| Previous | Next |
| TPM_E_COMMAND_BLOCKED | TPM_E_DUPLICATE_VHANDLE |
TPM_E_INVALID_HANDLE
Technical interpretation
TPM_E_INVALID_HANDLE means the Windows TBS translation layer cannot resolve the supplied virtual or physical handle for this command.
The first producer to identify is TBS command blocking, virtual-handle translation, retry or anti-hammering logic. Windows TBS schedules and mediates commands from multiple clients. It can block commands, translate virtual handles, request retry, and preserve anti-hammering policy before or after the raw device command path.
Read this result as its own boundary in a sequence, not as a verdict that every TPM feature is broken. The sequence reaches the Windows TBS translation layer cannot resolve the supplied virtual or physical handle for this command, and the component returns 0x80280401 before the application can safely assume that later key, attestation, boot or licensing work occurred.
Inputs and state to capture
- Request identity: exact function or command, input lengths, flags, caller context and this result.
- State identity: handle value, context handle, object type, creating response, TBS virtualization mapping, flush events, and process or power boundary.
- Platform identity: TPM generation, manufacturer/firmware revision, Windows build and relevant service events.
- Binary identity: preserve opaque structures byte-for-byte and log
0x80280401in hexadecimal.
Validate without broad changes
Create a fresh resource and use its returned virtual handle immediately within the same tbs context.
| Observed outcome | Interpretation |
|---|---|
| The exact request succeeds | The changed condition belongs to the rejected the Windows TBS translation layer cannot resolve the supplied virtual or physical handle for this command. |
| A more specific earlier code appears | Preserve the earlier result in the diagnostic trace; the previous trace probably lost the first producer. |
| The same code returns with identical bytes | Escalate the persistent it with firmware, service and command evidence rather than broad configuration changes. |
| The code disappears only after destructive reset | The experiment is not diagnostic because original protected state and evidence were removed. |
Neighboring response codes
| Nearby constant | Why it is different |
|---|---|
TPM_E_DUPLICATE_VHANDLE | The TPM returned a duplicate handle and the command needs to be resubmitted. |
TPM_E_COMMAND_BLOCKED | The command was blocked. |
TPM_E_EMBEDDED_COMMAND_BLOCKED | The command within the transport was blocked. |
By contrast, TBS_E_INVALID_CONTEXT rejects the TBS context itself; this code concerns a resource handle inside a command.
Fix and verify
Apply the narrow remedy: stop reusing handles after close, flush, service restart or resume and keep them scoped to the creating context. Do not disable command policy globally to make one test pass. First establish the caller, command code and supported higher-level alternative, because command blocking is a security boundary.
References
- Microsoft: Command Blocking in TBS — source for this result.
- Microsoft: Using TPM Base Services — source for this result.
- Microsoft: Tbsip_Submit_Command — source for this result.
- TCG: TPM 1.2 Main Specification — source for this result.
Looking for a different code? Search another status or error code.
