What is TPM attestation and should we enable it in Intune?
TPM attestation is the check that a laptop is actually the laptop it claims to be, not a virtual machine or a compromised device with a spoofed identifier. For SMBs running Intune and Conditional Access, it is a free extra layer.
Try this first
- 1Check in Intune that devices have TPM 2.0. Endpoint security, Hardware, or via a DeviceHealth report. Windows 11 already requires TPM 2.0, Windows 10 laptops from 2018 onwards usually have it too.
- 2Enable Health Attestation in Intune under Compliance policies, Windows 10/11. Requirements: BitLocker on, Secure Boot on, Code integrity on. A device that does not report any of these falls out of compliance.
- 3Tie the Compliance policy to a Conditional Access policy: Require device to be marked as compliant. From then on, a laptop without a healthy TPM cannot reach Microsoft 365.
- 4Test on your own laptop before broad rollout. A legitimate laptop with an odd driver stack can fail unexpectedly, better to find that yourself than via a flood of tickets.
- 5For BYOD: TPM attestation requires enrolment, which clashes with BYOD-without-MDM. There you pick between MAM-only or an extra MFA layer, not TPM.
When to bring us in
If you use virtual Windows desktops (AVD, Windows 365), confirm the virtual TPM implementation matches. Some older images fail TPM attestation and lock users out without you noticing.
See also
- I think I clicked a phishing linkNo shame, happens to everyone. The next fifteen minutes matter.
- A colleague's account is acting strangelySending mail in their name, rules hiding folders, unusual sign-ins. Suspicious.
- Lost the MFA app: new phone, no backup codesClassic problem after a phone upgrade. You are not the first to be locked out.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.