Windows 10: BitLocker without TPM but using a flash drive - doesn't need flash to boot.

Discus and support BitLocker without TPM but using a flash drive - doesn't need flash to boot. in AntiVirus, Firewalls and System Security to solve the problem; I'm trying to understand how full-disk bitlocker works as I intend deploying it on a number of PCs, not all of which have a TPM. I enabled bitlocker on... Discussion in 'AntiVirus, Firewalls and System Security' started by Robert190, Jan 4, 2020.

  1. Robert190 Win User

    BitLocker without TPM but using a flash drive - doesn't need flash to boot.


    I'm trying to understand how full-disk bitlocker works as I intend deploying it on a number of PCs, not all of which have a TPM. I enabled bitlocker on a windows 10 laptop which does have a TPM but I elected not to use it. Instead, I saved the key to a USB flash drive. My expectation was that if I attempted to reboot the laptop without the flash drive, it would fail but in fact, it boots as normal. I've tried several times, even removing the battery. So does bitlocker give any protection if there is no TPM?

    :)
     
    Robert190, Jan 4, 2020
    #1

  2. Bitlocker: using with TPM and without TPM via USB flash drive authentication

    Hi everybody.

    I need to use Bitlocker on several Windows 10 computers, all without TPM but one.

    On this one when I try to save the key to my Microsoft account I'm returned an error.

    I can save the key to file instead.

    How to fix this?

    Regarding computers without TPM I would understand how Bitlocker works using USB flash drive authentication and if, in case of hardware fault, data on hard drive can bbw recovered moving hard drive and USB flash drive to other computer.

    Thanks and best regards.
     
    Federico Rampin, Jan 4, 2020
    #2
  3. Yan.S Win User
    Bitlocker without TPM

    Hi there,

    I'm trying to use Bitlocker without TPM

    My version is Windows 10 Home, and I try to follow -

    To turn on BitLocker Drive Encryption on a computer without a compatible TPM



    1. Click Start, type gpedit.mscin the Start Search box, and then press ENTER.
    2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    3. In the Local Group Policy Editor console tree, click Local Computer Policy, click Administrative Templates, click Windows Components, and then clickBitLocker Drive Encryption.
    4. Double-click the setting Control Panel Setup: Enable Advanced Startup Options.
    5. Select the Enabled option, select the Allow BitLocker without a compatible TPM check box, and then click OK.
    You have changed the policy setting so that you can use a startup key instead of a TPM.

    1. Close the Local Group Policy Editor.
    2. To force Group Policy to apply immediately, you can click Start, typegpupdate.exe /forcein the Start Search box, and then press ENTER.
    3. Click Start, click Control Panel, click Security, and then click BitLocker Drive Encryption.
    4. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
    5. On the BitLocker Drive Encryption page, click Turn On BitLocker. This will only appear with the operating system volume.
    6. On the Set BitLocker Startup Preferences page, select the Require Startup USB Key at every startup option. This is the only option available for non-TPM configurations. This key must be inserted each time before you start
      the computer.
    7. Insert your USB flash drive in the computer, if it is not already there.
    8. On the Save your Startup Key page, choose the location of your USB flash drive, and then click Save.
    9. On the Save the recovery password page, you will see the following options:
    · Save the password on a USB drive. Saves the password to a USB flash drive.

    · Save the password in a folder. Saves the password to a folder on a network drive or other location.

    · Print the password. Prints the password

    While I have a problem on step 4.

    Double-click the setting Control Panel Setup: Enable Advanced Startup Options.

    I can find "BitLocker Drive Encryption" on my group policy editor, while I cannot find
    Control Panel Setup: Enable Advanced Startup Options anywhere.

    Thank you for your help.

    Best Regards,

    Yan
     
    Yan.S, Jan 4, 2020
    #3
  4. DaveLx1 Win User

    BitLocker without TPM but using a flash drive - doesn't need flash to boot.

    Windows 10 Bitlocker - install TPM

    My Win 10 Pro system drive is already Bitlocker encrypted without a TPM chip on my motherboard.

    If I now install a TPM on the motherboard, will Bitlocker make use of it? How do I enable it?

    (I want to boot-up without the USB flash drive containing the Start up key.)

    Thanks, --Dave
     
    DaveLx1, Jan 4, 2020
    #4
Thema:

BitLocker without TPM but using a flash drive - doesn't need flash to boot.

Loading...
  1. BitLocker without TPM but using a flash drive - doesn't need flash to boot. - Similar Threads - BitLocker without TPM

  2. Bitlocker trashed flash drives?

    in Windows 10 Gaming
    Bitlocker trashed flash drives?: Hi Today I encrypted two small USB flash drives on a Windows 10 computer. Both those drives seem to have been trashed by the process. If I plug one in, an error window pops up saying to insert the drive, in this case d and e. But obviously they are already inserted. In disk...
  3. Bitlocker trashed flash drives?

    in Windows 10 Software and Apps
    Bitlocker trashed flash drives?: Hi Today I encrypted two small USB flash drives on a Windows 10 computer. Both those drives seem to have been trashed by the process. If I plug one in, an error window pops up saying to insert the drive, in this case d and e. But obviously they are already inserted. In disk...
  4. Using BitLocker without a TPM

    in AntiVirus, Firewalls and System Security
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  5. Using BitLocker without a TPM

    in Windows 10 Gaming
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  6. Using BitLocker without a TPM

    in Windows 10 Software and Apps
    Using BitLocker without a TPM: I have an older PC I want to protect the data on with BitLocker. It's running Windows 10 Pro, and the PC does not have a TPM.If I enable and setup BitLocker without a TPM, and set it to require a password on boot not a USB key, is the password itself encrypted? Normally the...
  7. Bitlocker on USB flash drive

    in AntiVirus, Firewalls and System Security
    Bitlocker on USB flash drive: I have a 256GB USB Micro flash drive that I have plugged into my laptop Microsoft Laptop 3 running Windows 10 Professional. While I was working today it got locked by BitLocker somehow. I have used this drive for months and it's never been a problem nor did I ever used...
  8. Bitlocker on USB flash drives

    in AntiVirus, Firewalls and System Security
    Bitlocker on USB flash drives: I read through the below tutorial on how to encrypt USB removable data drives. Turn On or Off BitLocker for Removable Data Drives in Windows 10 However, I just wanted to know if it would be best practice to add the data BEFORE or AFTER encrypting a USB removable drive using...
  9. Unable to boot without flash drive

    in Windows 10 Installation and Upgrade
    Unable to boot without flash drive: I have install window 10 pro 64 bit through flash drive and now without the flash drive window doesn't boot up. https://answers.microsoft.com/en-us/windows/forum/all/unable-to-boot-without-flash-drive/76912778-d715-4e69-95ad-2d5c5d164c33
  10. USB Flash Drive with Bitlocker

    in AntiVirus, Firewalls and System Security
    USB Flash Drive with Bitlocker: I tried to use bitlocker on a USB Flash drive and about half way through we had a power bump and my PC restarted. Now I can't access the drive. I tried to use bitlocker again but right clicking does not offer bitlocker any more. Is the drive toast or can I retrieve the data I...