Windows 8.1 Update - 'A TCG Command has returned an error' - Automatic Encryption Involved?

Anonymous
2014-05-18T21:14:09+00:00

I've got a desktop system which has been showing error messages in the Event Viewer ever since the upgrade to Windows 8.1 Update.  It's an error in EnhancedStorage-EhStorTcgDrv that says "A TCG Command has returned an error".  The error is with the "AuthenticateSession" command.

Doing a bunch of research shows that this error involves SSD encryption.  However, this is for a gaming PC with no personal information on it.  There's no need for Bitlocker or anything of that sort on it.  So I'm not entirely sure why it's sending that command in the first place other than if it's using the "Opal" / Microsoft eDrive spec for automatic encryption. The SSD I'm using (Plextor PX-M5M) does fully support the Opal specification, but I do not have a TPM, and as this is a desktop PC it doesn't support Connected Standby, two features that previously were requirements for automatic encryption on Windows 8.1.  Did something change with regards to these requirements in Windows 8.1 Update? 

I guess the really important question is... is this actually a message I should be worried about?  It's listed in Event Viewer as critical.  Can it just be ignored instead?

For what it's worth, my first thought was actually that the SSD or the mSATA slot it is installed in were the cause.  However, both of those have been swapped out as part of my troubleshooting, and that hasn't solved anything.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-05-22T10:34:16+00:00

Hello,

Thank you for your response.

Did you try performing clean boot?

Sometimes, "A TCG Command has returned an error" message appears because the device encryption is turned on.

I would suggest you to turn off the device encryption and check if it helps. Device encryption is turned on by default. Please use these steps.

a. If you have performed a clean install of Windows 8.1, device encryption is turned on by default. If you have upgraded a previous Windows installation to Windows 8.1, you can turn device encryption on by using PC info.

b. To open PC info, swipe in from the right edge of the screen, tap "Settings", and then tap "Change PC settings". (If you're using a mouse, point to the upper-right corner of the screen, move the mouse pointer down, click "Settings", and then click "Change PC settings".)

c. Tap or click "PC & devices", and then tap or click "PC info". The "Device Encryption" section appears at the bottom of the PC info page.

d. In the "Device Encryption" section, select "Turn On".

To opt out of automatic device encryption:

If you do not want the devices you are deploying to be automatically protected with device encryption, you can configure the unattend file to enforce the following registry setting:

• Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker

• Value: PreventDeviceEncryption equal to True (1)

• Type: REG_DWORD

Note: Serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

http://support.microsoft.com/kb/322756

For reference:

What's New in BitLocker for Windows 8.1 and Windows Server 2012 R2

http://technet.microsoft.com/en-us/library/dn306081.aspx

I hope this information helps.

Thank you

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Oldest
  1. Anonymous
    2014-12-24T06:13:54+00:00

    Hello!

    I have tried adding the registry value (I'm quite certain I did it correctly) and the issue still persists (same error as above). I'm also on a Z97 chipset with a Crucial MX100 512gb drive. However, my O/S drive is a Corsair Force 3 120gb.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2014-12-28T13:02:57+00:00

    Hello Erocker,

    Thank you for the update.

    Did you try using suggestions in my responses on September 24, 2014?

    Please use those suggestions and reply with results.

    Thank you

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2014-12-28T23:10:17+00:00

    Ratandeep,

    Are you getting help from an application engineer or are you trying to figure this out yourself?  I've been going through Technet articles on Bitlocker, Self Encrypting Disks, reviewing postings at the Crucial forum, reading technotes from the Micron website, and even looking at the Opal spec from TCG.  Some of the advice you give conflicts with what I've been reading.

    From the Crucial forum, the educated guess is that there is a bug in Bitlocker.  Analysis of the log message indicates the SID_AUTHORITY is trying to authenticate itself to the SSD but is failing.  Guess is that it is a bad password(PIN).  I hope this is being relayed to someone who can root cause the problem.  Owners of other drive manufacturers are also reporting seeing the error message so it is not a Crucial exclusive problem but seems to be more prevalent on Crucial drives for some reason.

    One thing you haven't mentioned to people here is that their SSD is always encrypted, even if Bitlocker is off!  From the TechNetarticle you mentioned: "[as part of] a clean install of Windows 8.1...device encryption is initialized on the operating system drive and fixed data drives on the computer with a clear key (this is the equivalent of standard BitLocker suspended state)".  Suspended means encrypted with a clear key, not the same as no encryption.  I'm suspecting that is why Bitlocker is trying to authenticate for everyone.

    And the registry change you are recommending is causing people to needlessly edit their registry.  If you read the same TechNet article closely, the registry change must be made to Win8.1 before installation! "If you do not want the devices you are deploying to be automatically protected with device encryption, you can configure the unattend file to enforce the following registry setting:"  The unattend file is a configuration file that big companies use for deploying Windows so a user doesn't have to answer all the questions and enter keys when installing Windows.  Making the registry change after installation does nothing.

    We appreciate your help but this is a complex technical problem that should be researched further.

    BTW, I resolved my crash problem.  As mentioned, this was a new build and one of my memory sticks succumbed to infant mortality.  With different memory, no crashes but still getting the TCG Command error on power up.  Others experiencing crashes might want to also check the rest of their system.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2014-12-29T09:14:14+00:00

    Hello Mbulger,

    Thank you for responding.

    It is good to know that you managed to fix the issue.

    I really appreciate your efforts and time.

    Please feel free to reply, if you have any other issues with Windows.

    Thank you

    Was this answer helpful?

    0 comments No comments