This thread was automatically locked due to age.
This sounds like two issues - TPM lockout AND the cert issue. The cert issue (which you've done what I'd recommend) should be resolved now you've deleted their old cert with their outdated cached creds. However this is not associated with the constant request for the RK.
This is probably caused by a key protector missing - or the TPM being locked out.
A device must have TWO key protectors really - Normally this is TPM chip AND the numerical password (the recovery key)
If a laptop keeps prompting for the recovery key then the other protector is not useable/visable.
This can happen when the TPM locks out (normally from too many failed attempts with the PIN) or the key protector has been removed.
Once logged on (hopefully you've fixed the cert issue, and you'll not see that!) please run an elevated cmd prompt (Admin command prompt)
Type
manage-bde -status c:
This assumes your HDD IS C (most are but substitute if not)
This will list a few things but include your Key Protectors.
Please paste this back into this thread. It'll look a bit like this....(graphic from MS - note they've missed off the drive letter so it'll list all encrypted drives, not just C like I specified.
If there's only Numerical password listed (this is the recovery key) then this is the issue, but lets try and do one step at a time!
This sounds like two issues - TPM lockout AND the cert issue. The cert issue (which you've done what I'd recommend) should be resolved now you've deleted their old cert with their outdated cached creds. However this is not associated with the constant request for the RK.
This is probably caused by a key protector missing - or the TPM being locked out.
A device must have TWO key protectors really - Normally this is TPM chip AND the numerical password (the recovery key)
If a laptop keeps prompting for the recovery key then the other protector is not useable/visable.
This can happen when the TPM locks out (normally from too many failed attempts with the PIN) or the key protector has been removed.
Once logged on (hopefully you've fixed the cert issue, and you'll not see that!) please run an elevated cmd prompt (Admin command prompt)
Type
manage-bde -status c:
This assumes your HDD IS C (most are but substitute if not)
This will list a few things but include your Key Protectors.
Please paste this back into this thread. It'll look a bit like this....(graphic from MS - note they've missed off the drive letter so it'll list all encrypted drives, not just C like I specified.
If there's only Numerical password listed (this is the recovery key) then this is the issue, but lets try and do one step at a time!