Unable to Enroll Latitude or Precision in Microsoft Intune
Summary: Learn what to do when a Latitude or Precision is unable to be enrolled in Microsoft Intune. An error message of "TPM attestation has expired" is seen.
Symptoms
An issue may occur when enrolling a Latitude or Precision in Microsoft Intune. An error message about the Trusted Platform Module (TPM) of "TPM attestation has expired" is seen. This happens after the Dell TPM firmware is updated to version 1.769. The firmware update allows the Latitude or Precision to be detected by Windows Autopilot, but the "TPM attestation has expired" error occurs again after seven minutes.
Affected Platforms:
- Latitude 5430
- Latitude 5520
- Latitude 5530
- Latitude 7320
- Latitude 7420
- Latitude 9430
- Precision 3570
- Precision 5550
- Precision 5570
- Precision 7560
Affected Operating System:
- Windows 11 build 24H2
Cause
Dell engineering has already identified the root cause. Autopilot enrollment certificate requires an intermediate certificate authority (CA) certificate during authentication which they missed during the loading process. This caused the attestation failure.
The enrollment process uses the wrong NV_index from the Trusted Platform Module (TPM) chipset.
The issue only affects computers that are shipped with Windows 10 and then upgraded to Windows 11, or the computer shipped with Windows 10 and then reimaged to Windows 11 using SupportAssist or Dell Recovery.
Resolution
Microsoft engineering has released KB5055627. Updating the computer with KB5055627 resolves this issue. For more information about KB5053656, refer to April 25, 2025-KB5055627 (OS Build 26100.3915) Preview - Microsoft Support.