Site icon EfmSoft

What does HRESULT 0x80280400 (TPM_E_COMMAND_BLOCKED) mean?

 
Previous Next
TPM_20_E_SENSITIVE TPM_E_INVALID_HANDLE

TPM_E_COMMAND_BLOCKED

Technical interpretation

TPM_E_COMMAND_BLOCKED means Windows TBS command policy blocked the outer TPM command before normal device execution.

The first producer to identify is TBS command blocking, virtual-handle translation, retry or anti-hammering logic. Windows TBS schedules and mediates commands from multiple clients. It can block commands, translate virtual handles, request retry, and preserve anti-hammering policy before or after the raw device command path.

Inputs and state to capture

QuestionEvidence
What exact state was rejected?Windows TBS command policy blocked the outer TPM command before normal device execution
Which layer owns the result?TBS command blocking, virtual-handle translation, retry or anti-hammering logic.
What must be correlated?command ordinal or command code, caller token and app-container state, OS version, applicable blocked/allowed policy, and TBS event data
Controlled comparisonsubmit a benign allowed capability command through the same TBS context to prove transport and context creation are working

Record the original command or API call before retry logic for this result mutates its nonces, handles, buffers or state. Also retain the full HRESULT as 0x80280400; signed decimal logging can obscure the TPM/TBS facility and make searches less precise.

Validate without broad changes

  1. Establish the baseline with the same device, Windows build, account and TPM generation.
  2. Perform one narrow experiment: submit a benign allowed capability command through the same TBS context to prove transport and context creation are working.
  3. Compare raw inputs and the first response, not only the final application dialog.
  4. Stop after the first changed result; if a later error replaces this HRESULT, this condition was passed even if the whole workflow still fails.

Neighboring response codes

ResultDifferent diagnostic question
TPM_E_INVALID_HANDLEThe specified handle was not found.
TPM_E_DUPLICATE_VHANDLEThe TPM returned a duplicate handle and the command needs to be resubmitted.
TPM_E_EMBEDDED_COMMAND_BLOCKEDThe command within the transport was blocked.

The key distinction is that TPM_E_EMBEDDED_COMMAND_BLOCKED applies to a command carried inside a legacy transport.

Fix and verify

To correct this, use a supported higher-level API or an allowed command; change command policy only through documented administrative controls and with security review. Do not disable command policy globally to make one test pass. First establish the caller, command code and supported higher-level alternative, because command blocking is a security boundary.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version