Windows 10: How to enable BitLocker when booting from another boot manager?

Discus and support How to enable BitLocker when booting from another boot manager? in AntiVirus, Firewalls and System Security to solve the problem; I have ThinkPad P1 Gen 3 laptop and I dual boot Linux and Windows 10. For that I want to use a boot manager that supports booting both OS-es (Windows... Discussion in 'AntiVirus, Firewalls and System Security' started by secretblackhole, May 4, 2021.

  1. How to enable BitLocker when booting from another boot manager?


    I have ThinkPad P1 Gen 3 laptop and I dual boot Linux and Windows 10. For that I want to use a boot manager that supports booting both OS-es (Windows Boot Manager doesn't support that). I also want to have Secure Boot on and have my Windows partition encrypted using BitLocker. The problem I have is that when I boot Windows using another boot manager (I tried both rEFInd and systemd-boot) BitLocker support is disabled. I see that the reason for this is PCR7 binding not working - System Information says: PCR7 Configuration: Binding Not Possible Device Encryption Support: Reasons for failed automatic device encryption: PCR7 binding is not supported; Un-allowed DMA capable bus/device(s) detected When I boot Windows directly from UEFI (UEFI -> Windows Boot Manager) instead of using a third-party boot manager (UEFI -> Another boot manager -> Windows Boot Manager) I don't have those problems and BitLocker support works fine. I'm not a Windows expert and I don't know neither what PCR7 nor TPM is. I cannot find any resources on the internet that would explain how those things work nor how to fix the problem, so I came here. Can someone explain me what's the problem here? Why Windows cannot establish this PCR7 binding when I boot it using another boot manager? Can I somehow fix that?

    :)
     
    secretblackhole, May 4, 2021
    #1

  2. Bitlocker vague error message enabling on boot drive

    Trying to enable bitlocker on my boot drive:

    I have a TPM chip installed and cleared and in the TPM MMC console this shows as ready for use

    I have UEFI boot enabled and confirm that msinfo32 shows boot mode as UEFI

    I have GPT Partition on my boot disk (I did have to convert this using the mbr2gpt utility)

    When I try to enable bitlocker on c: drive it comes back with very unhelpful error "The data is invalid" after doing some checks.

    When I try to enable I see in the event log event ID811 from source Bitlocker-API

    "BitLocker cannot use Secure Boot for integrity because the required UEFI variable 'PK' is not present."

    Any ideas here? This is Windows 10 1709 build

    Thanks
     
    SteveOWilson, May 5, 2021
    #2
  3. Preparing Automatic repair on boot when bitlocker is enabled

    Hello, I'm having trouble getting bitlocker to work on my new drive.

    The drive is Intel pro 6000p, which is a self encrypting drive. I have eDrive enabled and did a fresh windows install on it.

    I then enabled bitlocker with a password, so to integrate with the self encrypting feature. I could confirm bitlocker was enabled by entering "manage-bde -status", which reported hardware encryption and protection on.

    But after that, whenever I boot it just go straight into "Preparing Automatic Repair", then follow by enter Bitlocker recovery key screen. No prompt for a password.

    I tried repairing it with the Windows media and the correct recovery key, but automatic repair was not successful.

    I was able to get back into Windows, by unlocking the drive in advanced option-->command prompt, using "manage-bde -unlock C: -pw". The system seems fine so I don't think there is a corruption in file. After disabling bitlocker in control panel (or
    via command prompt) the system boots normal again.

    Note: Fast boot is OFF, CSM is OFF, secure boot is ON, no other drive is present.

    Please I need your help. I did everything clean and tidy, I just want it to work!
     
    please-just-work, May 5, 2021
    #3
  4. How to enable BitLocker when booting from another boot manager?

    Windows boot manager

    There could be some system conflict triggered after the said changes. To help you with your concern, we suggest that you perform a clean boot. A
    clean boot is performed to start Windows by using a minimal set of drivers and startup programs. This will help to determine what is causing the issue on the Windows boot manager. To do this, click on this
    link and scroll down to the
    How to determine what is causing the problem by performing a clean boot section then follow the steps listed..

    Note: If the installation is successful and the issue has been resolved. Please go through the section “How to reset the computer to start as usual” to reset your computer to the normal startup.

    Let us know how it goes after performing the suggested steps.
     
    Eileen Gal, May 5, 2021
    #4
Thema:

How to enable BitLocker when booting from another boot manager?

Loading...
  1. How to enable BitLocker when booting from another boot manager? - Similar Threads - enable BitLocker booting

  2. Lost drive with boot manager, how can I boot another drive?

    in Windows 10 Software and Apps
    Lost drive with boot manager, how can I boot another drive?: Hi, I have a desktop with multiple drives. Win 10 was installed on Drive 0, and I assume that is where the boot loader was. I have Win 11 installed on Partition 5 of Drive 1. Drive 1 also has Linux on it and the Linux grub2 boot loader. Previously, when I wanted to access Win...
  3. Boot fails after enabling bitlocker

    in AntiVirus, Firewalls and System Security
    Boot fails after enabling bitlocker: Hi! After enabling Bitlocker on my Windows 10 system drive I'm unable to boot. I have turned on Bitlocker on my C drive with the full-drive encryption and new-not-backward-compatible-encryption options not sure how are the options exactly called. I have backed up the recovery...
  4. Booting Ubuntu from USB while Bitlocker is enabled.

    in Windows 10 Software and Apps
    Booting Ubuntu from USB while Bitlocker is enabled.: I recently restarted by Dell inspiron 16 7620 and booted from my live Ubuntu USB without issue. I shutdown, removed the USB and powered back on and got the Bitlocker recovery key prompt. I entered the key and booted into Windows 11 without issue. My intentions are to use my...
  5. Booting Ubuntu from USB while Bitlocker is enabled.

    in Windows 10 Gaming
    Booting Ubuntu from USB while Bitlocker is enabled.: I recently restarted by Dell inspiron 16 7620 and booted from my live Ubuntu USB without issue. I shutdown, removed the USB and powered back on and got the Bitlocker recovery key prompt. I entered the key and booted into Windows 11 without issue. My intentions are to use my...
  6. No boot Manager when booting up!

    in Windows 10 Gaming
    No boot Manager when booting up!: I am using EasyBCD to manage 3 drives each with windows installations W11 Pro, W11 Pro 2 and W10 Pro, however, Easy BCD shows all 3 installations, but when booting up there is no boot manager showing and it always boots up into windows 11 the one set to default. I have tried...
  7. No boot Manager when booting up!

    in Windows 10 Software and Apps
    No boot Manager when booting up!: I am using EasyBCD to manage 3 drives each with windows installations W11 Pro, W11 Pro 2 and W10 Pro, however, Easy BCD shows all 3 installations, but when booting up there is no boot manager showing and it always boots up into windows 11 the one set to default. I have tried...
  8. Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...

    in Windows 10 Network and Sharing
    Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...: I am using a DELL laptop and I have recently replaced the SSD inside it with another. In order to complete the file transfer, I moved the data to an external drive, booted Windows from it, and transferred the contents of the drive to the SSD. The SSD is completely functional...
  9. Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...

    in Windows 10 Gaming
    Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...: I am using a DELL laptop and I have recently replaced the SSD inside it with another. In order to complete the file transfer, I moved the data to an external drive, booted Windows from it, and transferred the contents of the drive to the SSD. The SSD is completely functional...
  10. Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...

    in Windows 10 Software and Apps
    Bitlocker enabled automatically when booting Windows from an alternate Drive and no key was...: I am using a DELL laptop and I have recently replaced the SSD inside it with another. In order to complete the file transfer, I moved the data to an external drive, booted Windows from it, and transferred the contents of the drive to the SSD. The SSD is completely functional...