validate without broad changes
| Question | Evidence |
|---|---|
| What exact state was rejected? | the TPM 1.2 delegation table is not in a state that permits the requested administrative modification |
| Which layer owns the result? | The TPM resource, context or delegation manager, sometimes mediated by TBS virtualization. |
| What must be correlated? | delegation administration enablement, owner authorization, table state, family and row identifiers, and prior lock commands |
| Controlled comparison | perform a read-only delegation query, then test administration in a freshly provisioned disposable environment |
Neighboring response codes
| Constant | Meaning |
|---|---|
TPM_E_TRANSPORT_NOTEXCLUSIVE | There was a command executed outside of an exclusive transport session. |
TPM_E_DELEGATE_FAMILY | Attempt to manage a family other then the delegated family. |
TPM_E_OWNER_CONTROL | Attempt to context save an owner-evict-controlled key. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_DELEGATE_LOCK reports a lock that blocks administration after it was otherwise enabled.
Fix and verify
Enable and perform delegation administration through the owner-controlled workflow before locking the table. Do not persist volatile TPM or TBS handles as durable identifiers. A numeric handle can be valid only inside the creating context and lifecycle, even when its value looks unchanged after restart.
Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.
Source material
Looking for a different code? Search another status or error code.
