Windows 10: Cannot resume bitlocker after CU suspends it

Discus and support Cannot resume bitlocker after CU suspends it in AntiVirus, Firewalls and System Security to solve the problem; This happens to many hundreds of our enterprise devices every month, after a cumulative update is installed on Windows. Bitlocker becomes suspended for... Discussion in 'AntiVirus, Firewalls and System Security' started by RadioActiveLamb, Jul 9, 2021.

  1. Cannot resume bitlocker after CU suspends it


    This happens to many hundreds of our enterprise devices every month, after a cumulative update is installed on Windows. Bitlocker becomes suspended for multiple reboots. Ultimately, I'd like to solve the root of the problem by eliminating the suspension over several reboots. However, for now, I just want to manually resume BitLocker without forcing a reboot. Here's the situation. Notice that the protection status indicates that BitLocker is suspended, and it will resume after one more reboot - this just after booting up from the CU install..PS C:\WINDOWS\system32> manage-bde -status BitLock

    :)
     
    RadioActiveLamb, Jul 9, 2021
    #1

  2. Bitlocker automatically suspending after CU

    I have nothing helpful to add to this but I'm experiencing the same problem. This first started with the June 2018 CU and happened again with today's July 2018 CU. After installing the CUs BitLocker is suspended on my OS volume and I have to manually resume
    it. This is on a machine without a TPM - I'm using BitLocker with a password. Please let me know if you find a solution for this Cannot resume bitlocker after CU suspends it :)

    Thanks!
     
    JayEssThree, Jul 9, 2021
    #2
  3. Crking Win User
    Bitlocker automatically suspending after CU

    Hi JayEssThree,

    I saw your comment on my TechNet thread. If I have any updates, I'll post them there.
     
    Crking, Jul 9, 2021
    #3
  4. Crking Win User

    Cannot resume bitlocker after CU suspends it

    Bitlocker automatically suspending after CU

    Hi

    I have encountered unexpected behavior with Bitlocker since cumulative update (CU) KB4100403 in June.

    The machine is running Windows 10 Pro, 1803. The machine has no TPM, and Bitlocker is set up to use a password prior to logging in.

    I noticed that since mid-June, Bitlocker is automatically suspended on my operating system drive during Cumulative Updates. Once the update has completed and I log in, Bitlocker is suspended and must either be manually resumed or will automatically
    resume once I manually restart the system. manage-bde shows the drive status as:

    Volume C: [System]

    [OS Volume]
    Size: 59.07 GB

    BitLocker Version: 2.0

    Conversion Status: Fully Encrypted

    Percentage Encrypted: 100.0%

    Encryption Method: XTS-AES 128

    Protection Status: Protection Off (1 reboots left) <-------------------

    Lock Status: Unlocked

    Identification Field: Unknown

    Key Protectors:

    Password

    Numerical Password

    The problem here is that Bitlocker should not be suspended unless user-initiated as this creates a security issue. Now I am aware of the following blog post relating to changes made to Bitlocker in 1803:
    NEW: Upgrade to Windows 10 1803 without suspending BitLocker. I have asked about this issue elsewhere have been pointed to this blog post, however it doesn't apply to my situation as (1) it applies
    only to Feature Updates, not the Cumulative Updates I am dealing with; and (2) it only applies to machines that have a TPM - mine does not.

    Looking at the Bitlocker event logs, each time Bitlocker is suspended, the event shows the action initiated by the system account, and each time it correlates with a CU installed in Windows Update.

    To get to the bottom of this, I have tried:

    (1) To eliminate issues related to software I've installed, I tried a fresh install of 1803 English International from my original ISO, only changed the GPO to allow Bitlocker without TPM, let Bitlocker encrypt, then applied all Windows updates (including
    the latest CU). On reboot, Bitlocker was suspended.

    (2) To eliminate issues related to my ISO, I used the media creation tool to make a new USB installer of 1803 US English. Then followed the same process as (1). On reboot, Bitlocker was suspended.

    (3) To attempt to eliminate as many hardware issues as possible, I set up a VirtualBox VM (without VM extensions or tools) and installed 1803 from my original ISO. Then followed the same process as (1). On reboot, Bitlocker was suspended.

    Has anyone else encountered this? Is this expected behavior since KB4100403, and if so, does anyone know why?

    Thanks
     
    Crking, Jul 9, 2021
    #4
Thema:

Cannot resume bitlocker after CU suspends it

Loading...
  1. Cannot resume bitlocker after CU suspends it - Similar Threads - Cannot resume bitlocker

  2. How to Resume or Suspend BitLocker encryption in Windows 10

    in Windows 10 News
    How to Resume or Suspend BitLocker encryption in Windows 10: [ATTACH]BitLocker security software created by Microsoft is based on next-generation secure computing architecture. It is encrypted for all devices whether portable or non-portable to prevent third-party intrusion while working on the device. It is used by many organizations...
  3. How to Suspend or Resume BitLocker Protection for Drives in Windows 10

    in Windows 10 News
    How to Suspend or Resume BitLocker Protection for Drives in Windows 10: [ATTACH] [ATTACH]On BitLocker-supported editions of Windows 10, you can temporarily suspend or pause BitLocker protection for an unlocked drive encrypted using BitLocker. For example, if you need to install new software that BitLocker might otherwise block, you can suspend...
  4. Bitlocker Suspended - Wizard Initiation Fails when Attempting to Resume

    in AntiVirus, Firewalls and System Security
    Bitlocker Suspended - Wizard Initiation Fails when Attempting to Resume: I have Windows 10 Pro and have Bitlocker activated on my computer for many months. I have (3) drives (C, D E) that were all encrypted with Bitlocker. C is the main Windows installation and boot drive. Recently, I received a prompt that showed that Bitlocker encryption was...
  5. Windows 10 BitLocker suspend protection triggers an immediate resume

    in Windows 10 Customization
    Windows 10 BitLocker suspend protection triggers an immediate resume: I have two internal hard drives in my laptop that are encrypted using BitLocker and I am trying to install a new Dell BIOS update that requires suspending BitLocker. Unfortunately, when I suspend BitLocker through the Control Panel or PowerShell, it suspends for less than 1...
  6. Resume/Suspend Process

    in Windows 10 Customization
    Resume/Suspend Process: In task manager I suspended a few processes, but when I tried to resume them it wouldn't allow me to. Like, nothing happened, I tried to restart, and many other solutions, but nothing happened. Any other solutions or tips?...
  7. BitLocker Drive Protection Suspended and Unable to Resume

    in AntiVirus, Firewalls and System Security
    BitLocker Drive Protection Suspended and Unable to Resume: Windows Defender requested that I "reset my TPM", which I did. But upon the restarting of the computer, the bitlocker drive protection is disabled for my C drive and when I try to resume it, it says, "An internal error has occurred within the Trusted Platform Module support...
  8. Bitlocker automatically suspending after CU

    in AntiVirus, Firewalls and System Security
    Bitlocker automatically suspending after CU: Hi I have encountered unexpected behavior with Bitlocker since cumulative update (CU) KB4100403 in June. The machine is running Windows 10 Pro, 1803. The machine has no TPM, and Bitlocker is set up to use a password prior to logging in. I noticed that since mid-June,...
  9. Cannot resume bitlocker encryption after restart

    in AntiVirus, Firewalls and System Security
    Cannot resume bitlocker encryption after restart: I was trying to encrypt my USB external hard drive (1 TB, mounted to E*Smile using BitLocker, and after the encryption got 10.1% finished, I accidentally shut down the computer. After restarting, I tried to resume the encryption, but it gives me an error: "Encryption could...
  10. Suspend or Resume BitLocker Protection for Drive in Windows 10

    in Windows 10 Tutorials
    Suspend or Resume BitLocker Protection for Drive in Windows 10: How to: Suspend or Resume BitLocker Protection for Drive in Windows 10 How to Suspend or Resume BitLocker Protection for Drive in Windows 10 [img] Information You can use BitLocker Drive Encryption to help protect your files on an entire drive. BitLocker can help...