| Previous | Next |
| TBS_E_NO_EVENT_LOG | TBS_E_PROVISIONING_NOT_ALLOWED |
TBS_E_ACCESS_DENIED
Technical interpretation
TBS_E_ACCESS_DENIED means Windows denied the caller permission to perform the selected TBS operation or command class.
The first producer to identify is the TBS client library, local RPC service and command scheduler before or around device execution. TBS centralizes TPM access through a local RPC service. A failure can therefore occur in the caller contract, RPC/service startup, scheduling, buffer handling or TPM submission, and each layer requires different evidence.
Inputs and state to capture
Preserve these this result items before changing anything:
- This result and
0x80284012, the exact returning method or command, and the first nested status. - caller token, integrity level, app-container state, command ordinal, TBS policy, process identity, and whether a higher-level API is available.
- The TPM generation, manufacturer/firmware revision, Windows build, caller identity and TBS/provider state.
- The complete opaque request artifacts, redacting authorization secrets but not rewriting structure boundaries.
Validate without broad changes
Run this focused check: run a harmless allowed TBS call under the same token and compare with the protected operation without elevating the whole application. Do not combine the test with firmware updates, TPM clearing, account changes, key recreation and policy edits in the same trial; such a result cannot isolate this boundary.
| Stage | Pass condition |
|---|---|
| Windows denied the caller permission to perform the selected TBS operation or command class | The original command reaches the next defined state without returning it. |
| Security behavior | The result verification still uses the intended TPM, authorization, locality and policy. |
| Output integrity | The object, digest, event log or state transition produced after it validates independently. |
Neighboring response codes
| Related result | Separate meaning |
|---|---|
TBSIMP_E_BUFFER_TOO_SMALL | The specified buffer was too small. |
TBS_E_BUFFER_TOO_LARGE | The input or output buffer is too large. |
TBSIMP_E_CLEANUP_FAILED | The context could not be cleaned up. |
The practical distinction is that TPM_E_COMMAND_BLOCKED is command-policy denial after TBS examines the command; it is the public access-control failure.
Fix and verify
The supported direction is to use the documented privilege boundary or a higher-level key API and grant only the minimum required access. Do not restart or disable TBS before capturing its service and event data. Most caller-contract errors are reproducible without touching TPM ownership, firmware state or stored keys.
Technical references
- Microsoft: About TPM Base Services — source for this result.
- Microsoft: TBS return codes — source for this result.
- Microsoft: Tbsi_Context_Create — source for this result.
- Microsoft: Tbsip_Submit_Command — source for this result.
Looking for a different code? Search another status or error code.
