Site icon EfmSoft

What does HRESULT 0x80284012 (TBS_E_ACCESS_DENIED) mean?

 
Previous Next
TBS_E_NO_EVENT_LOG TBS_E_PROVISIONING_NOT_ALLOWED

TBS_E_ACCESS_DENIED

Technical interpretation

TBS_E_ACCESS_DENIED (0x80284012) belongs to the public and internal TPM Base Services path. The base What Is page already shows the short Windows message; the additional diagnostic value is that this result marks Windows denied the caller permission to perform the selected TBS operation or command class.

The first producer to identify for it is the TBS client library, local RPC service and command scheduler before or around device execution. TBS centralizes TPM access through a local RPC service. A failure can therefore occur in the caller contract, RPC/service startup, scheduling, buffer handling or TPM submission, and each layer requires different evidence.

Inputs and state to capture

Preserve these this result items before changing anything:

Validate without broad changes

Run this focused check: run a harmless allowed TBS call under the same token and compare with the protected operation without elevating the whole application. Do not combine the result test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.

CheckpointPass condition
Windows denied the caller permission to perform the selected TBS operation or command classThe original this result command reaches the next defined state without returning it.
Security behaviorThe result verification still uses the intended TPM, authorization, locality and policy.
Output integrityThe object, digest, event log or state transition produced after it validates independently.

Neighboring response codes

Related resultSeparate meaning
TBSIMP_E_BUFFER_TOO_SMALLThe specified buffer was too small — a separate checkpoint when compared with it.
TBS_E_BUFFER_TOO_LARGEThe input or output buffer is too large — a separate checkpoint when compared with it.
TBSIMP_E_CLEANUP_FAILEDThe context could not be cleaned up — a separate checkpoint when compared with it.

The practical distinction is that TPM_E_COMMAND_BLOCKED is command-policy denial after TBS examines the command; it is the public access-control failure.

Fix and verify

The supported direction is to use the documented privilege boundary or a higher-level key API and grant only the minimum required access. Do not restart or disable TBS before capturing its service and event data. Most caller-contract errors are reproducible without touching TPM ownership, firmware state or stored keys.

If the same bytes still return it after the documented preconditions are satisfied, retain this code-specific trace for the platform vendor or Windows component owner rather than erasing state.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version