| Previous | Next |
| TPM_20_E_SENSITIVE | TPM_E_INVALID_HANDLE |
TPM_E_COMMAND_BLOCKED
Technical interpretation
TPM_E_COMMAND_BLOCKED means Windows TBS command policy blocked the outer TPM command before normal device execution.
The first producer to identify is TBS command blocking, virtual-handle translation, retry or anti-hammering logic. Windows TBS schedules and mediates commands from multiple clients. It can block commands, translate virtual handles, request retry, and preserve anti-hammering policy before or after the raw device command path.
Inputs and state to capture
| Question | Evidence |
|---|---|
| What exact state was rejected? | Windows TBS command policy blocked the outer TPM command before normal device execution |
| Which layer owns the result? | TBS command blocking, virtual-handle translation, retry or anti-hammering logic. |
| What must be correlated? | command ordinal or command code, caller token and app-container state, OS version, applicable blocked/allowed policy, and TBS event data |
| Controlled comparison | submit a benign allowed capability command through the same TBS context to prove transport and context creation are working |
Record the original command or API call before retry logic for this result mutates its nonces, handles, buffers or state. Also retain the full HRESULT as 0x80280400; signed decimal logging can obscure the TPM/TBS facility and make searches less precise.
Validate without broad changes
- Establish the baseline with the same device, Windows build, account and TPM generation.
- Perform one narrow experiment: submit a benign allowed capability command through the same TBS context to prove transport and context creation are working.
- Compare raw inputs and the first response, not only the final application dialog.
- Stop after the first changed result; if a later error replaces this HRESULT, this condition was passed even if the whole workflow still fails.
Neighboring response codes
| Result | Different diagnostic question |
|---|---|
TPM_E_INVALID_HANDLE | The specified handle was not found. |
TPM_E_DUPLICATE_VHANDLE | The TPM returned a duplicate handle and the command needs to be resubmitted. |
TPM_E_EMBEDDED_COMMAND_BLOCKED | The command within the transport was blocked. |
The key distinction is that TPM_E_EMBEDDED_COMMAND_BLOCKED applies to a command carried inside a legacy transport.
Fix and verify
To correct this, use a supported higher-level API or an allowed command; change command policy only through documented administrative controls and with security review. Do not disable command policy globally to make one test pass. First establish the caller, command code and supported higher-level alternative, because command blocking is a security boundary.
Technical references
Looking for a different code? Search another status or error code.
