Windows 10: Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable

Discus and support Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable in Windows 10 Ask Insider to solve the problem; Hi all, Wondering if some of you may be able to shed some light on this. We've been enabling Bitlocker on some client machines, but have been finding... Discussion in 'Windows 10 Ask Insider' started by /u/Razgriz-375, Jun 4, 2020.

  1. Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable


    Hi all,

    Wondering if some of you may be able to shed some light on this. We've been enabling Bitlocker on some client machines, but have been finding that with this enabled, and the device rebooted, the device can no longer see the bootable device, so gets stuck in the BIOS. The only work around we have at the moment is to disable secure boot.

    All machines have a TPM chip, and pass the checks. And I am under the impression that Secure Boot should be absolutely fine with Bitlocker encryption. So what gives?

    submitted by /u/Razgriz-375
    [link] [comments]

    :)
     
    /u/Razgriz-375, Jun 4, 2020
    #1

  2. UEFI Admin Password needed if BitLocker is enabled?

    Just a quick question. I have enabled BitLocker with TPM-Only protector and was just wondering if I need to set an Admin BIOS/UEFI password to prevent someone from changing the UEFI settings. I also have Secure Boot enabled as well along with the following BitLocker protection policies below.

    In my UEFI boot settings, I have Windows Boot Mannager and then my Internal HDD as the boot order.
    Boot from external media is enabled, because I tend to reinstall Windows from my Windows 10 bootable USB flash drive.

    With all these below BitLocker settings and policies, do I really need to set an Admin or Supervisor password to prevent an attacker from changing the UEFI settings in case the laptop gets stolen?

    My current BitLocker protection settings from the Windows 10 v1803 Security Baseline.

    Disable new DMA devices when this computer is locked:
    Enabled


    Allow Secure Boot for integrity validation:
    Enabled




    https://support.microsoft.com/en-us/...-reduce-1394-d

    Prevent installation of devices that match any of these device IDs
    PCI\CC_0C0A


    Prevent installation of devices using drivers for these device setup classes:
    {d48179be-ec20-11d1-b6b8-00c04fa372a7}
     
    win10freak, Jun 4, 2020
    #2
  3. Bitlocker vague error message enabling on boot drive

    Trying to enable bitlocker on my boot drive:

    I have a TPM chip installed and cleared and in the TPM MMC console this shows as ready for use

    I have UEFI boot enabled and confirm that msinfo32 shows boot mode as UEFI

    I have GPT Partition on my boot disk (I did have to convert this using the mbr2gpt utility)

    When I try to enable bitlocker on c: drive it comes back with very unhelpful error "The data is invalid" after doing some checks.

    When I try to enable I see in the event log event ID811 from source Bitlocker-API

    "BitLocker cannot use Secure Boot for integrity because the required UEFI variable 'PK' is not present."

    Any ideas here? This is Windows 10 1709 build

    Thanks
     
    SteveOWilson, Jun 4, 2020
    #3
  4. JohnC Win User

    Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable

    UEFI bios enabled but no secure boot on windows 10?


    I would go with what is showing in the Bios. If it says that the secure boot keys are loaded then it is on. I'm running the insider build and under System info it says secure boot is unsupported, but it is on and the keys are loaded in my UEFI BIOS. I think this is what the OP is saying. The only other thing that came to mind is if bitlocker was confused with secure boot, they are totally different. To check system info WIN + R type msinfo32 , hit OK.

    This is a partial listing.

    Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable [​IMG]
     
    JohnC, Jun 4, 2020
    #4
Thema:

Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable

Loading...
  1. Enabling Bitlocker with UEFI Secure Boot enabled renders the device unbootable - Similar Threads - Enabling Bitlocker UEFI

  2. How can i enable uefi and secure boot?

    in Windows 10 Software and Apps
    How can i enable uefi and secure boot?: so i wanted to try out windows 11 on my pc and it says it dosent meet the requirements because secure boot isn’t enabled. I tried changing the bios from legacy to ufei but when i pressed save and exit it kept going back to the bios until I switched it back to legacy please...
  3. How can i enable uefi and secure boot?

    in Windows 10 Gaming
    How can i enable uefi and secure boot?: so i wanted to try out windows 11 on my pc and it says it dosent meet the requirements because secure boot isn’t enabled. I tried changing the bios from legacy to ufei but when i pressed save and exit it kept going back to the bios until I switched it back to legacy please...
  4. how to enable secure boot even if UEFI and secure boot control is on/enabled

    in Windows 10 Gaming
    how to enable secure boot even if UEFI and secure boot control is on/enabled: as how the question goes, I can't find a way to manually enable secure boot itself even if secure boot control and UEFI is on and used. how do I enable it? like the secure boot in the BIOS settings of mine can't be changed but the secure boot control can be changed, I have...
  5. how to enable secure boot even if UEFI and secure boot control is on/enabled

    in Windows 10 Software and Apps
    how to enable secure boot even if UEFI and secure boot control is on/enabled: as how the question goes, I can't find a way to manually enable secure boot itself even if secure boot control and UEFI is on and used. how do I enable it? like the secure boot in the BIOS settings of mine can't be changed but the secure boot control can be changed, I have...
  6. Enable Secure Boot on Windows device

    in Windows 10 Gaming
    Enable Secure Boot on Windows device: Secure Boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the original equipment manufacturer OEM. Your organization's device management policies might require you to enable it...
  7. Enable Secure Boot on Windows device

    in Windows 10 Software and Apps
    Enable Secure Boot on Windows device: Secure Boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the original equipment manufacturer OEM. Your organization's device management policies might require you to enable it...
  8. Secure Boot Enabling W10 UEFI; for W11

    in Windows 10 Installation and Upgrade
    Secure Boot Enabling W10 UEFI; for W11: Please help me.I using W10 on UEFI/GPT. But SecureBootState is Off.What have i done: 1 in ASUS UEFI i selected Windows UEFI Mode instead of Other OS and broke boot process - Windows Boot Manager invoked repair procedure.2 I turned off driver signature enforcement F7 keyword...
  9. UEFI bios enabled but no secure boot on windows 10?

    in Windows 10 Support
    UEFI bios enabled but no secure boot on windows 10?: So i had secure boot up and running on my windows 8.1 machine after a clean install, but now since microsoft upgraded me to windows 10 it seems as my secure boot is off again, but it's enabled in my bios is so weird, it's enabled in bios but off in windows 10? Is not much of...
  10. UEFI Installation With Secure boot enabled

    in Windows 10 Installation and Upgrade
    UEFI Installation With Secure boot enabled: Hello tech guys, i need emergency help, i posting this thread from my frined's computer, i have a HP laptop, and few days ago i send it to tech shop for motherboard repair, and they did it as well, but after few days i am facing problem with BIOS, i cant change bios...