Skip to content
TroubleGrid

Call of Duty "Failed Attestation Status" when TPM 2.0 and Secure Boot are already on

Last verified October 2026Tested against Call of Duty: Modern Warfare 4, Call of Duty: Black Ops 7, Call of Duty: Warzone, Windows 10 version 22H2 and later, Windows 11, Secure Attestation Wizard 1.2.0 (16 September 2026)Well documented

"Failed Attestation Status" is not a ban and usually not a Secure Boot problem. It means Activision's attestation check did not pass, and the single most useful thing you can do is run Activision's own Secure Attestation Wizard, which names the exact reason. Two of the seven reasons it reports are fixed in minutes from inside Windows. The hardest one, "BIOS Firmware Update Required", points at your motherboard's TPM firmware rather than anything you can toggle — and on AMD boards reporting Manufacturer Version 3.*.0.*, Activision says the board needs a firmware update from its maker. Ignore advice about PCR7.

Modern Warfare 4, Black Ops 7 and Warzone all require TPM 2.0 and Secure Boot. The frustrating case is the one where you have already checked both, msinfo32 says Secure Boot State is On, tpm.msc says the TPM is ready, and the game still restricts you. That is because attestation checks more than those two switches, and the generic advice circulating for this error — clear the TPM, chase a PCR7 value, flash any BIOS you can find — mostly addresses things the check does not look at. This page works the notice Activision's own tool gives you, in the order that costs you least.

Symptoms

  • An in-game notification that your system does not meet the security requirements, or a "Failed Attestation Status" message
  • In Modern Warfare 4, every online game mode is unavailable
  • In Black Ops 7 and Warzone, Ranked Play and some playlists are unavailable, and you may be placed in a separate matchmaking pool
  • msinfo32 reports Secure Boot State: On and BIOS Mode: UEFI, yet the game still reports a failure
  • tpm.msc reports "The TPM is ready for use" but attestation still does not pass
  • The Secure Attestation Wizard reports "BIOS Firmware Update Required" on a board already running its latest published BIOS

Why this happens

The board's TPM firmware is on a version Activision rejects

The attestation check looks at the TPM's firmware version, not just whether a TPM is present and enabled. Activision states that AMD boards reporting TPM Manufacturer Version 3.*.0.* are not compatible with the applicable Call of Duty titles and require a firmware update to meet compliance, and that Intel systems reporting INTC 302.12.*.* or INTC 303.12.*.* may require one. This is why a PC that passes every check in Windows can still fail: the fix lives in a motherboard BIOS release, and whether one exists is up to the board maker.

If the notice is "BIOS Firmware Update Required", check your TPM Manufacturer Version

Windows is installed in Legacy/MBR mode, so Secure Boot can never report On

Secure Boot requires UEFI boot mode and a GPT system disk. If Windows was installed in Legacy (CSM) mode on an MBR disk, the Secure Boot option may not even appear in firmware, and enabling it changes nothing. Activision requires BIOS boot mode to be UEFI rather than Legacy and the partition style to be GPT rather than MBR, and the wizard reports this as "Boot Partition not set to GPT" or "BIOS Boot mode not set to UEFI".

If the notice is about GPT or UEFI, convert the disk and switch the firmware

The wizard could not get the UAC approval it needs to enrol the attestation key

The check enrols an attestation identity key, which needs an elevation prompt to be approved. Activision documents "Authorization Key Failed" as meaning the scan could not obtain User Account Control authorization, and notes that on first launch you may be asked to approve CODBrokerInstaller.exe or enrollaik.exe — declining blocks play. This looks like a hardware failure and is not one.

If the notice is "Authorization Key Failed", approve the elevation prompt

Windows is out of date, so the boot event log the check reads is rejected

Attestation reads the TCG event log that firmware and Windows produce during boot. Activision documents "TCG Event Log Failed" as meaning your version of Windows is out of date, with the remedy being to restart and install the latest Windows update. Nothing in firmware needs touching for this one.

If the notice is "TCG Event Log Failed", update Windows

Fixes

Run Activision's Secure Attestation Wizard and read the notice

about 5 min

There are seven distinct reasons attestation fails and they have different fixes. The wizard tells you which one you have, so you are not guessing.

Applies to: Windows 10 version 22H2 and later, Windows 11

  1. Download the Secure Attestation Wizard from Activision's TPM and Secure Boot support article. The current build is version 1.2.0, dated 16 September 2026, and arrives as a .zip.
  2. Extract the .zip, then run CODSecureAttestationWizard.exe, accept the terms and run the scan. The display language can be changed under Settings.
  3. Read the result. It will report one of: "TPM 2.0: Not Enabled", "Secure Boot: Not Enabled", "Boot Partition not set to GPT", "BIOS Boot mode not set to UEFI", "BIOS Firmware Update Required", "Authorization Key Failed" or "TCG Event Log Failed".
  4. Note which one you got and go to the matching step below. If the wizard reports you are compliant, Activision says you can delete it.
  5. One result is worth reading carefully rather than panicking over: "BIOS Firmware Update Required" means your firmware does meet the minimum requirements but an update is recommended and may be required in future. On its own it is not the same as being told your hardware is unsupported.

Confirmed by the vendor.

Source: Activision Support

Confirm what Windows itself reports

about 5 min

Three one-line checks tell you whether the problem is a switch you can flip or something deeper, before you open a firmware menu at all.

Applies to: Windows 10 version 22H2 and later, Windows 11

  1. Press Windows+R, enter tpm.msc and look for "The TPM is ready for use". While you are there, note the Manufacturer Version — you need it for the firmware step below.
    tpm.msc
  2. Press Windows+R and enter msinfo32. BIOS Mode should read UEFI and Secure Boot State should read On.
    msinfo32
  3. Open Disk Management (diskmgmt.msc), right-click the system disk, choose Properties and open the Volumes tab. Partition style should read GPT.
    diskmgmt.msc
  4. If you prefer PowerShell for the Secure Boot check, Confirm-SecureBootUEFI should return True.
    Confirm-SecureBootUEFI
  5. If all three read correctly — TPM ready, UEFI, Secure Boot On, GPT — then the two switches everyone tells you to check are not your problem, and you should be working the specific wizard notice instead.

Confirmed by the vendor.

Source: Activision Support, Microsoft Learn

If the notice is "TCG Event Log Failed", update Windows

about 30 min

Activision documents this notice as meaning Windows is out of date, which makes it the cheapest failure on the list to clear.

Applies to: Windows 10 version 22H2 and later, Windows 11

  1. Restart the PC. Activision's remedy for this notice begins with a restart, not with a settings change.
  2. Open Settings > Windows Update, install every pending update and restart again when asked.
  3. Re-run the Secure Attestation Wizard. Note that Call of Duty requires Windows 10 version 22H2 or later, or any version of Windows 11 — on an older Windows 10 build, the feature update is the fix.

Confirmed by the vendor.

Source: Activision Support

If the notice is "Authorization Key Failed", approve the elevation prompt

about 5 min

This one is a declined or missing UAC prompt rather than a hardware fault, and it is cleared from inside the wizard.

Applies to: Windows 10 version 22H2 and later, Windows 11

  1. In the wizard, select Generate Key.
  2. When Windows asks for permission to run enrollaik.exe, approve it and select Yes so your TPM 2.0 settings can be validated. Declining is what produced the notice.
  3. If no prompt appears at all, check your User Account Control notification setting — Activision documents adjusting it for exactly this case — then try Generate Key again.
  4. Launching the game may also ask you to approve CODBrokerInstaller.exe. Declining that blocks play, so accept it.

Confirmed by the vendor.

Source: Activision Support

Stop chasing PCR7 "Binding not possible" — it is working as designed

about 5 min

This is the most common wasted detour on this error. PCR7 is a BitLocker binding detail, it is not one of the things Activision's check reports on, and both Microsoft and Dell document the message as expected behaviour.

Applies to: Windows 10 version 22H2 and later, Windows 11

  1. If msinfo32 shows PCR7 Configuration as "Binding not possible", note that this is about BitLocker, not about Call of Duty. It means Windows cannot bind BitLocker to PCR7 and uses TPM profile 0, 2, 4, 11 instead.
  2. Microsoft states plainly that Windows is secure whether TPM profile 0, 2, 4, 11 or profile 7, 11 is used. Dell documents the same message as working as designed according to Microsoft, and says Microsoft recommends using PCR 0, 2, 4, 11.
  3. The usual cause is benign: BitLocker only accepts the Microsoft Windows PCA 2011 certificate for early boot components, and anything else in the measured boot chain — commonly a third-party option ROM on a graphics, network or storage card — pushes it onto the other profile. Desktops with add-in cards hit this; laptops with the option ROM built into system BIOS often do not.
  4. None of the seven notices Activision's wizard reports is about PCR7. So treat a "Binding not possible" reading as noise for this problem and go back to the notice the wizard actually gave you.

Confirmed by the vendor.

Source: Microsoft Learn, Dell, Activision Support

If the notice is "BIOS Firmware Update Required", check your TPM Manufacturer Version

Advancedabout 45 min

Activision names specific TPM firmware versions as non-compliant. The remedy is a motherboard BIOS release containing newer TPM firmware, which only the board maker can supply.

Applies to: AMD systems reporting TPM Manufacturer Version 3.*.0.*, Intel systems reporting INTC 302.12.*.* or INTC 303.12.*.*

Before you do this

A firmware update is the riskiest ordinary thing you can do to a PC: an interrupted flash can leave the board unable to boot. Use only the firmware your board maker publishes for your exact model, use their own flashing tool, and do not flash during an unstable power supply. Firmware changes also alter the measured boot state, so if BitLocker or device encryption is on, save your recovery key first — you may be asked for it on the next boot.

First:

  • Your exact motherboard or PC model number, and the firmware version you are currently on
  • Your BitLocker or device encryption recovery key saved somewhere off the PC, if encryption is enabled
  • Mains power, and on a laptop a charged battery
  1. Open tpm.msc and read the Manufacturer Version under Manufacturer Information.
    tpm.msc
  2. On AMD, if it reads 3.*.0.*, Activision states these boards are not compatible with the applicable Call of Duty games and require a firmware update to meet compliance. On Intel, INTC 302.12.*.* or INTC 303.12.*.* may require one.
  3. Go to your motherboard or PC maker's support page for your exact model and look for a BIOS release that mentions updated TPM or fTPM firmware. Activision's guidance is to ask the manufacturer whether an update is available, rather than to flash anything you can find.
  4. Update using the maker's own documented method for your board — most now support flashing from a USB stick in firmware itself. Follow their instructions, not a generic guide.
  5. After updating, re-check tpm.msc, confirm Secure Boot is still On in msinfo32, then re-run the wizard.
  6. If you are already on the newest published BIOS and still fail, there may be no fix available to you yet: the required TPM firmware has to reach a BIOS release for your board first. Activision's documented route here is the manufacturer — for Lenovo it asks players to raise a support ticket, and says that if you have updated the BIOS and still fail, contact Lenovo so they can provide the correct firmware for your PC. Activision also invites players to report persistent failures so studios can work with hardware makers.

Confirmed by the vendor.

Source: Activision Support

If the notice is about GPT or UEFI, convert the disk and switch the firmware

Can cause data lossabout 60 min

Secure Boot cannot be enabled on a Legacy/MBR install at all, so this is the only route for those machines — and it is the one step on this page that cannot be undone.

Applies to: Systems where msinfo32 reports BIOS Mode: Legacy, Systems where the system disk partition style is MBR

Before you do this

This repartitions your system disk and cannot be reversed. Converting without then switching the firmware to UEFI leaves the PC unbootable. Do not run this on a machine that already reports GPT and UEFI, and do not run it at all without a current backup and, if encryption is enabled, your recovery key.

First:

  • A current, verified backup of anything on the disk you cannot lose
  • Your BitLocker or device encryption recovery key saved off the PC, with protection suspended before you start
  • Confirmation that the motherboard supports UEFI boot
  • A successful mbr2gpt /validate run before attempting the conversion
  1. Confirm this is actually your situation: Disk Management shows the system disk as MBR, or msinfo32 shows BIOS Mode as Legacy. If it already reads GPT and UEFI, do not run this.
  2. Back up anything you cannot lose. Microsoft's own tool prints "If conversion is successful the disk can only be booted in GPT mode. These changes cannot be undone!" before it proceeds.
  3. If BitLocker or device encryption is on, suspend protection first. MBR2GPT returns code 6 and refuses to run if a volume on the disk is encrypted, and Microsoft notes that resuming BitLocker afterwards requires deleting and recreating the existing protectors.
  4. Check the disk is eligible before changing anything. MBR2GPT.EXE lives in Windows\System32 on any supported Windows version. From an elevated prompt, validate first — it reports eligibility without touching the disk. Validation needs at most three primary partitions, no extended or logical partitions, and one partition marked active and as the system partition.
    mbr2gpt /validate /allowFullOS
  5. Only if validation passes, convert. Note that when run from full Windows the existing MBR system partition cannot be reused, so the tool shrinks the OS partition to create a new 100 MB EFI system partition.
    mbr2gpt /convert /allowFullOS
  6. Before restarting into Windows, enter firmware setup and switch boot mode from Legacy/CSM to UEFI. Microsoft is explicit that after conversion the firmware must be reconfigured to boot in UEFI mode — skip this and the PC will not boot. Confirm the board supports UEFI before you begin.
  7. With the machine booting in UEFI mode, enable Secure Boot in firmware, then re-run the wizard. If a drive letter went missing, Microsoft notes the remapping runs after conversion and may need fixing by hand.

Confirmed by the vendor.

Source: Microsoft Learn, Activision Support

Known issues

  • AMD boards reporting TPM Manufacturer Version 3.*.0.* are stated by Activision to be incompatible with the applicable Call of Duty titles and to require a motherboard firmware update. Whether such an update exists depends on the board maker, so some systems have no fix available from the player's side.

    Affects AMD fTPM Manufacturer Version 3.*.0.* · Status: workaround only

  • Intel systems reporting Manufacturer Version INTC 302.12.*.* or INTC 303.12.*.* may require a motherboard firmware update, per Activision's support article.

    Affects Intel PTT INTC 302.12.*.*, Intel PTT INTC 303.12.*.* · Status: workaround only

If none of this worked

If the wizard reports you are fully compliant and the game still restricts you, this page is not your problem — that is a game or account-side issue, not a firmware one. If the wizard reports "BIOS Firmware Update Required" on a board that is already running its newest published BIOS, there may genuinely be nothing you can do yet: the updated TPM firmware has to appear in a BIOS release for your model first, and Activision's own guidance at that point is to contact the manufacturer and to report the failure so studios can work with hardware makers. Note also that this page covers the attestation check only. A restriction that arrived with a ban notice, or that applies to a single account on a PC where another account plays fine, is something else entirely.

Common questions

Is "Failed Attestation Status" a ban?
No. It is a hardware attestation result, not a disciplinary action. Activision describes it as a notification shown when a system does not meet the security requirements. The consequence is restricted access rather than a ban: in Modern Warfare 4 you are restricted from playing any online game mode, while in Black Ops 7 and Warzone you lose certain modes including Ranked Play and certain playlists, and may be placed in separate matchmaking pools.
Should I clear the TPM to fix this?
Activision's support article does not list clearing the TPM among its remedies. Each of the seven notices it documents has its own specific fix — a Windows update, a UAC approval, a GPT conversion or a firmware update — so work the notice you actually got instead. Clearing a TPM changes the state that disk encryption is tied to, so if you use BitLocker or device encryption, do not do it without your recovery key saved somewhere off the PC.
My PCR7 says "Binding not possible". Is that why attestation fails?
There is no indication that it is. PCR7 binding is a BitLocker detail, and it is not one of the things Activision's wizard reports on. Microsoft states that Windows is secure whether BitLocker uses TPM profile 0, 2, 4, 11 or profile 7, 11, and Dell documents the "Binding Not Possible" message as working as designed, typically caused by a third-party option ROM on an add-in card appearing in the measured boot chain.
Do I need Secure Boot and TPM 2.0 for every Call of Duty game?
Activision's article names Modern Warfare 4, Warzone and Black Ops 7 as requiring both. The supported platforms are Windows 10 version 22H2 or later and any version of Windows 11, with TPM 2.0 provided by Intel PTT on 8th Generation or newer Intel CPUs, AMD CPU fTPM on Ryzen 2000 series or newer, or a discrete TPM.
Why does the game fail when Windows says Secure Boot is On?
Because attestation checks more than that one switch. It also depends on boot mode being UEFI, the system disk being GPT, the TPM's firmware version, a valid TCG boot event log, and an attestation key that could actually be enrolled. That is why the wizard reports seven distinct notices rather than a single pass or fail — and why the two switches most guides tell you to check can both be correct while the check still fails.

Did this fix work?

If a step is wrong, outdated, or did not help, telling us is the fastest way to get it corrected. Reports are reviewed before new articles.

Report a problem with this page

Related problems

Sources

  • Activision Support · Support page · checked Oct 10, 2026

    • Both TPM 2.0 and Secure Boot are required to play Call of Duty: Modern Warfare 4, Call of Duty: Warzone and Call of Duty: Black Ops 7.
    • For Modern Warfare 4, players who do not meet the requirements are restricted from playing any online game mode.
    • For Black Ops 7 and Warzone, non-compliant players are restricted from certain game modes including Ranked Play and certain playlists, and may be placed in separate matchmaking pools.
    • "Failed Attestation Status" is the name of the notification shown when a system does not meet the security requirements.
    • Activision publishes a Secure Attestation Wizard, version 1.2.0 dated September 16 2026, distributed as a .zip which is extracted and run as CODSecureAttestationWizard.exe.
    • The wizard scans the PC's BIOS information and reports one of: "TPM 2.0: Not Enabled", "Secure Boot: Not Enabled", "Boot Partition not set to GPT", "BIOS Boot mode not set to UEFI", "BIOS Firmware Update Required", "Authorization Key Failed" or "TCG Event Log Failed".
    • "BIOS Firmware Update Required" means the firmware meets the minimum requirements but an update is recommended and may be required in the future.
    • "Authorization Key Failed" means the scan could not obtain User Account Control authorization; the remedy is to select Generate Key and approve the UAC prompt for enrollaik.exe.
    • "TCG Event Log Failed" means the version of Windows is out of date; the remedy is to restart the computer and install the latest Windows update.
    • AMD boards reporting TPM Manufacturer Version 3.*.0.* are not compatible with applicable Call of Duty games and require a firmware update to meet compliance; players should ask their motherboard manufacturer whether an update is available.
    • Intel systems reporting Manufacturer Version INTC 302.12.*.* or INTC 303.12.*.* may require a motherboard firmware update.
    • TPM state is checked by running tpm.msc, which should report "The TPM is ready for use".
    • Secure Boot and boot mode are checked by running msinfo32, where BIOS Mode should read UEFI and Secure Boot State should read On.
    • Partition style is checked in Disk Management under the drive's Properties on the Volumes tab, which should read GPT.
    • Supported operating systems are Windows 10 version 22H2 or later, or any version of Windows 11.
    • TPM must be version 2.0: Intel requires 8th Generation or newer with Intel PTT, AMD requires Ryzen 2000 series or newer with AMD CPU fTPM; a discrete TPM is also referenced.
    • BIOS boot mode must be UEFI rather than Legacy, and the disk partition style must be GPT rather than MBR.
    • Lenovo prefers that players submit a ticket through its support website, and if the BIOS has been updated and attestation still fails, players should contact Lenovo directly for the correct BIOS firmware update.
    • On first launch players may be asked to approve CODBrokerInstaller.exe or enrollaik.exe, and declining blocks play.
    • Activision links Microsoft's MBR2GPT guidance for converting a disk from MBR to GPT, noting prerequisites including Secure Boot disabled, BitLocker off and no dual boot.
  • Microsoft Learn · Documentation · checked Oct 10, 2026

    • A PCR7 Configuration of "Binding not possible" in msinfo32 means Windows cannot bind BitLocker to PCR7, the Secure Boot measurement register, and BitLocker uses TPM profile 0, 2, 4, 11 instead.
    • BitLocker only accepts the Microsoft Windows PCA 2011 certificate for signing early boot components; any other signature on boot code causes BitLocker to use TPM profile 0, 2, 4, 11 rather than 7, 11.
    • Binaries signed with the UEFI CA 2011 certificate prevent BitLocker from binding to PCR7.
    • Microsoft states that Windows is secure regardless of whether TPM profile 0, 2, 4, 11 or profile 7, 11 is used.
    • Secure Boot state can be confirmed with the Confirm-SecureBootUEFI PowerShell cmdlet, which should return True.
    • In msinfo32 the expected healthy result is BIOS Mode reading UEFI and PCR7 Configuration reading Bound.
  • MBR2GPTOfficial

    Microsoft Learn · Documentation · checked Oct 10, 2026

    • MBR2GPT.EXE is located in the Windows\System32 directory on any device running a currently supported version of Windows, and converts a disk from MBR to GPT without modifying or deleting data on the disk.
    • The tool runs from Windows PE by default and is blocked from running in full Windows unless the /allowFullOS option is supplied.
    • The syntax is MBR2GPT /validate|convert [/disk:<diskNumber>] [/logs:<logDirectory>] [/map:<source>=<destination>] [/allowFullOS], where /validate only reports whether the disk is eligible.
    • The tool's own conversion output states "If conversion is successful the disk can only be booted in GPT mode. These changes cannot be undone!"
    • Microsoft states that after the disk has been converted to GPT partition style, the firmware must be reconfigured to boot in UEFI mode, and that the device must be confirmed to support UEFI before converting.
    • An MBR disk with BitLocker-encrypted volumes can be converted only while protection is suspended, and to resume BitLocker afterwards the existing protectors must be deleted and recreated.
    • Return code 6 means conversion failed because one or more volumes on the disk is encrypted.
    • Validation requires the disk to have at most three primary partitions, no extended or logical partitions, and one partition set as active and as the system partition.
    • When run from the full OS the existing MBR system partition cannot be reused, so a new 100 MB EFI system partition is created by shrinking the OS partition.
    • Drive letter remapping runs after the layout conversion, and Microsoft notes that at that stage the operation cannot be undone.
  • Dell · Knowledge base · checked Oct 10, 2026

    • Dell documents the PCR7 "Binding Not Possible" message as working as designed according to Microsoft, and describes it as expected behaviour rather than a defect.
    • The BIOS measures certificates from option ROMs to determine the PCR7 value, and if a third-party UEFI CA is present in that value the system does not allow PCR7 and asks for 0, 2, 4, 11 instead.
    • Systems with a PCI graphics, network, storage or other add-in card whose option ROM triggers this are affected, while laptops with the option ROM built into the system BIOS can still use PCR7.
    • Dell's stated resolution is that Microsoft recommends using PCR 0, 2, 4, 11.