Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Intune»Windows AutoPilot Securing your hardware Failed 0x800705b4
    Intune

    Windows AutoPilot Securing your hardware Failed 0x800705b4

    Peter KlapwijkBy Peter KlapwijkAugust 19, 2019Updated:December 3, 2019132 Mins Read

    In this post I just want to share some information about Windows AutoPilot, more specific the Device preparation phase.

    During our testing with Windows AutoPilot self-deploying mode on our internal network, we run into an error during the Device Preparation phase:
    Securing your hardware (Failed 0x800705b4)

    Error 800705b4 is usually related to the TPM chip, but doesn`t exactly tell what is wrong with it. As we were testing self-deploying mode on pretty modern hardware, we checked the TPM attestation and that showed Ready as expected. After that we switched network to an unrestricted line (our internal network is restricted) and we found out self-deploying mode was working fine. So our issue should be network related. As we already whitelisted all the url`s we could find in the AutoPilot documentation from Microsoft, we were pretty curious what url`s we missed. After some testing we found a few url`s which pointed to two hardware vendor domains:
    intel.com
    nuvoton.com

    After we have whitelisted those domains from both vendors on the internetal network, we could succesfully deploy the same piece of hardware using Windows AutoPilot self-deploying mode on our internal network.

    It seems that not all hardware is shipped with the TPM certificate pre-installed and therefor during the TPM attestation proces the vendor website is contacted to get this certificate. On Michael Niehaus his blog about TPM attestation (found here, must read) there is a remark about a remote server which is contacted during the TPM attestation proces and that seems to be a site of a hardware vendor and not (only) a Microsoft site.
    We (I) wasn`t aware of that, maybe you were not aware of that, so that`s why I wanted to share this small piece of info. Hope you can take advantage of it.

    Happy testing!

    Autopilot Azure AD EMS Intune MEM Microsoft 365 Microsoft Endpoint Manager WD ATP Windows10
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Use an ATKey.Pro security key with multiple accounts

    November 23, 2020

    Configure macOS FileVault with Microsoft Intune

    August 15, 2019

    Easily deploy Office Pro Plus with Intune

    July 25, 2017
    View 13 Comments

    13 Comments

    1. Deepak on March 4, 2020 15:07

      I am facing the same issue, it works fine on open network but tpm attestation always fails on corporate network , it’s a surface pro 4 , could you please help which are the culprit urls that are not accessible on corporate network

      Reply
      • Peter Klapwijk on March 5, 2020 08:15

        First make sure the device is Attestation Ready. You can see that on a device in Windows Security, under Device Security, Security Processor. If the device supports this and that is fine. You have to check on the network level what URLs are blocked.

        Reply
        • deepak on April 1, 2020 13:55

          device attestation states ready , i also tried a fiddler trace , but was unable to capture the affected URLs , appreciate if you can share how you guys identified the blocked urls

          Reply
    2. Peter Klapwijk on April 1, 2020 14:23

      Our network guys helped us out.
      They provided us logging which showed a couple of blocked URLs which we whitelisted.

      But if you have a look at Windows security, Security processor details, the manufacturer of the TPM is shown.

      Reply
    3. mike on July 28, 2020 00:45

      Can someone help me out? I am getting an error 0x081039020 Securing your hardware. using Self deployment mode, Everything seems correct on the Dell Latitude 3189. I deleted all the devices from intone and azure and reimported them but no luck. Has anyone came across this error before? I have it on about 10 devices already. Thanks in advance

      Reply
      • Peter Klapwijk on July 28, 2020 08:12

        Don`t recognize the error. But make sure nothing is wrong with the TPM chip and update the drivers of the devices to the latest and try again.

        Reply
      • Tor Marius on May 27, 2021 13:32

        Hi,
        did you find a solution on this problem?

        Reply
    4. Dalton Reeves on August 24, 2020 17:54

      Im getting this error with trying to selfdeploy a Surface Laptop 3. Get the 0x800705b4 on the securing hardware step. Occurs on a an open network and at the office.

      Reply
    5. huub kop on October 6, 2020 10:44

      Hi eceryone, since thursday oct 1e we do get error 0x800705b4, hence we do autopilot over private internet connection, so, there are no url blockings. The laptop is a HP 430 G7 with TPM enabled.

      Reply
    6. Patrick on January 27, 2021 17:54

      Seeing the same issue (error securing hardware – 0x81039024) with a Lenovo Thinkpad X1 – 5th gen on a LAN connection connected to a router without any filtering enabled. AzureADJoined device with Intune MDM and Autopilot selfdeploy…

      Reply
    7. Arvind Sharma on July 1, 2021 10:46

      I am trying to deploy Intune on a co-operate device. Hardware ID is enrolled at azure portal already. It fails before device setup with error 0x800705b4 at Preparing your device for mobile management. Any suggestions…?

      Reply
      • Arvind Sharma on July 1, 2021 11:02

        Hi.. It’s me Arvind again. I am using my home network, so ideally there must not be a issue with internet. Do you recon, Updating Bios or resetting TPM would help?? By the way it’s a Lenovo T490S machine.

        Reply
        • Peter Klapwijk on July 2, 2021 11:07

          Hi Arvind,

          It’s always advised to update the drivers, also to prevent other issues during enrollment.
          And make sure the device is Attestation Ready. You can see that on a device in Windows Security, under Device Security, Security Processor.

          Reply
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Hard drive and partitions are not shown while installing Windows

    October 14, 2025

    Intune compliance for Windows 365 Cloud PCs

    September 12, 2025

    Intune connector for Active Directory configuration error

    August 29, 2025

    Deploy Microsoft Defender updates in deployment rings

    July 4, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Awards
    Sponsor
    Follow me on Twitter
    Tweets by inthecloud_247
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Defender Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Archives
    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Luis on Application installation issues; Download pending
    • AndrewWak on Issues syncing SharePoint Online libraries with OneDrive for Mac
    • Peter Klapwijk on Deploy Microsoft Defender updates in deployment rings
    • Magnus on Deploy Microsoft Defender updates in deployment rings
    • Gertjan Jongeneel on Add an Azure AD group to the local administrators group with Microsoft Intune
    most popular

    Application installation issues; Download pending

    October 1, 2024

    How to change the Windows 11 language with Intune

    November 11, 2022

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Recent Comments
    • Luis on Application installation issues; Download pending
    • AndrewWak on Issues syncing SharePoint Online libraries with OneDrive for Mac
    • Peter Klapwijk on Deploy Microsoft Defender updates in deployment rings
    • Magnus on Deploy Microsoft Defender updates in deployment rings
    • Gertjan Jongeneel on Add an Azure AD group to the local administrators group with Microsoft Intune
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

    Copyright © 2023 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved. No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand: Don’t pass off my work as yours, it’s not nice.

    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}