TPM

24 events across 1 channel

EventTitleChannelSample
2The TPM self test command failed.SystemN
12The device driver for the Trusted Platform Module (TPM) encountered an error in …SystemN
14The device driver for the Trusted Platform Module (TPM) encountered a …SystemN
15The device driver for the Trusted Platform Module (TPM) encountered a …SystemN
16A compatible TPM is not found.SystemN
17The Trusted Platform Module (TPM) hardware failed to execute a TPM command.SystemN
18This event triggers the Trusted Platform Module (TPM) provisioning/status check …SystemN
19The system firmware failed to enable overwriting of system memory on restart.SystemN
20A command was sent to the Trusted Platform Module (TPM) successfully resetting …SystemN
21A standard user issued Trusted Platform Module (TPM) command returned an …SystemN
22TPM Base Services (TBS) has been configured in a test mode until the next full …SystemN
23A standard user Trusted Platform Module (TPM) command was blocked because the …SystemN
24The Trusted Platform Module (TPM) status: statusEnabled and statusActive.SystemN
25Creation of the Windows AIK directory failed.SystemN
26Creation of provisioning event has failed.SystemN
27The initialization of the Trusted Platform Module (TPM) failed.SystemN
28Information about the Storage Root Key creation.SystemN
29Creation of the Storage Root Key failed.SystemN
30Reset and/or resume count do not match expected values after hibernate/resume.SystemN
31Information about Kernel Soft Reboot.SystemN
32Encountered an error calling TpmApi.SystemN
33The Trusted Platform Module (TPM) has been cleared as requested by Requester.SystemN
34A PPI request to clear the Trusted Platform Module (TPM) has been requested by …SystemN
35The TPM base register address is a non-standard address.SystemN

Event ID 2: The TPM self test command failed.

#
Provider
TPM
Channel
System

Description

The TPM self test command failed.

Message #

The TPM self test command failed.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 12: The device driver for the Trusted Platform Module (TPM) encountered an error in the TPM hardware, which might prevent some applications using TPM s...

#
Provider
TPM
Channel
System

Description

The device driver for the Trusted Platform Module (TPM) encountered an error in the TPM hardware, which might prevent some applications using TPM services from operating correctly. Please restart your computer to reset the TPM hardware. For further assistance on this hardware issue, please contact the computer manufacturer for more information.

Message #

The device driver for the Trusted Platform Module (TPM) encountered an error in the TPM hardware, which might prevent some applications using TPM services from operating correctly.  Please restart your computer to reset the TPM hardware.  For further assistance on this hardware issue, please contact the computer manufacturer for more information.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 14: The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services.

#
Provider
TPM
Channel
System

Description

The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer.

Message #

The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 15: The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services.

#
Provider
TPM
Channel
System

Description

The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer.

Message #

The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 16: A compatible TPM is not found.

#
Provider
TPM
Channel
System

Description

A compatible TPM is not found.

Message #

A compatible TPM is not found.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 17: The Trusted Platform Module (TPM) hardware failed to execute a TPM command.

#
Provider
TPM
Channel
System

Description

The Trusted Platform Module (TPM) hardware failed to execute a TPM command.

Message #

The Trusted Platform Module (TPM) hardware failed to execute a TPM command.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
TpmCommandOrdinal UInt32
TpmResponseCode UInt32

Event ID 18: This event triggers the Trusted Platform Module (TPM) provisioning/status check to run.

#
Provider
TPM
Channel
System

Description

This event triggers the Trusted Platform Module (TPM) provisioning/status check to run.

Message #

This event triggers the Trusted Platform Module (TPM) provisioning/status check to run.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 19: The system firmware failed to enable overwriting of system memory on restart.

#
Provider
TPM
Channel
System

Description

The system firmware failed to enable overwriting of system memory on restart. The ACPI request could not be interpreted by the firmware. The firmware should be upgraded.

Message #

The system firmware failed to enable overwriting of system memory on restart. The ACPI request could not be interpreted by the firmware. The firmware should be upgraded.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data1 UInt32
Data2 UInt32

Event ID 20: A command was sent to the Trusted Platform Module (TPM) successfully resetting the TPM lockout logic.

#
Provider
TPM
Channel
System

Description

A command was sent to the Trusted Platform Module (TPM) successfully resetting the TPM lockout logic. This event is generated when a successful command sent to the TPM resets the TPM lockout logic. With this event, all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.

Message #

A command was sent to the Trusted Platform Module (TPM) successfully resetting the TPM lockout logic. This event is generated when a successful command sent to the TPM resets the TPM lockout logic.  With this event, all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 21: A standard user issued Trusted Platform Module (TPM) command returned an authorization failure.

#
Provider
TPM
Channel
System

Description

A standard user issued Trusted Platform Module (TPM) command returned an authorization failure. This event is generated when a command sent to the TPM by a standard user returns a response indicating an authorization failure. If too many authorization failures occur, standard users may be temporarily prevented from sending TPM commands requiring authorization. This helps prevent the TPM from entering a hardware lockout because of too many authorization failures. User Security ID:UserSID. Process Path ProcessPath.

Message #

A standard user issued Trusted Platform Module (TPM) command returned an authorization failure. This event is generated when a command sent to the TPM by a standard user returns a response indicating an authorization failure.  If too many authorization failures occur, standard users may be temporarily prevented from sending TPM commands requiring authorization.  This helps prevent the TPM from entering a hardware lockout because of too many authorization failures. 
User Security ID:%1. 
Process Path %2.

Fields #

NameDescription
UserSID UnicodeString
ProcessPath UnicodeString

Event ID 22: TPM Base Services (TBS) has been configured in a test mode until the next full restart.

#
Provider
TPM
Channel
System

Description

TPM Base Services (TBS) has been configured in a test mode until the next full restart. The TBS will not perform TPM resource virtualization or TPM command blocking until the next full restart.

Message #

TPM Base Services (TBS) has been configured in a test mode until the next full restart. The TBS will not perform TPM resource virtualization or TPM command blocking until the next full restart.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 23: A standard user Trusted Platform Module (TPM) command was blocked because the standard user has exceeded the maximum authorization failures permitted.

#
Provider
TPM
Channel
System

Description

A standard user Trusted Platform Module (TPM) command was blocked because the standard user has exceeded the maximum authorization failures permitted. This event is generated when too many recent TPM commands sent to the TPM by a standard user returned a response indicating an authorization failure. The standard user is currently temporarily prevented from sending TPM commands requiring authorization. This helps prevent the TPM from entering a hardware lockout because of too many authorization failures. User Security ID:UserSID.

Message #

A standard user Trusted Platform Module (TPM) command was blocked because the standard user has exceeded the maximum authorization failures permitted. This event is generated when too many recent TPM commands sent to the TPM by a standard user returned a response indicating an authorization failure.  The standard user is currently temporarily prevented from sending TPM commands requiring authorization.  This helps prevent the TPM from entering a hardware lockout because of too many authorization failures. 
User Security ID:%1.

Fields #

NameDescription
UserSID UnicodeString

Event ID 24: The Trusted Platform Module (TPM) status: statusEnabled and statusActive.

#
Provider
TPM
Channel
System

Description

The Trusted Platform Module (TPM) status: statusEnabled and statusActive.

Message #

The Trusted Platform Module (TPM) status: %1 and %2.

Fields #

NameDescription
statusEnabled UInt32
statusActive UInt32

Event ID 25: Creation of the Windows AIK directory failed.

#
Provider
TPM
Channel
System

Description

Creation of the Windows AIK directory failed.

Message #

Creation of the Windows AIK directory failed.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data UInt32

Event ID 26: Creation of provisioning event has failed.

#
Provider
TPM
Channel
System

Description

Creation of provisioning event has failed.

Message #

Creation of provisioning event has failed.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32

Event ID 27: The initialization of the Trusted Platform Module (TPM) failed.

#
Provider
TPM
Channel
System

Description

The initialization of the Trusted Platform Module (TPM) failed. The TPM may be in failure mode. To allow diagnosis, contact the TPM manufacturer with the attached information.

Message #

The initialization of the Trusted Platform Module (TPM) failed. The TPM may be in failure mode. To allow diagnosis, contact the TPM manufacturer with the attached information.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
TPM_PT_MANUFACTURER HexInt32
TPM_PT_VENDOR_STRING_1 HexInt32
TPM_PT_VENDOR_STRING_2 HexInt32
TPM_PT_VENDOR_STRING_3 HexInt32
TPM_PT_VENDOR_STRING_4 HexInt32
TPM_PT_VENDOR_TPM_TYPE HexInt32
TPM_PT_FIRMWARE_VERSION_1 HexInt32
TPM_PT_FIRMWARE_VERSION_2 HexInt32
DataSize UInt16
GetTestResult_Data UInt8

Event ID 28: Information about the Storage Root Key creation.

#
Provider
TPM
Channel
System

Description

Information about the Storage Root Key creation.

Message #

Information about the Storage Root Key creation.

Fields #

NameDescription
SrkSymKeyPolicyValue UInt32
TpmAes256Capability UInt32
ActualSymBitsUsed UInt32
SrkAsymKeyPolicyValue UInt32
TpmRsa3kCapability UInt32
ActualAsymBitsUsed UInt32

Event ID 29: Creation of the Storage Root Key failed.

#
Provider
TPM
Channel
System

Description

Creation of the Storage Root Key failed.

Message #

Creation of the Storage Root Key failed.

Fields #

NameDescription
SrkSymKeyPolicyValue UInt32
TpmAes256Capability UInt32
ActualSymBitsUsed UInt32
SrkAsymKeyPolicyValue UInt32
TpmRsa3kCapability UInt32
ActualAsymBitsUsed UInt32

Event ID 30: Reset and/or resume count do not match expected values after hibernate/resume.

#
Provider
TPM
Channel
System

Description

Reset and/or resume count do not match expected values after hibernate/resume.

Message #

Reset and/or resume count do not match expected values after hibernate/resume.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
resetCountBefore UInt32
restartCountBefore UInt32
resetCountAfter UInt32
restartCountAfter UInt32

Event ID 31: Information about Kernel Soft Reboot.

#
Provider
TPM
Channel
System

Description

Information about Kernel Soft Reboot.

Message #

Information about Kernel Soft Reboot.

Fields #

NameDescription
functionName UnicodeString
status UInt32NTSTATUS reference

Event ID 32: Encountered an error calling TpmApi.

#
Provider
TPM
Channel
System

Description

Encountered an error calling TpmApi.

Message #

Encountered an error calling TpmApi.

Fields #

NameDescription
description UnicodeString
status UInt32NTSTATUS reference

Event ID 33: The Trusted Platform Module (TPM) has been cleared as requested by Requester.

#
Provider
TPM
Channel
System

Description

The Trusted Platform Module (TPM) has been cleared as requested by Requester. Keys previously created in the storage and endorsement hierarchies will no longer work.

Message #

The Trusted Platform Module (TPM) has been cleared as requested by %3. Keys previously created in the storage and endorsement hierarchies will no longer work.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Requester UnicodeString

Event ID 34: A PPI request to clear the Trusted Platform Module (TPM) has been requested by Requester.

#
Provider
TPM
Channel
System

Description

A PPI request to clear the Trusted Platform Module (TPM) has been requested by Requester.

Message #

A PPI request to clear the Trusted Platform Module (TPM) has been requested by %3.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Requester UnicodeString

Event ID 35: The TPM base register address is a non-standard address.

#
Provider
TPM
Channel
System

Description

The TPM base register address is a non-standard address.

Message #

The TPM base register address is a non-standard address.

Fields #

NameDescription
driverFile HexInt32
lineNumber UInt32
Data1 UInt32
Data2 UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 1b6b0772-251b-4d42-917d-faca166bc059

Defined in tpm.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads