Access Denied Error 0x80070005 message when initializing TPM for Bitlocker

Access Denied Error 0x80070005 message when initializing TPM for Bitlocker

  • Comments 5
  • Likes

 

Hello, my name is Manoj Sehgal. I am a Senior Support Engineer in the Windows group and today’s blog will cover How to initialize TPM successfully when you enable Bitlocker in Windows 7.

A common problem we have seen since the release of Windows 7 has been to initialize TPM successfully so that you can successfully turn ON Bitlocker. This is most likely due to incorrect permissions for the SELF account in AD for ms-TPMOwnerInformation attribute.

When you try to turn on Bitlocker on Windows 7 Operating System Drive, you may get the Access Denied Error message while initializing TPM.

image

Additionally, when you open the TPM Management Console and you try to initialize TPM you get error message 0x80070005.

image

NOTE: If you are using SCCM to build Windows 7 machines and using Bitlocker Task Sequencer you may see the following error message(s) logged in smsts.log for OSDbitlocker.

pTpm->TakeOwnership( sOwnerAuth ), HRESULT=80070005 e:\nts_sms_fre\sms\client\osdeployment\bitlocker\bitlocker.cpp,480)OSDBitLocker 3032 (0x0BD8)
Failed to take ownership of TPM. Ensure that Active Directory permissions are properly configured.
Access is denied. (Error: 80070005; Source: Windows) OSDBitLocker 3032 (0x0BD8)

Resolution:

To set correct permissions, follow the instruction below:

1. Open Active Directory Users and Computers.

2. Select the OU where you have all computers which will have Bitlocker turned ON.

3. Right Click on the OU and click Delegate Control.

image

4. Click Next and then click Add.

image

image

5. Type SELF as the Object Name.

image

6. Select create a custom task to delegate.

image

7. From the object in the folder, select Computer Objects.

image

8. Under show these permissions, select all 3 checkbox.

image

9. Scroll down in permissions and select the attribute Write msTPM-OwnerInformation.

image

10. Click Finish.

After you have done the above steps, you should be able to initialize TPM successfully.

More Information:

Backing Up BitLocker and TPM Recovery Information to AD DS

http://technet.microsoft.com/en-us/library/dd875529(WS.10).aspx

 

 

Author:

Manoj Sehgal
Senior Support Engineer
Microsoft Corporation

Your comment has been posted.   Close
Thank you, your comment requires moderation so it may take a while to appear.   Close
Leave a Comment
  • worked a treat.

    Thanks,

    Mark.

  • Hi Manoj,

    I get the same error when I try to start the service "Function Discovery Resource Publication".  The error message is "Windows could not start the Function Discovery Resource Publication service on local computer.  Error 0x80070005: Access is denied."

    I am trying to do this because I am trying to network my Win7 desktop to my Vista64 laptop.  On the win7 machine i could't turn Network Discovery on so this why I am trying to start this service.  

    Any help would be appreciated.

    Mark Sutton

  • Manoj

    Can i apply this to my OU on AD when am using MBAM ?

  • LIFE SAVER!!!!
    Thanks for posting this information! Worked like a charm :)

  • For WindowsXP Tech Support
    contact on 1-800-935-0537
    http://www.computertechsupport.us/
    (FREE CONSULT)