UNSOLVED

dell_nerd

updated

15 years ago

D

dell_nerd

4 Posts

0

67202

August 8th, 2011 04:00

Latitude E6410 MBAM

Hi all,

i am use the new tool from Microsoft for Bitlocker administration.

when i am use E6410 with Bios A09 and Driver Cab A06 for HDD encryption the following error will display " take ownership of tpm failed"
i have first TPM in bios enabled!
When i go to TPM.msc , i can manual take ownership and can start the encryption of my HDD
Has anyone an solution for me by this behavior?

Rgds,
dell_nerd
  • DELL-Warren B

    1 Rookie

    1124 Posts

    1519

    0

    Posted August 8th, 2011 10:00

    Have you reviewed the whitepaper (below) on TPM enablement?

    http://media.community.dell.com/en/dtc/attach/tpm_best_practices - web post.zip
  • dell_nerd

    4 Posts

    1519

    0

    Posted August 9th, 2011 07:00

    Hi,

    yes i have reviewed the whitpaper but it seems that mbam service can't take ownership
  • DELL-Warren B

    1 Rookie

    1124 Posts

    1519

    0

    Posted August 11th, 2011 13:00

    I'm checking to see if we have any additional information on using MBAM with Dell client systems.
  • dell_nerd

    4 Posts

    1519

    0

    Posted August 16th, 2011 05:00

    Hi,

    have you any update for me?

    Microsoft says:

    In these articles, we should notice:

    Microsoft works closely with hardware manufacturers and industry groups to make it possible to manage most functions of the TPM from within the TPM Management console. However, on some occasions, it may not be possible to control all aspects of your TPM security hardware from inside this version of Windows. Examples may include:



    l Hardware that does not fully support the TPM 1.2 specification.

    l Hardware that does not contain a fully supported BIOS

    l Hardware that has an option to hide the TPM security hardware from the operating system

    l Hardware for which the manufacturer has decided to require that the BIOS screens be used to turn on, turn off, or clear the TPM



    In such cases, you may be able to manage your TPM security hardware from the BIOS or setup screens of your computer.

  • DELL-Warren B

    1 Rookie

    1124 Posts

    1520

    0

    Posted August 18th, 2011 13:00

    If TPM.msc is working correctly, then I would expect that the issue is on how MBAM attempts to manage the TPM. It should use the same functions as TPM.msc. Can Microsoft explain the difference?

    I couldn't find any Dell specific documentation on MBAM.
  • dell_nerd

    4 Posts

    1520

    0

    Posted August 30th, 2011 03:00

    Hi,
    Microsoft says :After performing your issue based on your DELL E6420/6410, we suggest that you can try to use the Dell™ Client Configuration Toolkit (CCTK) to perform TPM Activation via the following link:

    This was working but the next issue comes up: mbam starts the encryption but it failed

    it seems that mbam does not take the same functions as TPM.msc

    i tried this with HP notebook and it works completly What makes this different from DEll
  • DELL-Warren B

    1 Rookie

    1124 Posts

    1520

    0

    Posted August 30th, 2011 23:00

    Thanks for the additional details. I'll follow up with the dev team.
  • 1520

    0

    Posted September 22nd, 2011 22:00

    The Dell BIOS TPM has to be set to "Disabled" not "Activate" which is completely counter intuative since it works perfectly using the "manage-bde -TPM" commands and the TPM mmc. The MBAM client will now start the compatability check and then prompt for a reboot which brings up a BIOS prompt to accept TPM changes and youll now have TPM recovery data in the MBAM console after encryption starts.

    I dont know whether to blame Dell or MS for the pain but I hope this saves someone else frustration.
  • 1520

    0

    Posted October 4th, 2011 10:00

    I had the same issue on a 6320 with A06 BIOS. It would exhibit the same behavior until I updated the Dell Control Vault firmware and driver. The firmware would not update until I took ownership of the TPM and following the update,
    I cleared the TPM and rebooted, it was set to enabled and deactivated. MBAM picked it up successfully on the restart.

    I am not certaint whether it was something specific with firmware or driver updates, or whether it reset the TPM state in a way I had not.
  • ShawnD123

    1 Message

    299

    0

    Posted October 13th, 2011 08:00

    My company is looking into using MBAM for bitlockering all our dell machines and have had mixed results. From the sounds of it others have as well. We have run into the "Can't take TPM ownership" issue ourselfs and are you saying the setting the TPM to Disabled and not Activate, you get around this issue?