Hi Bala Siva Sai Akhil Malepati,
Thank you for your patience.
Could please confirm if you are using Microsoft Azure Attestation (MAA) for performing SGX attestation?
As i checked with our internal team here is the response:
- THIM stores all the Trusted Computing Base (TCBs) published by Intel to date in its storage and, by default, provides the minimum TCB that is supported based on the version and the FMSPC of the machine. In this case, THIM is returning the minimum supported TCB value, which is 14, whereas Intel provides a TCB value of 16, the latest TCB value released by Intel.
- The default TCB baseline from THIM lags the latest baseline offered by Intel to prevent any attestation failure scenarios for ACC customers who require more time for patching platform software (PSW) updates. If a customer prefers to perform the SGX attestation against the latest TCB offered by Intel, they can perform timely roll out of platform software (PSW) updates and use the custom TCB baseline enforcement feature offered by Microsoft Azure Attestation (MAA)
MAA offers the custom TCB baseline enforcement feature which empowers customers to perform SGX attestation against a desired TCB baseline. It is always recommended for Azure Confidential Computing (ACC) SGX customers to install the latest PSW version supported by Intel and configure their SGX attestation policy with the latest TCB baseline supported by Azure.
Please find more details here - Custom TCB baseline enforcement for Azure Attestation users | Microsoft Learn
If the information is helpful, please consider by clicking the "Accept Answer & Upvote" on the post.