PaulWoodward
Member
Both Parallels and Microsoft are partly responsible. I now know Microsoft turned on a newer, more robust TPM attestation method in the July update. It's called AIKv2, and it is coming back at some point. On newer hardware, this generally works fine, but older TPM implementations, such as the older model laptops where I work, this broke. In the face of widespread issues it seems Microsoft have now used the Controlled Feature Rollout (CFR) mechanism to disable the AIKv2 enforcement, and I'm now seeing some success with the previously affected laptops. There is speculation that MS did not intend to enforce AIKv2 this month, just ship the code for later enablement, but who knows? If Parallels had proactively updated their vTPM to be compatible with the more robust AIKv2, this would have been a non-issue. Given the work Parallels just did recently to finally get the new Secure Boot certificates working properly, which included updating the virtual firmware, it's disappointing they didn't future proof the TPM at the same time. Although CFR is able to roll back the specific change, there is no official way for an Admin to control or even tell what CFR is doing, which new features are enabled or disabled. But there is a chance that affected Parallels VMs may get the CFR update from MS to disable AIKv2, and return to the non-broken statre. I'll be trying this out today, if time allows.