Windows 10: Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry

Discus and support Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry in AntiVirus, Firewalls and System Security to solve the problem; Hello, After looking through the "Group Policy Reference for Windows" https://www.microsoft.com/en-us/download/confirmation.aspx?id=25250 I found... Discussion in 'AntiVirus, Firewalls and System Security' started by Bradley Fronberry, Mar 13, 2020.

  1. Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry


    Hello,

    After looking through the "Group Policy Reference for Windows" https://www.microsoft.com/en-us/download/confirmation.aspx?id=25250 I found the registry key changes to turn on "Require additional authentication at startup."Line 3823 I push the proper registry settings and it activates properly requiring a USB startup key. The issue is when trying to deactivate the setting. I remove the keys I've added but the computer still looks for a USB Key to be inserted after reboot. I've tried numerous times and as well have pushed the "gpupdate" command prior to reboot. Thoughts, reasons, workaround, fixes?

    :)
     
    Bradley Fronberry, Mar 13, 2020
    #1
  2. kevvyb Win User

    Bitlocker Process - 2 bek (startup) keys and one recovery key


    I don't know if this what should happen but I was watching the process of key storage as I went through the BitLocker encryption process.

    To see what was happening on the usb drive to which I was saving the startup and recovery keys I had to enable 'show system files' in order to see the .bek key.* I have seen posts stating that these are 'hidden files'. Maybe they are both? I am assuming that if the restart to check that usb key works succeeds, then presumably the machine is 'booting' from the usb key (.bek file)...?

    1. Turned bitlocker on the C drive
    2. usb drive was preselected to save STARTUP KEY
    3. clicked on save
    4. ONE bek key created on USB drive
    5. Question re save location for recovery key > selected save to usb flash drive
    6. USB drive preselected > clicked on save
    7. Another bek key and recovery key saved with same timestamp
    8. clicked on next > encrypt entire drive > run check > restart
    So TWO .bek (startup) keys......Does anyone know why two?

    One for each partition although I did not yet have BitLocker turned on my data partition.
    Or maybe one for the Windows recovery partition?* Although I thought I had read that this remained unencrypted...?
     
    kevvyb, Mar 13, 2020
    #2
  3. Jan Del Win User
    Bitlocker USB

    Hi, Margaret.

    BitLocker requires you to have a USB key in able to access the information. You can create a USB key by using a blank thumb drive or USB drive formatted to NTFS OR FAT32 and follow these steps:

    • Click Start and go to Control Panel.
    • Look for System and Security then click it.
    • Select BitLocker Drive Encryption.
    • Under BitLocker Drive Encryption, click Turn on BitLocker.
    • Choose how you want to unlock your drive during startup: Insert a USB flash drive or
      Enter a Password and then click Next.
    • On the How Do You Want To Store Your Recovery Key Page, click Save the Recovery Key To A File.
    • In the Save BitLocker Recovery Key As dialog box, choose a save location, and then click
      Save.
    • You can now print the recovery key if you want to. When you have finished, click
      Next.
    • On the Are You Ready To Encrypt This Drive page, click Start Encrypting.

    Note: Do not remove the USB flash drive until the encryption process is complete. How long the encryption process takes depends on the size of the drive and other factors.

    Get back to us if you need further assistance.
     
    Jan Del, Mar 13, 2020
    #3
  4. Xylee Del Win User

    Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry

    Xylee Del, Mar 13, 2020
    #4
Thema:

Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry

Loading...
  1. Unable to Deactivate "TPMandStartupKey" USB Bitlocker Startup key after changing via registry - Similar Threads - Unable Deactivate TPMandStartupKey

  2. Windows key deactivated after changing device name

    in Windows 10 Gaming
    Windows key deactivated after changing device name: Greetings, I changed device name of one of our Laptops and since then windows licence got deactivated and it says that licence is activated on another PC. I tried removing it from PC and activating it again, but it didn't work. Is there a solution to this? Is there a way to...
  3. Windows key deactivated after changing device name

    in Windows 10 Software and Apps
    Windows key deactivated after changing device name: Greetings, I changed device name of one of our Laptops and since then windows licence got deactivated and it says that licence is activated on another PC. I tried removing it from PC and activating it again, but it didn't work. Is there a solution to this? Is there a way to...
  4. Unable to Change Permission to Full Control on Registry Keys

    in Windows 10 Gaming
    Unable to Change Permission to Full Control on Registry Keys: I need to edit a registry key but before I do so, I need to be granted full control of the key. I am getting an error message when I try to do this. I am already listed as the owner of the key. I have tried changing both my administrator account as well as my use account to...
  5. Unable to Change Permission to Full Control on Registry Keys

    in Windows 10 Software and Apps
    Unable to Change Permission to Full Control on Registry Keys: I need to edit a registry key but before I do so, I need to be granted full control of the key. I am getting an error message when I try to do this. I am already listed as the owner of the key. I have tried changing both my administrator account as well as my use account to...
  6. Bitlocker: is the USB startup key the same as the recovery key?

    in Windows 10 Gaming
    Bitlocker: is the USB startup key the same as the recovery key?: Hi guys,I want to encrypt my computer with bitlocker, using the USB startup key.But when my computer gets stolen, the disk can be put inside another computer. Can the plain text visible startup key on the USB then unlock the drive? Or are these keys different?Thanks!Tonka....
  7. Bitlocker: is the USB startup key the same as the recovery key?

    in Windows 10 Software and Apps
    Bitlocker: is the USB startup key the same as the recovery key?: Hi guys,I want to encrypt my computer with bitlocker, using the USB startup key.But when my computer gets stolen, the disk can be put inside another computer. Can the plain text visible startup key on the USB then unlock the drive? Or are these keys different?Thanks!Tonka....
  8. Disabling Keys via Registry

    in Windows 10 Support
    Disabling Keys via Registry: I need to disable the Ctrl, Alt, Del, Esc, an function keys. These need to be registry edits, not through 3rd party software. Thanks in advance :) 141760
  9. Set two keys via registry

    in Windows 10 Support
    Set two keys via registry: Hello Please somebody help, in Windows 10 64-bit 1903 , in settings under Search then first tab is Permissions & history I want to check if any of these 2 items can be set via registry a) Radio button : to Off b) button: Windows cloud search to Off thanks in advance for any...
  10. Set three keys via registry

    in Windows 10 Support
    Set three keys via registry: Hello Please somebody help, in Windows 10 64-bit 1903 , in settings under Search then first tab is Permissions & history I want to check if any of these 3 items can be set via registry a) Radio button : to Off b) button: Windows cloud search to Off c) button " My device...