cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Adgilbert
Fanfold Paper
Posts: 12
Registered: ‎05-24-2017
Location: US
Views: 1,852
Message 1 of 19

ThinkPad T470 TPM Lockout during SCCM Task Sequence

We are running SCCM Current Branch version 1706 and ADK 1703.  We just started having issues with the T470 TPM not initializing correctly during the OSD Deployment.  The TPM goes through the Pre-Provision steps without any problem but when we attempt to Enable Bitlocker and send the Key into AD we get "The TPM is defending against dictionary attacks and is in a time-out period." Error Code: 0x80280803

 

This is not a problem on any other model at this time.  We are also deploying M710s and X270 devices with the same task sequence using the same steps without issue.  Is there a step we need to take on the T470?

 

This task sequence is deploying Windows 7

 

Machine is in UEFI mode with CSM support.  Secure Boot is disabled and TPM is set to Active version 2.0

 

Let me know what else you need to help get this resolved.

 

Thanks!

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,836
Message 2 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

Has Win10 ever been installed on the machine?  Because Win10 will automatically take ownership of the TPM.  I have heard of strange things like this after Win10 takes ownership, and then you re-image the box with Win7 and try to use the TPM without clearing it first.  Anyway, once the TPM is in lockout (or in this strange state that causes lockout), the only solution is to clear it.

Adgilbert
Fanfold Paper
Posts: 12
Registered: ‎05-24-2017
Location: US
Views: 1,820
Message 3 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

This occurs on machines "out of the box".  I don't know what OEM OS is on them, I assume Windows 10.  This wasn't a problem until we updated our ADK and CB versions to current so we could start developing Windows 10 deployments.  We still need to deploy Windows 7 until we are fully tested and certified for 10 in our environment.

 

I have cleared the TPM from the BIOS and no change in behavior. 

 

I tried to post this under the Enterprise forum but it wouldn't post.  Hoping to get more feedback.

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,814
Message 4 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

Please try running the attached VBS (and reboot) before the pre-provision steps and see if the problem still happens?

cscript.exe tpm_clear_enable_activate.vbs

Adgilbert
Fanfold Paper
Posts: 12
Registered: ‎05-24-2017
Location: US
Views: 1,803
Message 5 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

No change.  The error log says Initial TPM State: 55  but I can't find any documentation on what the "states" of TPM are and what they mean.  Even when its clear it cant take ownership when it gets to the Enable Bitlocker steps.  

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,795
Message 6 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

What error log are you referring to?

As an experiment, can you try taking the preprovisioning and BitLocker steps out of your OSD and manually setting up BitLocker after deployment?  I think we need to prove that the TPM can work successfully and then figure out how to get it working within your image after that.

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,793
Message 7 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

What I mean is:

1.  deploy the system without BitLocker

2.  run tpm.msc, initialize the TPM

3.  from BitLocker control panel, turn on BitLocker

 

Can you get that working?

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,782
Message 8 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

 

We were able to reproduce this, and then realized that the required Microsoft hotfix for TPM 2.0 support wasn't in our Win7 reference image.  After the image was deployed, we saw the failure in smsts.log.  Then, I wasn't able to manually initialize the TPM (in TPM.msc) either.  Same error about the TPM defending against dictionary attacks.  So I applied the hotfix, rebooted, cleared the TPM one last time, and finally I was able to initialize it in TPM.msc without error.  Just applying the hotfix wasn't enough - the TPM was in a bad state so it had to be cleared also.

 

So we have added the hotfix and are currently rebuilding the image.  I'll let you know how that goes.

 

Is this hotfix in your image?  https://support.microsoft.com/en-us/help/2920188/update-to-add-support-for-tpm-2-0-in-windows-7-and-...

 

Adgilbert
Fanfold Paper
Posts: 12
Registered: ‎05-24-2017
Location: US
Views: 1,779
Message 9 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

Yes, that patch is in the image we are using.  We are able to image the M710s and the X270 using UEFI with CSM and TPM 2.0 and it works and we were able to use the T470 in this matter. 

 

In doing some testing I switched the TPM to 1.2 and used Legacy boot with CSM support and it imaged and bitlocker applied but immediatly went into recovery mode.  I am retesting with an OS image without the TPM 2.0 patch in it to see where we get.

 

 

Lenovo Staff
Lenovo Staff
Posts: 6,158
Registered: ‎10-29-2009
Location: NC
Views: 1,771
Message 10 of 19

Re: ThinkPad T470 TPM Lockout during SCCM Task Sequence

Your issue with TPM 1.2 and legacy mode is probably caused by not setting the boot order to make HDD first.  Also, prior to a legacy mode deployment, you need to load default settings in BIOS mode to make "Windows Boot Manager" boot entry go away (which is only for UEFI mode).

 

We are still deploying the T470 with Win7/UEFI + hotfix + TPM 2.0; will have results to share later this afternoon.

And we're back...

Move delayed but still coming

Learn More

Check out current deals!


Shop current deals

Top Kudoed Authors