Windows 10: Can't enable BitLocker with TPM only

Discus and support Can't enable BitLocker with TPM only in Windows 10 Ask Insider to solve the problem; I'm having a hard time getting BitLocker to work the same way on my newly built desktop as it does on my Surface Pro 3, i.e. the drive is unlocked... Discussion in 'Windows 10 Ask Insider' started by /u/My-username-is-too-l, Jan 28, 2020.

  1. Can't enable BitLocker with TPM only


    I'm having a hard time getting BitLocker to work the same way on my newly built desktop as it does on my Surface Pro 3, i.e. the drive is unlocked instantly with the TPM and I go straight to the windows login screen.

    When I try to configure BitLocker it just wants me to plug in an USB-drive to configure it as a startup key. I don't get any other options whatsoever.

    I've activated and changed the group policy for startup so that all of the methods for unlocking are allowed. I also unchecked "Allow BitLocker without a compatible TPM".

    I tried changing the TPM only-option to "required" but I just get some error saying that there's a conflict with the startup options. Changing the options regarding a startup key to "do not allow" gives me another error saying that "the startup options are configured incorrectly".

    Is there another setting that I'm missing?!

    I initially tried doing this with the fTPM that comes with my Ryzen 5 3600. Since I wasn't able to get it to work I bought a separate Asus Tpm-chip for my Asus ROG B450-E motherboard, reinstalled windows and still got the same results.

    Not sure what other info is relevant, but I've enabled the TPMs in BIOS (not both at the same time), cleared both TPMs multiple times, installed the latest drivers for every component etc. Would greatly appreciate any help!

    submitted by /u/My-username-is-too-l
    [link] [comments]

    :)
     
    /u/My-username-is-too-l, Jan 28, 2020
    #1
  2. Yan.S Win User

    Bitlocker without TPM

    Hi there,

    I'm trying to use Bitlocker without TPM

    My version is Windows 10 Home, and I try to follow -

    To turn on BitLocker Drive Encryption on a computer without a compatible TPM



    1. Click Start, type gpedit.mscin the Start Search box, and then press ENTER.
    2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    3. In the Local Group Policy Editor console tree, click Local Computer Policy, click Administrative Templates, click Windows Components, and then clickBitLocker Drive Encryption.
    4. Double-click the setting Control Panel Setup: Enable Advanced Startup Options.
    5. Select the Enabled option, select the Allow BitLocker without a compatible TPM check box, and then click OK.
    You have changed the policy setting so that you can use a startup key instead of a TPM.

    1. Close the Local Group Policy Editor.
    2. To force Group Policy to apply immediately, you can click Start, typegpupdate.exe /forcein the Start Search box, and then press ENTER.
    3. Click Start, click Control Panel, click Security, and then click BitLocker Drive Encryption.
    4. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    5. On the BitLocker Drive Encryption page, click Turn On BitLocker. This will only appear with the operating system volume.
    6. On the Set BitLocker Startup Preferences page, select the Require Startup USB Key at every startup option. This is the only option available for non-TPM configurations. This key must be inserted each time before you start
      the computer.
    7. Insert your USB flash drive in the computer, if it is not already there.
    8. On the Save your Startup Key page, choose the location of your USB flash drive, and then click Save.
    9. On the Save the recovery password page, you will see the following options:
    · Save the password on a USB drive. Saves the password to a USB flash drive.

    · Save the password in a folder. Saves the password to a folder on a network drive or other location.

    · Print the password. Prints the password

    While I have a problem on step 4.

    Double-click the setting Control Panel Setup: Enable Advanced Startup Options.

    I can find "BitLocker Drive Encryption" on my group policy editor, while I cannot find
    Control Panel Setup: Enable Advanced Startup Options anywhere.

    Thank you for your help.

    Best Regards,

    Yan
     
    Yan.S, Jan 28, 2020
    #2
  3. lx07 Win User
    Bitlocker - Win 10 - TPM 2.0 - Legacy Mode


    According to here you need to boot in UEFI to configure bitlocker then you can change to CSM.
    Pre-Provision Bitlocker - TPM 2.0 - SCCM 1610
     
  4. Can't enable BitLocker with TPM only

    BitLocker not requiring password at boot. (Without TPM)


    I've recently installed bitlocker on my computer. Although windows says my C: drive is encrypted; I am not asked for my decryption password when i boot the computer. I get put straight into the login screen. I've done the necessary steps to enable bitlocker without TPM but maybe i missed something. Help please.
     
    xBrokenxSoulx, Jan 28, 2020
    #4
Thema:

Can't enable BitLocker with TPM only

Loading...
  1. Can't enable BitLocker with TPM only - Similar Threads - Can't enable BitLocker

  2. BitLocker could not be enabled - TPM or BIOS problem?

    in Windows 10 Gaming
    BitLocker could not be enabled - TPM or BIOS problem?: Hello everyone,I recently tried to activate BitLocker using the TPM on my computer, without success.Here is the error I get at startup: When I open the PowerShell console to enter the following command :"Enable-BitLocker -MountPoint $env:SystemDrive -EncryptionMethod...
  3. BitLocker could not be enabled - TPM or BIOS problem?

    in Windows 10 Software and Apps
    BitLocker could not be enabled - TPM or BIOS problem?: Hello everyone,I recently tried to activate BitLocker using the TPM on my computer, without success.Here is the error I get at startup: When I open the PowerShell console to enter the following command :"Enable-BitLocker -MountPoint $env:SystemDrive -EncryptionMethod...
  4. BitLocker could not be enabled - TPM or BIOS problem?

    in AntiVirus, Firewalls and System Security
    BitLocker could not be enabled - TPM or BIOS problem?: Hello everyone,I recently tried to activate BitLocker using the TPM on my computer, without success.Here is the error I get at startup: When I open the PowerShell console to enter the following command :"Enable-BitLocker -MountPoint $env:SystemDrive -EncryptionMethod...
  5. Enabling TPM

    in Windows 10 Customization
    Enabling TPM: Is it harmful to enable TPM in windows 10? What difference does it make by enabling it https://answers.microsoft.com/en-us/windows/forum/all/enabling-tpm/b400cf82-d5a8-448c-80cf-cf21fc661418
  6. Enable Bitlocker Without TPM

    in AntiVirus, Firewalls and System Security
    Enable Bitlocker Without TPM: Hello everyone, i need to enable BitLocker on all the computers all parittions inside the company using a script or command line without enabling TPM option and backup the recovery key to AD DS. is there a way to achieve that, i have searched a lot to do this with no...
  7. Cannot enable BitLocker, device can't use TPM

    in AntiVirus, Firewalls and System Security
    Cannot enable BitLocker, device can't use TPM: I have two drives, one stores the OS and the other stores other files. I have BitLocker enabled on the second drive but cannot seem to enable it on the first drive containing the OS. Please see error message below. I have a TPM chip installed on my board.. so I do not see...
  8. Can't enable Bitlocker.

    in Windows 10 Ask Insider
    Can't enable Bitlocker.: [ATTACH] I've recently build my new rig. I enabled Secure boot and TPM in the bios which is in UEFI mode. However when trying to enable bitlocker on my C: drive I get the following error:...
  9. Bitlocker with TPM

    in AntiVirus, Firewalls and System Security
    Bitlocker with TPM: Hi , I,m not sure if this is the right place to post this . Anyway , My query is about encryption on win10 pro . Previously I had a laptop with no TPM so I had to us the group policy editor to allow encryption to work , fine ,all was working and I had to type a password...
  10. BitLocker with TPM mode protection only?

    in AntiVirus, Firewalls and System Security
    BitLocker with TPM mode protection only?: I have a laptop which is a Dell E6440 and was just wondering if it vulnerable to these DMA attacks through Thunderbolt and Firewire methods. Reason asking, is because I have BitLocker full disk encryption turned ON with TPM-Only protection (meaning no PIN). Would this be...