This can happen after a hardware repair, TPM reset, or operating system reinstall.
The TPM’s current endorsement key (EK) does not match the EK stored in the database.
Here’s a helpful, user-friendly message you can display when a TPM endorsement key mismatch occurs, depending on your audience (end user, IT admin, or developer). Security Check Failed – TPM Key Mismatch
Your device’s security chip (TPM) is reporting a different endorsement key than what our system has on record.