Windows 10: Bitlocker Lockout

Discus and support Bitlocker Lockout in Windows 10 Network and Sharing to solve the problem; How do I retrieve 32 digit bitlocker key without access to computer and no previous printouts?... Discussion in 'Windows 10 Network and Sharing' started by Rachel_343, Aug 11, 2019.

  1. Bitlocker Lockout


    How do I retrieve 32 digit bitlocker key without access to computer and no previous printouts?

    :)
     
    Rachel_343, Aug 11, 2019
    #1
  2. Mithin_EJ Win User

    BitLocker on Surface Pro 3 not working correctly

    Hi JulianSchubert,

    Thank you for posting your question in the Microsoft Community

    TPM will lock itself out after a few incorrect authentication attempts. These could be due to incorrect PIN entry for BitLocker or incorrect PIN entry for TPM virtual smartcard PIN. For TPM version 1.2, the lockout behavior depends
    on individual TPM manufacturer. For TPM 2.0, the specification states that the TPM will enter lockout after 32 incorrect attempts.

    To terminate this BitLocker recovery loop, you need to suspend BitLocker within WinRE, I suggest you to follow the below steps.

    Step 1:

    1. Choose the “Skip this drive” link at the bottom of the page where you are asked to enter the recovery key. You should be presented with a menu that will let you get to a command prompt (The sequence is Advanced
      options -> Troubleshoot -> Advanced options -> Command prompt).
    2. Once you have a command prompt,
      use the following command to check the BitLocker status of the C: drive:
      manage-bde -status c:

    3. If the status is returned as locked, you’ll need to use the following command to unlock it using your recovery password:
      manage-bde -unlock c: -rp <your 48-digit recovery password>
    4. Once the drive is unlocked you'll need to use the following command to suspend protection:
      manage-bde -protectors -disable c:
    5. Then exit and reboot. The computer should now successfully boot Windows. Once there, use the BitLocker control panel to resume BitLocker protection.
    6. You can reset TPM lockout using
      tpm.msc
    Note: The recovery loop can occur for other reasons such as cases where TPM is disabled or malfunctions. You can still use the above steps to suspend BitLocker and boot Windows in such cases

    Hope it helps.
     
    Mithin_EJ, Aug 11, 2019
    #2
  3. Windows 10 BitLocker and TPM lockout

    Hi,

    I have hit an issue with BitLocker which uses TPM on a Windows 10 laptop.

    In the past you were able to take ownership of the TPM and export the key/password. The current version of Win10 no longer allows this. This would all be fine if you no longer needed the key. Unfortunately on this laptop the TPM has now got itself in a locked
    state after too many failed logins by the user. We were eventually able to login with the BitLocker recovery key after it rejected it initially. However because Windows retains ownership we do not have the TPM key and therefore we cannot do the reset.

    I have trawled various TechNet articles and cannot see how we are supposed to resolve this. Does the TPM automatically clear the lockout itself after a period of time?

    I have suspended BitLocker on that computer. It looks like I cannot resume it until the TPM lockout has ended.

    Isn't this an oversight on how we are supposed to be able to resolve issues?

    Thanks!

    Stephen.
     
    StephenGibb- [O365], Aug 11, 2019
    #3
  4. Bitlocker Lockout

    Win10 Bitlocker and Interactive logon: Machine account lockout?


    There is a Bitlocker PIN (Which you enter in to the Blue Screen), then there is a separate password for your Windows account. The local security policy setting "Interactive Logon: Machine Account Lockout Threshold" is specifically for use in conjuction with Bitlocker encrypted systems. If you have this policy set, it prevents Brute-Force Logon in to Windows. You must first enter your Bitlocker PIN (If set), then you must also log in to Windows. If you use the wrong password too many times on your Windows account, that local security policy will cause the system to go in to Bitlocker Recovery Mode.
     
    Peffercorn19, Aug 11, 2019
    #4
Thema:

Bitlocker Lockout

Loading...
  1. Bitlocker Lockout - Similar Threads - Bitlocker Lockout

  2. bitlocker PIN

    in AntiVirus, Firewalls and System Security
    bitlocker PIN: Hi, i have a problem on few devices, i run Bitlocker for them and people didn't set pin on their devices, but system is asking about PIN. What should i do in this case? 2nd question - can i reset TPM remotely for some other computers?...
  3. Windows BitLocker

    in Windows 10 Installation and Upgrade
    Windows BitLocker: My computer activated BitLocker for some reason. I obtained my recovery key but program says its incorrect. What can I do next? https://answers.microsoft.com/en-us/windows/forum/all/windows-bitlocker/3d7f7529-69f2-4009-83e7-9d8eca6e235c
  4. Bitlocker Enabled on New HP Laptop - Disable or Keep?

    in AntiVirus, Firewalls and System Security
    Bitlocker Enabled on New HP Laptop - Disable or Keep?: I just bought a new HP ProBook and I've just noticed it is supplied with Bitlocker enabled on the system drive. I only use the laptop in a secure location for general home PC use. Are there any disadvantages of keeping Bitlocker enabled on the drive? Macrium Reflect works OK...
  5. Bitlocker Enabled on New HP Laptop - Disable or Keep?

    in Windows 10 Support
    Bitlocker Enabled on New HP Laptop - Disable or Keep?: I just bought a new HP ProBook and I've just noticed it is supplied with Bitlocker enabled on the system drive. I only use the laptop in a secure location for general home PC use. Are there any disadvantages of keeping Bitlocker enabled on the drive? Macrium Reflect works OK...
  6. Can I use a thumb drive when asked for a Bitlocker Recovery Key?

    in Windows 10 Network and Sharing
    Can I use a thumb drive when asked for a Bitlocker Recovery Key?: Bitlocker offers the option to save the Recovery Key to a drive other than the encrypted drive. If I save the key to a thumb drive and later, for some reason, I am prompted for the Recovery Key when I start my PC, can I simply insert the thumb drive instead of manually...
  7. Bitlocker waking up non-encrypted HDD drives every hour

    in Windows 10 Drivers and Hardware
    Bitlocker waking up non-encrypted HDD drives every hour: So I'm running Bitlocker encrypted and non-encrypted HDD disks and have set up disk to sleep after 5 minutes. However, every hour Bitlocker wakes up the disks that are _not_encrypted, apparently to check if they can be encrypted, or something similar. Disks that have all...
  8. Bitlocker key and password recovery

    in AntiVirus, Firewalls and System Security
    Bitlocker key and password recovery: Hi, i have a drive that is locked but i do not have the 48 key password. i only have the 32 key identification key. how do i unlock my drive with this?...
  9. Windows 10 Mobile - how to find/recover bitlocker key in microSD?

    in Windows 10 Installation and Upgrade
    Windows 10 Mobile - how to find/recover bitlocker key in microSD?: Hello, I have a Microsoft Lumia 640 which after rebooting several times (bootloop) simply didn't start. I removed the microSD and the phone boots just fine. The microSD then needs to be formatted in order to repair it. However, the same was encrypted with bitlocker by the...
  10. Win10 Bitlocker and Interactive logon: Machine account lockout?

    in AntiVirus, Firewalls and System Security
    Win10 Bitlocker and Interactive logon: Machine account lockout?: I am VERY confused - Please help. By setting up Full Drive Encryption on Win10 and 8 systems, with a BitLocker password, will that BitLocker password would be the same as the normal Windows user account password? On these OS systems there is a new Local Security Policy...