| Previous | Next |
| TPM_E_DOING_SELFTEST | TPM_20_E_CONTEXT_GAP |
TPM_E_DEFEND_LOCK_RUNNING
Technical interpretation
TPM_E_DEFEND_LOCK_RUNNING means the TPM anti-hammering or dictionary-attack defense timer is active, so protected authorization attempts are being rejected.
The first producer to identify is TBS command blocking, virtual-handle translation, retry or anti-hammering logic. Windows TBS schedules and mediates commands from multiple clients. It can block commands, translate virtual handles, request retry, and preserve anti-hammering policy before or after the raw device command path.
Inputs and state to capture
Preserve these items before changing anything:
- This result and
0x80280803, the exact returning method or command, and the first nested status. - failed authorization count, lockout timing if available, affected entity, command and auth session, system time behavior, and prior failed attempts.
- Record the TPM generation, manufacturer/firmware revision, Windows build, caller identity, and TBS/provider state.
- The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.
Validate without broad changes
Run this focused check: stop attempts and observe recovery after the policy-defined interval rather than testing more passwords. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.
| Stage | Pass condition |
|---|---|
| the TPM anti-hammering or dictionary-attack defense timer is active, so protected authorization attempts are being rejected | The original command reaches the next defined state without returning it. |
| Security behavior | Verification still uses the intended TPM, authorization, locality and policy. |
| Output integrity | The object, digest, event log or state transition produced after it validates independently. |
Neighboring response codes
| Related result | Separate meaning |
|---|---|
TPM_E_RETRY | The TPM is too busy to respond to the command immediately, but the command could be resubmitted at a later time. |
TPM_E_EMBEDDED_COMMAND_UNSUPPORTED | The command within the transport is not supported. |
TPM_E_EMBEDDED_COMMAND_BLOCKED | The command within the transport was blocked. |
The practical distinction is that TPM_E_RETRY reports temporary command load; this code is a security lockout caused by authorization failures.
Fix and verify
The supported direction is to correct the authorization source, respect lockout policy, and use supported recovery or administrative mechanisms. Do not disable command policy globally to make one test pass. First establish the caller, command code and supported higher-level alternative, because command blocking is a security boundary.
Technical references
- Microsoft: Command Blocking in TBS — source for this result.
- Microsoft: Using TPM Base Services — source for this result.
- Microsoft: Tbsip_Submit_Command — source for this result.
- TCG: TPM 1.2 Main Specification — source for this result.
Looking for a different code? Search another status or error code.
