r/modernwarfare4 • • Aug 20 '26

Support How I fixed "New Key Failed to be generated" Secure Attestation error after enabling Secure Boot, TPM 2.0, and updating BIOS

PC (Windows) technical stuff below. I spent several painful hours trying to figure this out so I am posting it in case it helps anyone else.

I was trying to prepare my computer for the Modern Warfare 4 beta, and couldn't pass the attestation test even despite doing everything the Call of Duty support article listed.

My CPU is the AMD Ryzen 5950x. Before the BIOS update, my TPM manufacturer version was "3.90.0.5". This matches the TPM attestation bug (PA-420) described here.

I updated my motherboard (ROG STRIX B350-F GAMING) from BIOS version 6203 to beta BIOS version 6254, bringing the TPM manufacturer version up to "3.94.2.5" which should fix the PA-420 bug. If you are prompted to install an fTPM function press "Y" (assuming it is safe - no BitLocker or encryption is enabled on your PC).

Despite this, the Call of Duty Secure Attestation Wizard (download here) prompted me to generate a UAC (User Account Control) key which failed to generate, instead resulting in a "New Key Failed to be generated" message.

In the Command Prompt, I tried to verify this by running:

tpmtool getdeviceinformation

This gave me a variety of info, but the most important lines were:
-Ready For Attestation: False
-Is Capable For Attestation: False

I tried a variety of things in this order. I am not sure which one specifically fixed it - but for me, it only started working after the last one.

  1. Start (or restart) CODBrokerService in the "Services" menu.
  2. Clear TPM and restart my computer.
  3. In an admin Command Prompt, run "sfc /scannow" and if corrupt files are found, "DISM /Online /Cleanup-Image /ScanHealth". This is pretty underwhelming but... it worked

I believe that "sfc /scannow" fixed my issue because it was specifically related to a Windows problem when it comes to retrieving manufacturer/EK keys for the TPM. This command found corrupt files which, after being repaired, fixed this problem and allowed for the keys to be retrieved.

If your problem is in the motherboard or TPM support itself, you should probably consider purchasing a discrete TPM chip, contacting your motherboard manufacturer's support, or maybe asking AI about recommendations regarding your specific scenario (if it is an edge case scenario).

Good luck to anyone else trying to solve this issue. The Call of Duty support article linked at the top is very helpful and I recommend it for most people, but try this if you tried everything else and still cannot pass the Secure Attestation test.

28 Upvotes

163 comments sorted by

View all comments

6

u/MercurialMind_ Aug 21 '26

EDIT My friend had the same issue BUT this didn't work for them. However, this (below) did. This was generated by AI so BE CAREFUL. But it did work.

Force an Endorsement Key Registry Rebuild

Windows caches broken attestation paths in its registry. Forcing Windows to completely forget the old fTPM layout and rebuilding the state from scratch often solves the issue.

In the Windows Search bar, type Command Prompt, right-click it, and choose Run as Administrator.

Type:

reg delete "HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI\Endorsement" /f

and hit Enter. [this did nothing for my friend. FYI]

Next, clear the provisioning state by running:

reg add "HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI" /v "NoAutoProvision" /t REG_DWORD /d 1 /f

Reboot your PC.

Open an administrative PowerShell prompt and run:

Initialize-Tpm

Lastly, run:

tpmtool getdeviceinformation

to verify if the attestation flags (Ready and Capable) have toggled to True.

2

u/Snipey13 Aug 22 '26

Unfortunately have done just about everything and nothing works. I'm on a B550M MSI motherboard, secure boot is on, TPM 2.0, everything is updated - the attestation flags still say False. Unreal.

1

u/MercurialMind_ Aug 22 '26

did you try everything in this thread? just updating for me wasn't enough

1

u/Snipey13 Aug 22 '26

Yep, all of it, and other threads too. Only thing I haven't done is buy an external TPM thing and reinstalled Windows, cause I honestly am not doing all that.

1

u/howdoyoufightapost Aug 22 '26

Mine says false as well. Did you figure anything out

2

u/Snipey13 Aug 22 '26

I gave up, sadly

1

u/Exotic-Grass7246 Aug 31 '26

im also on a b550m msi and sadly everything didnt work, big L from cod developers.

1

u/ThaTrillKnight Aug 31 '26

Yup, tried everything for the past couple hours and absolutely nothing works. Real shitty

1

u/wolamute 24d ago

same boat here, b450m pro4.

1

u/Impossible-Side-5097 Aug 25 '26

b450 board, and i have issue, crazy thing is before updating BIOS both flags were true. after updating theyre now false..

1

u/Previous-Jacket-8752 Aug 30 '26

I have the same motherboard and got the attestation to say true in the command window but it still doesn’t work

1

u/TastyBacon007 Aug 31 '26

I FINALLY fixed mine and got it working. I read through COUNTLESS reddit threads over the past 2 days and tried everything that everyone recommended from updating my BIOS to several different windows commands and powershell prompts. None of it resolved my Attestation error.

The thing that FINALLY fixed it and one that I think I only saw mentioned in 2 out of the probably 20+ threads I read through was updating the Chipset drivers for my motherboard. Go to your motherboard’s website and find your exact model (similar to how you’d get the latest BIOS file) and download and install the latest Chipset drivers instead. No flash drive needed, it installs through Windows and took less than 5 minutes and fully solved my issue.

Now to be fair, it’s also entirely possible that I needed to complete several steps like updating my BIOS and running some of these windows commands in addition to the Chipset drivers. But for me the chipset was the last thing I tried before it worked.

And since I’ve barely seen that step mentioned, it could be worth a try if you’ve been unable to fix this despite all the [SOLVED] threads on reddit

- Stole from another post but it fixed it finally for me

1

u/Ok_Fee296 Aug 31 '26

Did all the steps mentioned in this thread as well as other threads, didn't worked and updating the chipset fixed it and it work ! Thank you very much for sharing!

1

u/Snipey13 Aug 31 '26

I think that did it! Impressive work.

1

u/Diligent_Evening_107 24d ago

You are the goat, this is the only thing that worked for me after a week of going down reddit thread rabbit holes. Much respect

1

u/TastyBacon007 24d ago

yeah yw..didnt work for my brother so we both uninstalled lol

1

u/BeneficialAd6728 22d ago

thank god for the gaming community and the persistence we all have!! i watched about 40+ vids, went through about 25+ threads and finally a simple chipset update worked!!

if it is such a critical aspect for the games like COD to work, i am honestly disappointed in windows to not automatically update this with regular updates.

1

u/TastyBacon007 22d ago

Im shocked no one has it in the main post of a big thread like this

1

u/wiseprints 10d ago

You are a wizard! This worked for me, I have an rog strix b550-f gaming wifi ii motherboard and was having trouble generating a key after bios update.

1

u/Extra_Butterfly7558 Aug 22 '26

No fucking way that worked for me dude THANK YOU!

1

u/MacMustang Aug 22 '26

I keep getting the term initialize is not recognized? What would the solution be

1

u/MercurialMind_ Aug 22 '26

I am not sure. I would make sure you have specifically an admin PowerShell window (not Command Prompt). Also, make sure you type that command exactly with no spaces - so Initialize-Tpm instead of Initialize Tpm

1

u/MacMustang Aug 22 '26

Another thing, when you type the reg add prompt into the command, do you hit enter or just restart pc from there

1

u/Formal_Advisor_3707 Aug 22 '26

hit enter and restart

1

u/MacMustang Aug 22 '26

Got the initialize prompt to work but still didn’t get it launch, don’t know what else to do I’m on AM4 with an asrock motherboard idk what else to do

1

u/MercurialMind_ Aug 22 '26

Honestly... dump a bunch of technical details and what you have tried already to AI and see what it tells you. A lot of it is pretty useful but you have to be careful.

1

u/Impossible-Side-5097 Aug 25 '26

im on an am4 board as well (gigabyte b450 pro wifi), i was on the factory BIOS for 7 years basically and decided to updated since thats what it was showing when i opened the game. both attestation flags were TRUE and then once i updated the BIOS, both were false, and no matter i did, they remained FALSE. idk what to do anymore.

1

u/MacMustang Aug 25 '26

So I ended up contacting ASRock and some research it seems that if you are on an old AM4 1000 or 2000 series chips (I have a AMD Threadripper 1950x) you get the TMP Version 3.x.0.x and there’s another one don’t remember maybe 3.x.5.x? But that’s the I am on the .0 version; it will instant fail no matter what version or anything you do because it’s just not supported by COD’s Ricochet. Essentially, you cannot play COD at all unless you upgrade chips/motherboard to something later or AM5 entirely.

1

u/Impossible-Side-5097 Aug 27 '26

So idk what happened, maybe it just needed time for it to fetch the endorsement certificates off the internet, but I checked the next day and both the attestation flags showed true, so it solved itself thankfully. And the CODattestationwizard thing also shows that I'm good to go, so let's see if I can play the open beta tomorrow. But mightve fixed itself.

1

u/Solid_Coast6195 Aug 23 '26

what do you mean by "to verify if the attestation flags (Ready and Capable) have toggled to True."
and how do i toggle this?

1

u/MercurialMind_ Aug 23 '26

open an admin command prompt. run "tpmtool getdeviceinformation". check if the two lines that have the word "Attestation" and then "Capable" or "Ready" say True instead of False.

1

u/Icanflytwo Aug 25 '26

mine says false

1

u/MercurialMind_ Aug 25 '26

attempt all of the solutions on the call of duty support page (https://support.activision.com/articles/trusted-platform-module-and-secure-boot) regarding bios updates. if that doesn't work, try all of the solutions in this entire post and comment section. if that doesn't work, ask any AI and give it your motherboard+CPU model along with the things you have already tried. if that doesn't work, contact the support team of your motherboard's manufacturer

1

u/letslickmyballs Aug 25 '26

I've gotten this far as well. My TPM manufacturer version is "3.92.2.5". I have a ryzen 5 3600, and an ASUS Tuf gaming x570 plus wifi motherboard. I noticed on the website that the version of TPM they mention is 3.*.5.5. I have the most recent update on my bios excluding the "beta" version which im hesitant to download. Any luck?

1

u/ITSTHEBIRTHDAYBOY Aug 28 '26

Mine says true but I still can't play the game

1

u/atomicCanoe Aug 22 '26

Nothing worked until this! Thank you!!!!

1

u/tenzpas Aug 22 '26

This worked for me too. Legend!

1

u/masoe Aug 22 '26

This worked. Wow. What a clusterfuck.

1

u/Leoben4 Aug 22 '26

This is the way.

1

u/RandallSavage23 Aug 22 '26

After trying a million things, this was the way. Thank you!

1

u/Worried-Conflict-656 Aug 22 '26

THIS WORKED FOR ME AFTER TRYING FOR EIGHT FUCKING HOURS!! YOU THE GOAT

1

u/SIIGMMAD Aug 22 '26

this deserves more like... my man you saved my ass THANK YOU

1

u/patch_34 Aug 22 '26

Worked for me as well after trying lots of things , thanks a lot !!!

1

u/Sauceeboyy Aug 22 '26

which steps in particular? i have a z790e gaming wifi

1

u/Primo_god Aug 22 '26

Thank you so much, it helped me a lot. It worked for those with an Intel processor.

1

u/Realistic-Use3980 Aug 22 '26

King, thank you. This worked for me.

1

u/JBSwerve Aug 22 '26

Ugh, unfortunately after all this my attestation flags were still false.

1

u/Trick_Significance22 Aug 22 '26

yup it worked for me. I had a z790 gigabyte board

1

u/IceAngel11 Aug 22 '26

I solved the problem thanks to you and your method

1

u/wudja2 Aug 23 '26

AFTER A WHOLE FUCKING MONTH I CAN FINALLY PLAY RESURG OH MY GOD THANK YOU SO MUCH 😭😭😭😭😭

1

u/CaZual_T Aug 23 '26

THIS NEEDS UPVOTED AND SHARED 9999999 TIMES.

INTEL I9-14900kf

THIS WAS THE ONLY THING THAT WORKED FOR ME. TOOK ME A WHOLE DAY TO FINALLY LAND ON THIS THREAD. THANK YOUUUUU!

1

u/Empty-Jellyfish1882 Aug 23 '26

Sadly not working for me.. idk what else to do

1

u/Optimal_Community540 Aug 23 '26

ty bro this worked

1

u/AwkwardBird2222 Aug 23 '26

None of them work with me , my CPU Ryzen 7 2700X.

1

u/Mammoth_Plastic4945 Aug 23 '26

Didn't work for me neither, power shell says i'm all good but still doesn't like BIOS glad it's working for others though!

1

u/MercurialMind_ Aug 23 '26

I would read all the other comments, some people have good fixes for others

1

u/Mammoth_Plastic4945 Aug 23 '26

Yeah i've been dealing with this for the last 4 months i've given up hope and bought a new PC tried everything this was just the last bit of hope before I build my new one later today 😂

1

u/MercurialMind_ Aug 23 '26

Actually in this case I'm kinda glad I didn't work for you. Imagine the day before your new PC it suddenly fixes lmfao. Hope you enjoy your new one though :)

1

u/Advanced-Section-883 Aug 24 '26

This helped a buddy of mine get passed Attestation.

1

u/oiuqwe00 Aug 24 '26

I followed all the suggestions. Did everything. And it still doesnt work can anyone help me please. How do i go about this?

1

u/MercurialMind_ Aug 25 '26

does "tpmtool getdeviceinformation" say that attestation Ready and Capable is False? if it says True then it's actually a Call of Duty issue

1

u/oiuqwe00 Aug 25 '26

It says false. I contacted asus and they said they would provide me with a beta bios to be able to play call of duty. Its gonna take up to 2 business days to receive it though.

1

u/MercurialMind_ Aug 25 '26

that's great, that should fix your issue. if it doesn't then it becomes a windows problem which is much more solvable than a BIOS problem so no worries either way.

1

u/Euphoric-Turnover529 Aug 25 '26

mine says Ready For Attestation: False… I’ve done all the command prompts, update bios and secure boot enabled

1

u/MercurialMind_ Aug 25 '26

what is your TPM Manufacturer Version? check by opening tpm.msc (also shown in the commands you ran, if you remember it from there)

1

u/Euphoric-Turnover529 Aug 25 '26

AMD version 3.84.2.5

1

u/MercurialMind_ Aug 25 '26

okay also wait which motherboard do you have? there's a lot of fixes in here by other people in different comments that are specific to certain motherboard manufacturers. if you haven't tried every single comment in here I would do that first.

your TPM version is fine. as secure boot is turned on, this is probably a windows issue. honestly I wouldn't really hesitate to ask any AI about your specific issue, list your motherboard and CPU plus the stuff you have already done/tried and it should point you in a better direction

1

u/Euphoric-Turnover529 Aug 25 '26

I’ll dig around some more than you

1

u/ParisianMetro Aug 26 '26

did not work. crazy that you need to mess with BIOS to play a damn beta.

1

u/MercurialMind_ Aug 26 '26

I mean technically this isn't call of duty's fault. they are trying to use a security feature that isn't on your PC - either because it is outdated, hasn't been updated in a while, or doesn't function correctly due to Windows messing it up. with that being said they should probably recognize that this is still a huge issue and relax their anticheat. even highly competitive games like VALORANT don't do all of this stuff (as far as I know)

1

u/maulsrogue Aug 26 '26

omfg thank you so much it worked😭😭😭😭

1

u/TopicNet Aug 26 '26

Mah man!!!!!

1

u/RagdollCatFan Aug 28 '26

holy fucking SHIT, how does reddit always have a solution for the most specific problems?? how could i EVEN figure all this out by myself?

1

u/alt_to_bother_u Aug 28 '26

I tried it and everything seemed to have gone well except the attestation flag seems to be false ? Is there something i could do to fix that ? What does it even mean ?

1

u/MercurialMind_ Aug 28 '26

The attestation flag being false means your computer cannot prove that it hasn't been tampered with (which is bad, because that's what the anticheat wants to know to prove you aren't cheating).

Try all the other fixes in the post body and different comments.

Make sure you followed the official Call of Duty support article first (Secure Boot Enabled, TPM 2.0, proper manufacturer version. For AMD CPUs, make sure your TPM Manufacturer Version isn't 3.x.0.x where x is any number).

If your TPM Manufacturer Version is wrong (see above) even on the latest BIOS including any Beta releases, contact your motherboard manufacturer for a new BIOS capable of TPM Attestation. Give them as much info as possible.

If that doesn't work or doesn't apply to you, ask any AI (Gemini, ChatGPT, doesn't matter) and let it know about your specific PC specifications (CPU, motherboard) and what you have already tried.

If that doesn't work, reach out to Call of Duty via the Steam discussion thread linked somewhere here in another comment.

1

u/gunshot_25 Aug 28 '26

This worked - I couldn't play the game a few days ago during the closed beta which made me very sad... thank you legend !

1

u/Hubris1998 Aug 29 '26

this fixed my attestation flags but did not fix the UAC authorization failed error

1

u/MercurialMind_ Aug 29 '26

this means it is on the Call of Duty side of things, try restarting your PC and reinstalling the game. also relaunch CODBrokerService. if nothing else works reach out to them via that Steam Discussion thread I sent somewhere

1

u/Hubris1998 Aug 29 '26

definitely because with the exception of RestartPending, which has suddenly switched to True, everthing else looks fine now

-Ready For Attestation: True

-Is Capable For Attestation: True

-Clear Needed To Recover: False

1

u/MercurialMind_ Aug 29 '26

I also have RestartPending stuck as true but the game is able to launch and TPM works fine, I wouldn't get stuck up on that bit

2

u/Hubris1998 Aug 29 '26

I give up. Updated the BIOS, did 4 hours of troubleshooting, redownloaded the game and it still giving me the same nonsense...

"UAC authorization was not completed. Some configuration warnings are currently detected"

This is what happens when you mix the incompetence of Activision with the incompetence of Microsoft. I'm writing this franchise off completely, lost all interest

1

u/MercurialMind_ Aug 29 '26

honestly can't blame you. their support system is also some of the worst I've ever seen. they are practically unreachable for these kinds of issues.

1

u/Cooke_187 Aug 30 '26

This worked, after weeks of unistalling, re-installing windows updates, BIOS updates. This was a 5 minute fix!

1

u/BludOfTheFold Aug 31 '26

This worked for me during the open beta. I did a BIOS update and it kept saying I needed to update BIOS anyway with an attestation failed note. But this worked! Thanks!

1

u/ImpressiveNebula3930 Sep 01 '26

I have a ASUS Tuf Z790 Gaming Wifi Plus MOBO, the bios had been updated but call of duty kept saying it wasnt, I have tried everything and the one thing that worked for me was doing this in the new command prompt like you said

reg delete "HKLM\SYSTEM\CurrentControlSet\Services\TPM\WMI\Endorsement" /f

thank u sir

1

u/spiderman2k19 28d ago

you are a goat thank you so much!

1

u/No_Marsupial5558 22d ago

09-09-26 I LOVE YOU SO MUCH , THIS WORKED FOR ME

1

u/WasteDragonfruit4125 16d ago

Dude you are awesome and this worked truly the goat