Windows 8.1 Update - 'A TCG Command has returned an error' - Automatic Encryption Involved?

Anonymous
2014-05-18T21:14:09+00:00

I've got a desktop system which has been showing error messages in the Event Viewer ever since the upgrade to Windows 8.1 Update.  It's an error in EnhancedStorage-EhStorTcgDrv that says "A TCG Command has returned an error".  The error is with the "AuthenticateSession" command.

Doing a bunch of research shows that this error involves SSD encryption.  However, this is for a gaming PC with no personal information on it.  There's no need for Bitlocker or anything of that sort on it.  So I'm not entirely sure why it's sending that command in the first place other than if it's using the "Opal" / Microsoft eDrive spec for automatic encryption. The SSD I'm using (Plextor PX-M5M) does fully support the Opal specification, but I do not have a TPM, and as this is a desktop PC it doesn't support Connected Standby, two features that previously were requirements for automatic encryption on Windows 8.1.  Did something change with regards to these requirements in Windows 8.1 Update? 

I guess the really important question is... is this actually a message I should be worried about?  It's listed in Event Viewer as critical.  Can it just be ignored instead?

For what it's worth, my first thought was actually that the SSD or the mSATA slot it is installed in were the cause.  However, both of those have been swapped out as part of my troubleshooting, and that hasn't solved anything.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-05-22T10:34:16+00:00

Hello,

Thank you for your response.

Did you try performing clean boot?

Sometimes, "A TCG Command has returned an error" message appears because the device encryption is turned on.

I would suggest you to turn off the device encryption and check if it helps. Device encryption is turned on by default. Please use these steps.

a. If you have performed a clean install of Windows 8.1, device encryption is turned on by default. If you have upgraded a previous Windows installation to Windows 8.1, you can turn device encryption on by using PC info.

b. To open PC info, swipe in from the right edge of the screen, tap "Settings", and then tap "Change PC settings". (If you're using a mouse, point to the upper-right corner of the screen, move the mouse pointer down, click "Settings", and then click "Change PC settings".)

c. Tap or click "PC & devices", and then tap or click "PC info". The "Device Encryption" section appears at the bottom of the PC info page.

d. In the "Device Encryption" section, select "Turn On".

To opt out of automatic device encryption:

If you do not want the devices you are deploying to be automatically protected with device encryption, you can configure the unattend file to enforce the following registry setting:

• Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BitLocker

• Value: PreventDeviceEncryption equal to True (1)

• Type: REG_DWORD

Note: Serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

http://support.microsoft.com/kb/322756

For reference:

What's New in BitLocker for Windows 8.1 and Windows Server 2012 R2

http://technet.microsoft.com/en-us/library/dn306081.aspx

I hope this information helps.

Thank you

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Most helpful
  1. Anonymous
    2016-02-05T16:55:05+00:00

    Actually, that's not a Microsoft issue. Crucial is to blame for this error and it's consequences.

    Windows is just doing what is specified by TCG Opal standard and turns on the eDrive mode when a drive reports that it's fully compatible to this feature.

    The problem with Crucials SSDs is that their implementaion is faulty. Every other SSD from every other company which meets eDrive specification works flawlessly in this mode.

    I have never seen any reports of someone using eDrive mode with a Crucial SSD who is not experciencing these problems. So they should either fix their firmware or completely disable TCG Opal features.

    In any way, it's nonsense to blame MS for this error as they are exactly doing what they should according to the specifications which are reported by the drive itself (!)

    Was this answer helpful?

    0 comments No comments
  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2015-12-29T23:09:42+00:00

    OK, GUYS !!!

    Just stop whatever you're doing and read this.

    I know this topic is very old, but I've been dealing with this s*** for too long and I finally know exactly what to do.

    Don't listen to Microsoft, they'll tell you that your hardware is the cause of all this, and it's not.

    (I hope they don't delete this post)

    I have a MX100 from Crucial, and it is actually an edrive, which means it is self-encrypted.

    There is a "software" in the firmware that encrypts everything on its own, and it is very good. But MS Windows doesn't want that. It wants to do it itself.

    I spent, in total, more than 8 hours with the Microsoft Support from France, USA, UK... And they know nothing more than what you can read in these forums.

    What you can read in these forums is true, actually. Crucial called it, it's a MS Windows problem.

    It isn't caused by your drive.

    Microsoft Windows from 8 to 10 is always trying to get inside your drive to encrypt it even if you don't want to, and....

    That's the catch : You actually have to give up and let Microsoft do its thing.

    I downloaded the "storage-executive-win-64.zip" (might be 32 for some of you) from the Crucial's website and I launched it, then reverted the PSID of my drive.

    It took me a long time, because I had to install Windows on another HDD to do it, and then RE-REinstall Windows on my SDD.

    (Because you cannot do it if you're using the drive you're trying to revert for running the OS)

    Trust me, no problem anymore. Nothing in the event viewer. My computer is running really fine.

    I know I seem really angry and all, but Microsoft WON'T LET YOU deactivate the encryption it's trying to do and won't give any solution against that.

    Fortunately, Crucial is a respectable brand and they answered to me quite quickly. They told me they knew about this problem caused by the OS, but Microsoft is not going to do anything about it (apparently, which I confirm).

    (Except if you pay them $500 to have a real technician on the phone (level2))

    So I gave up and formated. Then upgraded the firmware (just in case) of the SDD, and then I reverted the PSID.

    How you do this ?

    Simple.

    Let me give you a "too long; didn't read"

    • Check your system for 32 or 64 bits before downloading like above. (I know, I'm french. But you get the point.)

    - To get this information, go to"System" or press Windows key+Pause.

    • Download the software which matches your version
    • Install it
    • Launch it
    • Web-based, so it open in your default browser

    - Click on "Restore PSID"

    • Enter the PSID (Which is a number that is actually printed on the physical drive)

    (Yes, I had a hard time reading the PSID because my SSD is screwed upside down and I'm lazy)

    • Click "Confirm"
    • Reboot and install MS Windows again on the SSD
    • Enjoy

    I really really really hope that will help a lot of you guys.

    I'm not really mad at the Microsoft Technical Support. they do what they can.

    But I'm really mad at Microsoft itself not allowing us to what we want with our own computers.

    By the way, I've been working in IT support for more than 15 years, and I can tell you this is your only option.

    Everything regarding registry modifying is not working. (Tested it)

    Please tell me if it helped anyone of you.

    Regards,

    Greg

    Edit:

    Ok, I didn't explain why it lets Microsoft do its thing.

    But it's really simple.

    When you revert the PSID, you turn the drive to its "factory default mode".

    Which means it doesn't encrypt itself and lets Windows do its thing and that's why it's working.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-04-01T21:05:36+00:00

    Hi,

    I have also been trying to figure out the way to solve this issue and I think I have figured it out, it has to do with switching the driver for the Marvell SATA 3 to AHCI. When you don't use the Marvell driver, the error occurrs, and when you put it back it is gone. In searching all the forums for this problem there  was no concrete answer for this issue, but after doing my own research, I realized that I had changed the drivers out, as many people do, and it also causes freezing and other issues, probably because the chip for the Marvell is wired into the motherboard. Also, they only time that this does happen is with Crucial SSD's so maybe there should be a fix for the firmware, if that is possible.

    Was this answer helpful?

    0 comments No comments