| Previous | Next |
| TPM_E_PPI_BLOCKED_IN_BIOS | TPM_E_PCP_DEVICE_NOT_READY |
TPM_E_PCP_ERROR_MASK
What failed and what did not
TPM_E_PCP_ERROR_MASK means the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself.
The first producer to identify is CNG/NCrypt provider error mapping above TBS and the TPM. The Microsoft Platform Crypto Provider exposes TPM-backed keys through CNG. Provider HRESULTs may wrap key-policy, TBS or device failures, so the exact provider operation and nested status are essential.
Keep the result value 0x80290400 attached to the symbolic name. Some logs may store it as a negative signed integer or expose only a generic CNG, WMI, BitLocker or enrollment message. Preserve the original HRESULT because those representations can hide the TPM- or TBS-specific condition.
Collect a useful trace
- Producer: CNG/NCrypt provider error mapping above TBS and the TPM.
- Rejected invariant: the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself.
- What to capture: the full HRESULT from NCrypt or certificate enrollment, provider name, operation, key property, nested TPM/TBS status, and hexadecimal representation.
- Safe comparison: classify a captured provider HRESULT with the mask, then decode the actual low-order PCP error rather than invoking a provider operation for the mask.
Narrow experiment
| Question | Evidence |
|---|---|
| What exact state was rejected? | the bit mask used to identify Platform Crypto Provider TPM-related HRESULTs, not a failure returned for a key operation by itself |
| Which layer owns the result? | CNG/NCrypt provider error mapping above TBS and the TPM. |
| What must be correlated? | the full HRESULT from NCrypt or certificate enrollment, provider name, operation, key property, nested TPM/TBS status, and hexadecimal representation |
| Controlled comparison | classify a captured provider HRESULT with the mask, then decode the actual low-order PCP error rather than invoking a provider operation for the mask |
Similar-looking outcomes
| Constant | Meaning |
|---|---|
TPM_E_ERROR_MASK | This is an error mask to convert TPM hardware errors to win errors. |
TPM_E_FAIL | The operation failed. |
TPM_E_SHA_THREAD | There is no existing SHA-1 thread. |
The codes above may appear in the same workflow, but they are not aliases. TPM_E_ERROR_MASK classifies the broader TPM hardware mapping family, while this mask is tied to Platform Crypto Provider errors.
Operational response
Preserve provider and nested error values in telemetry and fix the concrete pcp condition. Do not treat a provider mask as a key-specific diagnosis. Preserve the exact NCrypt status and the inner TPM/TBS result before changing certificate or key enrollment policy.
Proof consists of a successful replay plus validation of the intended key, PCR, NV, context, event-log, provider or service result. A software fallback or a newly provisioned blank TPM answers a different question than the original failure.
Source material
Looking for a different code? Search another status or error code.
