Event ID - 514

Event Id514
SourceMicrosoft-Windows-TPM-WMI
DescriptionFailed to backup TPM Owner Authorization information to Active Directory Domain Services. Errorcode: %1
Event InformationAccording to Microsoft :
Cause :
The computer was not connected to organization's network
Resolution :
Connect to organization's network and recreate the TPM owner password
Connect the computer to a domain network
Connect to organization's network using one of the following methods:
  • Establish a wired connection at a physical site operated by organization
  • Connect using a wireless network provided by organization that connects to internal network.
  • If available connect remotely to organization's network by using a VPN
Then in order to force Windows to back up the TPM owner password to AD DS, recreate the TPM owner password using one of the following procedures.
Recreate the TPM owner password
To perform these procedures,must have membership in Administrators or must have been delegated the appropriate authority.
To recreate the TPM owner password, when know or have access to the existing owner password:
  1. Click Start, type tpm.msc in the Start Search box, and then press ENTER.
  2. If the User Account Control dialog box appears, verify the proposed action is correct, and then click Continue.
  3. Under Actions, click Change Owner Password.
  4. If you have a USB flash drive with the owner password:
    • Click I have a backup file with the TPM owner password.
    • Click Browse, locate the file, and then click Open.
    • Click Create new password.
  5. If you wish to type the owner password:
    • Click I want to type the TPM owner password.
    • Type the TPM owner password.
    • Click Create new password.
    • Click Automatically create the password.
  6. Click Save the password.
  7. Provide a file name or location, and then click Save.
  8. Click Change Password.
  9. Close the TPM Management console.
To recreate the TPM owner password, when do not know or have access to the existing owner password:
  1. Click Start, and then click Control Panel.
  2. Click Security.
  3. Click BitLocker Drive Encryption.
  4. If the User Account Control dialog box appears, verify the proposed action is correct, and then click Continue.
  5. If BitLocker is turned on, click Turn off BitLocker, and then click Disable BitLocker.
  6. Close the BitLocker Drive Encryption window.
  7. Click Start, type tpm.msc in the Start Search box, and then press ENTER.
  8. If the User Account Control dialog box appears, verify the proposed action is correct, and then click Continue.
  9. Under Actions, click Clear TPM.
  10. Click I do not have the TPM owner password.
  11. Click Restart.
  12. Follow the prompts presented in the pre-boot (BIOS) environment.These prompts vary by computer manufacturer.
  13. After the computer has restarted, log on as an administrator.
  14. Click Start, and then click Control Panel.
  15. Click Security.
  16. Click BitLocker Drive Encryption.
  17. If the User Account Control dialog box appears, verify the proposed action is correct, and then click Continue.
  18. In the BitLocker Drive Encryption window, click Turn On BitLocker.
  19. Click Restart.
  20. Follow the prompts presented in the pre-boot (BIOS) environment.These prompts vary by computer manufacturer.
  21. After the computer has restarted, log on as an administrator.
  22. The BitLocker Setup Wizard should resume.If it does not, repeat steps 14 to 18.
  23. Depending on the configuration of network and policies required by domain,may be presented with different options.Complete the wizard to enable BitLocker Encryption.
Cause :
The computer cannot reach a writable domain controller due to connectivity issues
Resolution :
Establish connectivity and recreate the TPM owner password
The following procedures describe the steps to troubleshoot a network connection and then create a new TPM owner password for backup to AD DS after connectivity has been restored.
Restore connectivity between the computer and the domain controllers
Note: The following procedures include steps for using the ping command to perform troubleshooting.Before performing these steps, check whether the firewall or IPsec settings on network allow ICMP traffic.ICMP is the TCP/IP protocol that is used by the ping command.
To perform this procedure,must have membership in Users or must have been delegated the appropriate authority.
To restore connectivity between the computer and the domain controllers:
  1. Determine at what point connectivity is failing, using network troubleshooting steps.
  2. Resolve any networking issues.If unable to discover or resolve the networking issue, contact a networking specialist or designated support contact.
  • Recreate the TPM owner password
  • Recreate the TPM owner password, when do not know or have access to the existing owner password (see the above steps)
Cause :
The computer is not a member of an AD DS domain
Resolution :
Join the computer to a domain and recreate the TPM owner password
The following procedures describe the steps required to join the computer to a domain and then to recreate the TPM owner password to cause it to be backed up to AD DS.
Join a domain
To perform this procedure,must have membership in Administrators or must have been delegated the appropriate authority.
To join a domain:
  1. Click Start, right-click Computer, and then click Properties.
  2. Under the heading Computer name, domain and workgroup settings click Change settings.
  3. If the User Account Control dialog box appears, verify the proposed action is correct, and then click Continue.
  4. Click Change.
  5. Select the Domain option.
  6. Type the name of the domain want to join in the text box.
  7. Click OK.
  8. In the Windows Security dialog box, type the name and password of a domain account that has permissions to join a computer to the domain, and then click OK.
  9. In the Computer Name/Domain Changes dialog box and then click OK.
  10. In the next Computer Name/Domain Changes dialog box and then click OK.
  11. In the System Properties dialog box, click Close.
  12. In the Microsoft Windows dialog box, click Restart Now.
  • Recreate the TPM owner password
  • Recreate the TPM owner password, when do not know or have access to the existing owner password (see the above steps)
Cause :
The AD DS domain has not been properly configured to store TPM passwords
Resolution :
Reconfigure AD DS and recreate the TPM owner password
Configuring domain involves verifying or extending your AD DS schema, correctly configuring permissions on directory objects and configuring clients with Group Policy or local policies to back up the recovery information.
Configure AD DS to back up BitLocker recovery information
These procedures describes the resources to help configure a domain to back up TPM owner passwords and the steps to re-create the TPM owner password for backup to AD DS after the domain has been configured.
To perform this procedure,must have membership in Domain Admins or must have been delegated the appropriate authority.
To configure AD DS to back up BitLocker recovery information:
  1. Review the information provided in "Configuring Active Directory to Back up Windows BitLocker Drive Encryption and Trusted Platform Module Recovery Information".
  2. Use the scripts provided to configure domain correctly.
Note: We recommend that first test the new configuration in a test environment.
  • Recreate the TPM owner password
  • Recreate the TPM owner password, when do not know or have access to the existing owner password (see the above steps)
Reference LinksEvent ID 514 from Microsoft-Windows-TPM-WMI

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.