• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
HP ProBook 450 G8 Notebook PC (1A888AV)

Hello HP Support,

I am using an HP ProBook 450 G8 Notebook PC, and I am trying to enable or provision the Secure Platform Module (SPM) in order to use features that require TPM functionality (such as BitLocker or Windows 11 requirements).

My BIOS is up to date (T70 Ver. 01.21.00, dated April 9, 2024) and I have attempted to provision the SPM using the HP CMSL tool and the Set-HPSecurePlatformPayload command with the official spm-enable.bin payload.

Although the command executes successfully, the SPM state remains NotProvisioned, and the BIOS does not provide any option to enable or configure TPM/SPM manually. The tpm.msc utility in Windows also reports "Compatible TPM cannot be found."

I understand that my warranty has expired, but I would like to confirm:

  1. Whether my specific device model and serial number supports SPM provisioning.

  2. If it is currently firmware-locked from provisioning, or if there are additional tools or steps that can help enable it.

  3. Whether any paid service is available to perform this provisioning if needed.

If you need any additional information (such as serial number, system logs, or screenshots), please let me know — I am happy to provide whatever is required to assist in resolving this issue.

Any guidance you can provide would be greatly appreciated.

Thank you in advance for your help.

Best regards,

3 REPLIES 3
HP Recommended

@Tcoder 

 

Please read the following document first

 

           https://developers.hp.com/hp-client-management/blog/hp-secure-platform-management-hp-client-manageme...

 

Then use

 

       https://developers.hp.com/hp-client-management/blog/hp-sure-admin-step-step

 

Regards.

 

BH
***
**Click the KUDOS thumb up on the left to say 'Thanks'**
Make it easier for other people to find solutions by marking a Reply 'Accept as Solution' if it solves your problem.




HP Recommended

I am trying to provision Secure Platform Management (SPM) on my HP ProBook 450 G8 (BIOS version T70 Ver. 01.21.00) using the HP Client Management Script Library (CMSL).

Here are the steps I followed:

  1. Generated the endorsement key (kek.pfx) and signing key (sk.pfx) certificates using OpenSSL.

  2. Verified the current Secure Platform Management state using Get-HPSecurePlatformState, which showed NotConfigured.

  3. Attempted to provision the Endorsement Key and Signing Key using:

    • New-HPSecurePlatformEndorsementKeyProvisioningPayload and Set-HPSecurePlatformPayload

    • New-HPSecurePlatformSigningKeyProvisioningPayload and Set-HPSecurePlatformPayload

During the signing key provisioning step, I received this error:
"The request was not accepted by the BIOS."

I have not disabled the Physical Presence Interface (PPI), and after rebooting the device, the Secure Platform Management state still shows as NotConfigured.

Also, the BIOS does not show any option named “Secure Platform Management,” and running the PowerShell command Get-HPBIOSSettingValue -Name "Secure Platform Management" returns a "Setting not found" error.

TPM is not present or enabled on this device, as indicated by Get-TPM.

Could you please advise if the HP ProBook 450 G8 supports Secure Platform Management and what the correct procedure is to provision it? Also, how can I confirm if PPI needs to be disabled or if there are additional BIOS settings required?

Thank you for your assistance.HPPP.jpg

 

HP Recommended

Hi Tcoder

I used the steps on this HP website: https://developers.hp.com/hp-client-management/blog/hp-sure-admin-step-step

However, I was also getting the same error as you, even though I had disabled  Physical Presence Interface (PPI). And when I thought through the error, I figured that the command was being sent to BIOS and BIOS was refusing the instruction. 

Then I figured it out, its was the BIOS Administrator password. I disabled it and the command went through. Refere to the attached  Screenshot.

 

Please note that I did not have to repeat the commands to create the payload files because I had created them previously. Its just the "Set-..." commands that were giving me errors, hence why I am showcasing these. Now I will reboot.

 

Maskiri_0-1757612047515.png

 

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.