Windows 10: Windows 10 BitLocker w/ TPM-Only authentication

Discus and support Windows 10 BitLocker w/ TPM-Only authentication in AntiVirus, Firewalls and System Security to solve the problem; I recently installed Windows 10 on a new computer I built. I then decided to encrypt my drives, so I installed a TPM on my motherboard. It is enabled... Discussion in 'AntiVirus, Firewalls and System Security' started by DavidVersteeg, Jul 17, 2018.

  1. Windows 10 BitLocker w/ TPM-Only authentication


    I recently installed Windows 10 on a new computer I built. I then decided to encrypt my drives, so I installed a TPM on my motherboard. It is enabled in BIOS and properly recognized in Windows' Device Manager. However, when I tried to encrypt my OS drive, things didn't go so simple as hoped.


    At first, when I clicked to turn on BitLocker on the drive, it gave me an error saying 'The startup options on this PC are not configured correctly'. After an online search, I was able to get past this by changing the 'Computer Administration\Administrative Template\Windows Components\BitLocker Drive Encryption\Operating System Drives\Require additional authentication at startup' settings in gpedit. I just had to enable the policy and uncheck the 'Allow BitLocker without a compatible TPM' and the BitLocker setup wizard allowed me to continue. The first thing it asked me for was to insert a removable USB flash drive to save a startup key to. After doing so, I completed the wizard and restarted the computer.


    After the restart I got a message regarding something about automatically unlocking (I cannot recall the exact message), but another online search found that this could be remedied by changing some settings in my BIOS to enable booting from USB. After doing so, I went through the BitLocker wizard again and this time I was able to encrypt my OS drive.


    The issue, is that it required me to have the USB drive with the key in it during boot. What I want, however, is a TPM-only authentication. I just cannot figure out how to do this. I went through various setting changes while the drive was encrypted, but to no avail, so I decrypted the drive to see if I missed something in the setup wizard. I had a couple more runs trying different settings in the gpedit, but nothing yielded the result I'm looking for. When I change 'Configure TPM startup' to 'Require TPM' in the aforementioned 'Require additional authentication on startup' policy, the BitLocker wizard prompts me the message that 'The Group Policy settings for BitLocker startup options are in conflict and cannot be applied.'

    The TPM Management Tool gives me the status that 'The TPM is ready for use, with reduced functionality. Information Flags: 0x80000'.


    What am I doing wrong? How can I get my OS drive encrypted with TPM-only authorization?


    Thanks in advance.


    Additional system details:

    Windows 10 Pro Build 1803

    OS Drive file system: NTFS

    :)
     
    DavidVersteeg, Jul 17, 2018
    #1
  2. RJO218 Win User

    Bitlocker without TPM available with Windows 10 upgrade?

    All pc's at my small business are currently using Windows 8.1 Pro. We are using Bitlocker without TPM. Will Bitlocker w/o TPM be available with the Windows 10 upgrade?
     
    RJO218, Jul 17, 2018
    #2
  3. Bitlocker TPM only authentication question

    I have Windows 10 pro systems and I am testing out bitlocker with TPM only, no pin. Is the drive encrypted still before I put in my Windows password? I ask this because I wonder if the drive is still susceptible to any password reset tricks, such as
    changing the accessibility program to command prompt, which can give them access to change the password? What if this OS encrypted drive was setup as a slave on this machine from which it was encrypted, would the tpm authenticate it and allow it to be read?
    Curious.
     
    BobBoklewski, Jul 17, 2018
    #3
  4. Windows 10 BitLocker w/ TPM-Only authentication

    Bitlocker in Windows 10 without TPM

    Thanks. I tried this and only got so far.

    Administrative Templates>Windows Components.

    After that, there is no option for "Bit Locker Drive Encryption" So I can't follow the steps from there.

    I am trying to install Bitlocker on a Windows 10 pro laptop. The error message I get is: "This device can't use a Trusted Platform Moduel. Your administrator must set the "Allow BitLocker without a compatible TPM" option in the "Required additional authentication
    at startup" policy for OS volumes.

    Under TMP Authorization it says "Compatible Trusted Moduel cannot be found on this computer. Verify that this computer has a 1.2 TPM or later and it is turned on in the BIOS"

    Please help. Bitlocker is the only reason I paid to upgrade to win 10 pro.
     
    windowsatemysoul, Jul 17, 2018
    #4
Thema:

Windows 10 BitLocker w/ TPM-Only authentication

Loading...
  1. Windows 10 BitLocker w/ TPM-Only authentication - Similar Threads - BitLocker TPM authentication

  2. Bitlocker and TPM

    in Windows 10 Gaming
    Bitlocker and TPM: So I turned off Bitlocker since I had to put in the code every time. I also disabled the Display since I took off the Display. I then restarted it, and it did not show up anymore, so I can not turn it back on. Also, TPM is nowhere to be found on my computer, a Lenovo Yoga 7i...
  3. Bitlocker and TPM

    in Windows 10 Software and Apps
    Bitlocker and TPM: So I turned off Bitlocker since I had to put in the code every time. I also disabled the Display since I took off the Display. I then restarted it, and it did not show up anymore, so I can not turn it back on. Also, TPM is nowhere to be found on my computer, a Lenovo Yoga 7i...
  4. Unable to Remove TPM-Only from BitLocker on Windows 11

    in Windows 10 Gaming
    Unable to Remove TPM-Only from BitLocker on Windows 11: Issue: Unable to Remove TPM-Only from BitLocker on Windows 11 System Details: OS: Windows 11 Pro Version 10.0.26100 BitLocker Version: 2.0 Encryption Method: XTS-AES 128 Boot Drive C: Encryption Status: Fully Encrypted Problem Description: I enabled BitLocker with TPM + PIN,...
  5. Unable to Remove TPM-Only from BitLocker on Windows 11

    in Windows 10 Software and Apps
    Unable to Remove TPM-Only from BitLocker on Windows 11: Issue: Unable to Remove TPM-Only from BitLocker on Windows 11 System Details: OS: Windows 11 Pro Version 10.0.26100 BitLocker Version: 2.0 Encryption Method: XTS-AES 128 Boot Drive C: Encryption Status: Fully Encrypted Problem Description: I enabled BitLocker with TPM + PIN,...
  6. Can't enable BitLocker with TPM only

    in Windows 10 Ask Insider
    Can't enable BitLocker with TPM only: I'm having a hard time getting BitLocker to work the same way on my newly built desktop as it does on my Surface Pro 3, i.e. the drive is unlocked instantly with the TPM and I go straight to the windows login screen. When I try to configure BitLocker it just wants me to plug...
  7. BitLocker, TPM and a Ryzen

    in Windows 10 Support
    BitLocker, TPM and a Ryzen: I simply love the BitLocker functionality. I've always used it and still using for my Intel laptop without TPM, but with a small change in Group Policy to skip TPM and use a password on every boot... and it simply working. Hovewer, now I've a AMD PC with Ryzen 1700x onboard....
  8. Bitlocker with TPM

    in AntiVirus, Firewalls and System Security
    Bitlocker with TPM: Hi , I,m not sure if this is the right place to post this . Anyway , My query is about encryption on win10 pro . Previously I had a laptop with no TPM so I had to us the group policy editor to allow encryption to work , fine ,all was working and I had to type a password...
  9. BitLocker with TPM mode protection only?

    in AntiVirus, Firewalls and System Security
    BitLocker with TPM mode protection only?: I have a laptop which is a Dell E6440 and was just wondering if it vulnerable to these DMA attacks through Thunderbolt and Firewire methods. Reason asking, is because I have BitLocker full disk encryption turned ON with TPM-Only protection (meaning no PIN). Would this be...
  10. How to Use Bitlocker on Only Non System Drive and without TPM

    in AntiVirus, Firewalls and System Security
    How to Use Bitlocker on Only Non System Drive and without TPM: I want to use Bitlocker on my Non System E Drive without TPM. I read somewhere to do the following for without TPM: " Under Local Computer Policy navigate to Computer Configuration \ Administrative Templates \ Windows Components \ Bit Locker Drive Encryption \ Operating...