Windows 10: Cannot enable BitLocker, device can't use TPM

Discus and support Cannot enable BitLocker, device can't use TPM in AntiVirus, Firewalls and System Security to solve the problem; I have two drives, one stores the OS and the other stores other files. I have BitLocker enabled on the second drive but cannot seem to enable it on the... Discussion in 'AntiVirus, Firewalls and System Security' started by cbb828282, Sep 21, 2020.

  1. cbb828282 Win User

    Cannot enable BitLocker, device can't use TPM


    I have two drives, one stores the OS and the other stores other files. I have BitLocker enabled on the second drive but cannot seem to enable it on the first drive containing the OS. Please see error message below. I have a TPM chip installed on my board.. so I do not see what the issue is. BitLocker on the second drive is using the TPM module, and to my knowledge you can store more than 1 key on the chip.. Please see second image for more info on the TPM admin..




    Cannot enable BitLocker, device can't use TPM 3cab5efd-608a-4023-9179-9b4bfced24db?upload=true.png




    Cannot enable BitLocker, device can't use TPM 4b5d6401-65d4-45aa-b934-38a1839d8028?upload=true.png

    :)
     
    cbb828282, Sep 21, 2020
    #1
  2. Yan.S Win User

    Bitlocker without TPM

    Hi there,

    I'm trying to use Bitlocker without TPM

    My version is Windows 10 Home, and I try to follow -

    To turn on BitLocker Drive Encryption on a computer without a compatible TPM



    1. Click Start, type gpedit.mscin the Start Search box, and then press ENTER.
    2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    3. In the Local Group Policy Editor console tree, click Local Computer Policy, click Administrative Templates, click Windows Components, and then clickBitLocker Drive Encryption.
    4. Double-click the setting Control Panel Setup: Enable Advanced Startup Options.
    5. Select the Enabled option, select the Allow BitLocker without a compatible TPM check box, and then click OK.
    You have changed the policy setting so that you can use a startup key instead of a TPM.

    1. Close the Local Group Policy Editor.
    2. To force Group Policy to apply immediately, you can click Start, typegpupdate.exe /forcein the Start Search box, and then press ENTER.
    3. Click Start, click Control Panel, click Security, and then click BitLocker Drive Encryption.
    4. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    5. On the BitLocker Drive Encryption page, click Turn On BitLocker. This will only appear with the operating system volume.
    6. On the Set BitLocker Startup Preferences page, select the Require Startup USB Key at every startup option. This is the only option available for non-TPM configurations. This key must be inserted each time before you start
      the computer.
    7. Insert your USB flash drive in the computer, if it is not already there.
    8. On the Save your Startup Key page, choose the location of your USB flash drive, and then click Save.
    9. On the Save the recovery password page, you will see the following options:
    · Save the password on a USB drive. Saves the password to a USB flash drive.

    · Save the password in a folder. Saves the password to a folder on a network drive or other location.

    · Print the password. Prints the password

    While I have a problem on step 4.

    Double-click the setting Control Panel Setup: Enable Advanced Startup Options.

    I can find "BitLocker Drive Encryption" on my group policy editor, while I cannot find
    Control Panel Setup: Enable Advanced Startup Options anywhere.

    Thank you for your help.

    Best Regards,

    Yan
     
    Yan.S, Sep 21, 2020
    #2
  3. lx07 Win User
    Bitlocker - Win 10 - TPM 2.0 - Legacy Mode

    According to here you need to boot in UEFI to configure bitlocker then you can change to CSM.
    Pre-Provision Bitlocker - TPM 2.0 - SCCM 1610
     
  4. Cannot enable BitLocker, device can't use TPM

    BitLocker refuses to enable

    Windows 10 Pro on Dell Optiplex 5040

    Domain-joined

    No TPM

    I have tried repeatedly to enable BitLocker on this machine and all attempts have failed. The majority of suggestions point me to gpedit.msc > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating
    System Drives > Require additional authentication at startup (and be sure "Allow BitLocker without a compatible TPM" option is checked). The option is checked and the GPO enabled, however, I still receive the error "This
    device can't use a Trusted Platform Module. Your administrator must set the "Allow BitLocker without a compatible TPM" option in the "Require additional authentication at startup" policy for OS volumes."

    We don't have any other computers with this issue, though, to be fair, this is one of the only computers without TPM. What else can be done?
     
    Matthew Wallace PS, Sep 21, 2020
    #4
Thema:

Cannot enable BitLocker, device can't use TPM

Loading...
  1. Cannot enable BitLocker, device can't use TPM - Similar Threads - Cannot enable BitLocker

  2. TPM vs Bitlocker. This device cannot use TPM. Is my TPM or isn't compatible with Windows...

    in Windows 10 Gaming
    TPM vs Bitlocker. This device cannot use TPM. Is my TPM or isn't compatible with Windows...: A few details up front, my Windows 10 is able to inform me about TPM status:-TPM Present: True -TPM Version: 2.0 -TPM Manufacturer ID: INTC -TPM Manufacturer Full Name: Intel TpmPresent : True TpmReady : True TpmEnabled : True TpmActivated : True TpmOwned : True...
  3. TPM vs Bitlocker. This device cannot use TPM. Is my TPM or isn't compatible with Windows...

    in Windows 10 Software and Apps
    TPM vs Bitlocker. This device cannot use TPM. Is my TPM or isn't compatible with Windows...: A few details up front, my Windows 10 is able to inform me about TPM status:-TPM Present: True -TPM Version: 2.0 -TPM Manufacturer ID: INTC -TPM Manufacturer Full Name: Intel TpmPresent : True TpmReady : True TpmEnabled : True TpmActivated : True TpmOwned : True...
  4. Having an issue with a customer trying to enable Bitlocker with MECM on a device with a TPM...

    in AntiVirus, Firewalls and System Security
    Having an issue with a customer trying to enable Bitlocker with MECM on a device with a TPM...: Having an issue with a customer trying to enable Bitlocker with Microsoft Endpoint Configurartion Manager on a device with a TPM disabled, they are limited due to these are Chinese devices, with a TPM, but due to some legal restriction, they have to have the TPM disabled, and...
  5. Using BitLocker without a TPM

    in AntiVirus, Firewalls and System Security
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  6. Using BitLocker without a TPM

    in Windows 10 Gaming
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  7. Using BitLocker without a TPM

    in Windows 10 Software and Apps
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  8. Enable Bitlocker Without TPM

    in AntiVirus, Firewalls and System Security
    Enable Bitlocker Without TPM: Hello everyone, i need to enable BitLocker on all the computers all parittions inside the company using a script or command line without enabling TPM option and backup the recovery key to AD DS. is there a way to achieve that, i have searched a lot to do this with no...
  9. Can't enable BitLocker with TPM only

    in Windows 10 Ask Insider
    Can't enable BitLocker with TPM only: I'm having a hard time getting BitLocker to work the same way on my newly built desktop as it does on my Surface Pro 3, i.e. the drive is unlocked instantly with the TPM and I go straight to the windows login screen. When I try to configure BitLocker it just wants me to plug...
  10. WHY use TPM with bitlocker?

    in AntiVirus, Firewalls and System Security
    WHY use TPM with bitlocker?: i still have to understand WHY to use TPM with bitlocker. these are my concerns, i tried to use bitlocker with my tpm but the encryption was "free" without to enter any password at boot. Ok this kind of encryption is useful ONLY IF a thief steal ONLY the hd .... but what if...