Although nowhere to be found in the documentation all my machines deployed on 1709, have a value of 0x5 and the TPM is set to Full (not delegated).
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@lexios Thanks for raising this. I added that value to the topic.
Thank you Justinha, I saw your amendment.
"A value of 5 means discard the Full TPM owner authorization for TPM 1.2 but keep it for TPM 2.0."
The question is, how was this value populated as 5 and why is the TPM owner auth stored in the registry by default?
On 1607, this was supposedly changed as per below:
https://docs.microsoft.com/en-us/windows/security/hardware-protection/tpm/change-the-tpm-owner-password
"Starting with Windows 10, version 1607, Windows will not retain the TPM owner password when provisioning the TPM. The password will be set to a random high entropy value and then discarded."
@lexios Sorry Alexander I got this update wrong. I'm working on improved text with the engineering team. ETA to publish that is Monday.
AndreaBichsel closed the case without it being resolved.
Reopening--sorry, I thought it had been resolved.
It's been a month. Any progress?
You can update this ticket since the information are now updated on another documentation page.
Thank you.
@lexios I should have notified here, but I'm glad you saw the update back on June 29.
on my windows 10 laptop , registry sets by default , why its happened to me.
OSManagedAuthLevel to 5