Recently in my lab, i ran into an issue with the Host TPM Attestation Alarm being set. This was a little annoying that out of the box there are some configuration items that are not done by standard, and this guide will cover the specific BIOS / RBSU Configs that need to be made to clear this up. First off, we need to boot into the BIOS / System Config / RBSU, so unfortunately you need to reboot your host - none of these changes can be made through the ILO "I reboot now - Good luck everybody else" Next up, we need to navigate to Server Security and Secure Boot Settings Next up, Select "Attempt Secure Boot" and accept the warning regarding the required reboot. Navigate back to the main "Server Security" Menu and Select Trusted Platform Module Options Ensure you have the below Config: Current TPM Type: TPM 2.0 Current TPM 2.0 Active PCRs: SHA256 Only TPM 2.0 Operation: No Action UNLESS your current TPM Type is not 2.0 - change to TPM ...