Windows 8.1 Update - 'A TCG Command has returned an error' - Automatic Encryption Involved?

Anonymous
2014-05-18T21:14:09+00:00

I've got a desktop system which has been showing error messages in the Event Viewer ever since the upgrade to Windows 8.1 Update.  It's an error in EnhancedStorage-EhStorTcgDrv that says "A TCG Command has returned an error".  The error is with the "AuthenticateSession" command.

Doing a bunch of research shows that this error involves SSD encryption.  However, this is for a gaming PC with no personal information on it.  There's no need for Bitlocker or anything of that sort on it.  So I'm not entirely sure why it's sending that command in the first place other than if it's using the "Opal" / Microsoft eDrive spec for automatic encryption. The SSD I'm using (Plextor PX-M5M) does fully support the Opal specification, but I do not have a TPM, and as this is a desktop PC it doesn't support Connected Standby, two features that previously were requirements for automatic encryption on Windows 8.1.  Did something change with regards to these requirements in Windows 8.1 Update? 

I guess the really important question is... is this actually a message I should be worried about?  It's listed in Event Viewer as critical.  Can it just be ignored instead?

For what it's worth, my first thought was actually that the SSD or the mSATA slot it is installed in were the cause.  However, both of those have been swapped out as part of my troubleshooting, and that hasn't solved anything.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-05-22T10:34:16+00:00

Hello,

Thank you for your response.

Did you try performing clean boot?

Sometimes, "A TCG Command has returned an error" message appears because the device encryption is turned on.

I would suggest you to turn off the device encryption and check if it helps. Device encryption is turned on by default. Please use these steps.

a. If you have performed a clean install of Windows 8.1, device encryption is turned on by default. If you have upgraded a previous Windows installation to Windows 8.1, you can turn device encryption on by using PC info.

b. To open PC info, swipe in from the right edge of the screen, tap "Settings", and then tap "Change PC settings". (If you're using a mouse, point to the upper-right corner of the screen, move the mouse pointer down, click "Settings", and then click "Change PC settings".)

c. Tap or click "PC & devices", and then tap or click "PC info". The "Device Encryption" section appears at the bottom of the PC info page.

d. In the "Device Encryption" section, select "Turn On".

To opt out of automatic device encryption:

If you do not want the devices you are deploying to be automatically protected with device encryption, you can configure the unattend file to enforce the following registry setting:

• Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker

• Value: PreventDeviceEncryption equal to True (1)

• Type: REG_DWORD

Note: Serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

http://support.microsoft.com/kb/322756

For reference:

What's New in BitLocker for Windows 8.1 and Windows Server 2012 R2

http://technet.microsoft.com/en-us/library/dn306081.aspx

I hope this information helps.

Thank you

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2015-12-29T23:09:42+00:00

    OK, GUYS !!!

    Just stop whatever you're doing and read this.

    I know this topic is very old, but I've been dealing with this s*** for too long and I finally know exactly what to do.

    Don't listen to Microsoft, they'll tell you that your hardware is the cause of all this, and it's not.

    (I hope they don't delete this post)

    I have a MX100 from Crucial, and it is actually an edrive, which means it is self-encrypted.

    There is a "software" in the firmware that encrypts everything on its own, and it is very good. But MS Windows doesn't want that. It wants to do it itself.

    I spent, in total, more than 8 hours with the Microsoft Support from France, USA, UK... And they know nothing more than what you can read in these forums.

    What you can read in these forums is true, actually. Crucial called it, it's a MS Windows problem.

    It isn't caused by your drive.

    Microsoft Windows from 8 to 10 is always trying to get inside your drive to encrypt it even if you don't want to, and....

    That's the catch : You actually have to give up and let Microsoft do its thing.

    I downloaded the "storage-executive-win-64.zip" (might be 32 for some of you) from the Crucial's website and I launched it, then reverted the PSID of my drive.

    It took me a long time, because I had to install Windows on another HDD to do it, and then RE-REinstall Windows on my SDD.

    (Because you cannot do it if you're using the drive you're trying to revert for running the OS)

    Trust me, no problem anymore. Nothing in the event viewer. My computer is running really fine.

    I know I seem really angry and all, but Microsoft WON'T LET YOU deactivate the encryption it's trying to do and won't give any solution against that.

    Fortunately, Crucial is a respectable brand and they answered to me quite quickly. They told me they knew about this problem caused by the OS, but Microsoft is not going to do anything about it (apparently, which I confirm).

    (Except if you pay them $500 to have a real technician on the phone (level2))

    So I gave up and formated. Then upgraded the firmware (just in case) of the SDD, and then I reverted the PSID.

    How you do this ?

    Simple.

    Let me give you a "too long; didn't read"

    • Check your system for 32 or 64 bits before downloading like above. (I know, I'm french. But you get the point.)

    - To get this information, go to"System" or press Windows key+Pause.

    • Download the software which matches your version
    • Install it
    • Launch it
    • Web-based, so it open in your default browser

    - Click on "Restore PSID"

    • Enter the PSID (Which is a number that is actually printed on the physical drive)

    (Yes, I had a hard time reading the PSID because my SSD is screwed upside down and I'm lazy)

    • Click "Confirm"
    • Reboot and install MS Windows again on the SSD
    • Enjoy

    I really really really hope that will help a lot of you guys.

    I'm not really mad at the Microsoft Technical Support. they do what they can.

    But I'm really mad at Microsoft itself not allowing us to what we want with our own computers.

    By the way, I've been working in IT support for more than 15 years, and I can tell you this is your only option.

    Everything regarding registry modifying is not working. (Tested it)

    Please tell me if it helped anyone of you.

    Regards,

    Greg

    Edit:

    Ok, I didn't explain why it lets Microsoft do its thing.

    But it's really simple.

    When you revert the PSID, you turn the drive to its "factory default mode".

    Which means it doesn't encrypt itself and lets Windows do its thing and that's why it's working.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-04-01T21:05:36+00:00

    Hi,

    I have also been trying to figure out the way to solve this issue and I think I have figured it out, it has to do with switching the driver for the Marvell SATA 3 to AHCI. When you don't use the Marvell driver, the error occurrs, and when you put it back it is gone. In searching all the forums for this problem there  was no concrete answer for this issue, but after doing my own research, I realized that I had changed the drivers out, as many people do, and it also causes freezing and other issues, probably because the chip for the Marvell is wired into the motherboard. Also, they only time that this does happen is with Crucial SSD's so maybe there should be a fix for the firmware, if that is possible.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-03-15T19:00:26+00:00

    How were you able to determine it was your memory stick causing the issue?

    I got lucky.  It was a new computer build and I passed Prime95 and Memtest86 with no problems (but the temps in Prime95 were scary).  A week or so later, I started getting crashes once every few days when just browsing.  Then once a day.  Then I couldn't run 10 minutes without a crash.  My computer would sometimes fail to boot and displayed non-existent error codes.

    It was then that I went into "shotgun" mode.  Swapping components out to try to isolate the problem.  It was then I found that going down from two memory sticks to one fixed the problem.  I also had a spare stick that I swapped in and that made the problem disappear too.  I exchanged the memory and haven't had a problem since.

    I saw the TCG error message early on which is how I ended up on this thread.  If my memory hadn't gotten so bad as to put me in "shotgun" mode, I would probably still be chasing after the disk encryption.

    This was the second time in my many years of computer building I went down the wrong path.  My previous problem was a sagging power supply.  Did you know the tolerance on the 5V line is only 5%?  I returned what was probably a perfectly good disk drive because it was showing bad SMART numbers due to a power supply that sagged on startup.

    So my personal recommendation is to check everything else out in your system to the best of your ability.  But if you still want to turn off disk encryption, I can give you the magic spell to turn Bitlocker all the way off.

    Was this answer helpful?

    0 comments No comments