How many times is too many?
After a device is locked, what options do Intune/MDM admins have to "unlock" it?
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
If the key is generated in a TPM2.0, the hardware anti-hammering behavior of the TPM allows 32 PIN attempts before locking out. Once the TPM locks out, there is a cool down period of 10 minutes before another attempt can be made. The OS will allow 5 attempts before forcing the user to reboot to allow more attempts.
TPM1.2 behavior is manufacturer specific.
If a TPM is locked out it can be reset by an admin, but this will destroy all of the keys protected by the TPM. For more information about TPM lockout behavior see https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/manage-tpm-lockout
Tested this with VM.
Most helpful comment
If the key is generated in a TPM2.0, the hardware anti-hammering behavior of the TPM allows 32 PIN attempts before locking out. Once the TPM locks out, there is a cool down period of 10 minutes before another attempt can be made. The OS will allow 5 attempts before forcing the user to reboot to allow more attempts.
TPM1.2 behavior is manufacturer specific.
If a TPM is locked out it can be reset by an admin, but this will destroy all of the keys protected by the TPM. For more information about TPM lockout behavior see https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/manage-tpm-lockout