BitLocker Technical Detail (2024)

BitLocker is a data protection feature which protects a disk from being read if it is stolen, lost or inappropriately decommissioned.

Trusted Platform Module

BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2. The TPM is a hardware component installed in many newer computers by the computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline.

System integrity verification

BitLocker can use a TPM to verify the integrity of early boot components and boot configuration data. This helps ensure that BitLocker makes the encrypted drive accessible only if those components have not been tampered with and the encrypted drive is located in the original computer.

BitLocker helps ensure the integrity of the start-up process by taking the following actions:

  • Provide a method to check that early boot file integrity has been maintained, and help ensure that there has been no adversarial modification of those files, such as with boot sector viruses or rootkits.
  • Enhance protection to mitigate offline software-based attacks. Any alternative software that might start the system does not have access to the decryption keys for the Windows operating system drive.
  • Lock the system when it is tampered with. If any monitored files have been tampered with, the system does not start. This alerts the user to the tampering, because the system fails to start as usual. In the event that system lockout occurs, BitLocker offers a simple recovery process.

Suspending BitLocker

BitLocker drive encryption needs to be suspended prior to making any of the following changes:

  • OS Upgrade/Installing additional OS
  • Hardware Change (e.g. Installing PCI cards)
  • Firmware updates
  • Non-Microsoft application updates that modify boot components.

BitLocker encrypted devices use the TPM chip to verify the integrity of early boot components and boot configuration data. This helps ensure that BitLocker makes the encrypted drive accessible only if those components have not been tampered with and the encrypted drive is located in the original computer.

This means that if a hardware change or change in the Boot Configuration Data is detected on boot, TPM will not release the BitLocker key and the computer will not be able to boot to Windows. BitLocker therefore needs to be suspended before making any of the above changes.

Contact the ISD IT Services if you need to do this.

Recovery key

A recovery key is required when the computer cannot access the OS partition. This happens if the TPM chip cannot verify the integrity of early boot components and boot configuration data or the TPM chip is not present at all.

Such scenarios are:

  • Upgrade of the system board or TPM.
  • Damage to a computer that causes the user to move the BitLocker-enabled volume to a different computer with a different TPM or no TPM at all.
  • Turning off, disabling, or clearing the TPM.
  • Upgrading critical early boot components that causes the TPM to fail validation.

When you need to enter your recovery key, the computer – instead of booting to Windows – will show the following screen:

BitLocker Technical Detail (1)

The recovery keys are stored securely in the UCL Active Directory and access is tightly controlled. If you do find yourself in a situation where a recovery key is required you should call the ISD IT Services in the first instance who will then invoke the key recovery process. The Recovery Key ID (location highlighted above) should be provided when logging the call.

BitLocker Technical Detail (2024)

FAQs

Why is my PC asking for BitLocker recovery key? ›

I understand you are encountering a BitLocker recovery key prompt after updating your BIOS, it generally means that the system's security configuration changed, prompting BitLocker to require the recovery key to ensure the system hasn't been tampered with.

How to fix BitLocker suspended? ›

Solutions: To resolve BitLocker suspension, reconnect the hard drive to the computer, and then unlock the drive using the BitLocker recovery key. If the issue is related to changes in the operating system or hardware, verify that the TPM is properly configured, and that the BitLocker configuration is set up correctly.

How to permanently unlock BitLocker drive? ›

  1. Type and search [Manage BitLocker] in the Windows search bar①, then click [Open]②.
  2. Click [Turn off BitLocker]③ on the drive that you want to decrypt. ...
  3. Confirm whether you want to decrypt your drive, then select [Turn off BitLocker]④ to start turning off BitLocker, and your drive will not be protected anymore.
Oct 24, 2023

How do I get rid of BitLocker error? ›

You can access Windows Bitlocker Manager and with the key, disable it.
  1. Press Windows, type Manage BitLocker;
  2. It will appear in the search, click on it to open it;
  3. It will show your computer's disks and which encryption is enabled;
  4. Click Disable BitLocker on the desired disk;
  5. Proceed to the end to finish.
Mar 27, 2023

How do I get my computer out of BitLocker mode? ›

To exit the BitLocker recovery screen, you will need to enter the recovery key. The recovery key is a 48-digit code that was provided to you when you first enabled BitLocker on your device. If you don't have the recovery key, you can't enter the drive.

How do I force BitLocker to disable? ›

Press Windows Start button. Type bitlocker. Click Manage BitLocker to enter the BitLocker Drive Encryption menu. Select Turn off BitLocker to proceed with decryption.

How long does BitLocker stay suspended? ›

Specify zero to suspend protection indefinitely until you resume it by using the Resume-BitLocker cmdlet.

What is the free software to unlock BitLocker drive? ›

DiskGenius supports to unlock BitLocker drives with password, recovery key or BEK file, and it can unlock BitLocker encrypted drive on computers whose system does not support BitLocker, such as Windows 10/8/7 Home edition, Windows XP and WinPE.

What is the command to unlock a BitLocker drive? ›

Open Command Prompt as an administrator and type one of the following commands: manage-bde -unlock X: -Password or manage-bde -unlock X: -RecoveryPassword. Remember to replace the letter “X” with the drive letter of the BitLocker encrypted drive.

Is it possible to unlock BitLocker without a key? ›

If you don't have the BitLocker password and recovery key, you may need to format the drive to remove the encryption, or use the third-party tools, such as Passware Kit, Elcomsoft Forensic Disk Decryptor, and Elcomsoft Distributed Password Recovery.

What causes BitLocker to trigger? ›

The BitLocker recovery key prompt can be triggered by a variety of reasons, including hardware changes, software updates (especially if BIOS update is involved), etc. It is not necessarily alarming. The recent security update can be definitely a trigger here as well.

Why is my PC showing BitLocker? ›

If you experiences that the computer shows BitLocker recovery screen after power on, it means that the HDD/SDD has been encrypted. (HDD/SDD is locked.) Once PC hardware components have been replaced or BIOS settings have been changed, all may cause system shows BitLocker recovery screen after power on.

How can I recover BitLocker? ›

Here are the steps to do so:
  1. Go to the Microsoft BitLocker Recovery Keys page (https://account.microsoft.com/devices/recoverykey).
  2. Sign in with the Microsoft account that you used to set up BitLocker on your LG gram laptop.
  3. Enter the recovery key ID that is displayed on the BitLocker screen.
Feb 16, 2024

Top Articles
Best Internet Security Software | Antivirus Total Security
4 Real Estate Appraisal & Valuation Methods [Complete Guide]
Www.craigslist Virginia
Noaa Charleston Wv
Breaded Mushrooms
Craigslist Campers Greenville Sc
Couchtuner The Office
Math Playground Protractor
Craigslist Parsippany Nj Rooms For Rent
Bloxburg Image Ids
Www.megaredrewards.com
Whiskeytown Camera
Becky Hudson Free
Which Is A Popular Southern Hemisphere Destination Microsoft Rewards
Jet Ski Rental Conneaut Lake Pa
Pro Groom Prices – The Pet Centre
C Spire Express Pay
ExploreLearning on LinkedIn: This month's featured product is our ExploreLearning Gizmos Pen Pack, the…
Flights To Frankfort Kentucky
Peraton Sso
Billionaire Ken Griffin Doesn’t Like His Portrayal In GameStop Movie ‘Dumb Money,’ So He’s Throwing A Tantrum: Report
Odfl4Us Driver Login
No Hard Feelings - Stream: Jetzt Film online anschauen
Moving Sales Craigslist
Terry Bradshaw | Biography, Stats, & Facts
Dashboard Unt
800-695-2780
Doctors of Optometry - Westchester Mall | Trusted Eye Doctors in White Plains, NY
Is Poke Healthy? Benefits, Risks, and Tips
3 Ways to Format a Computer - wikiHow
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Alima Becker
Graphic Look Inside Jeffrey Dresser
Palmadise Rv Lot
Xemu Vs Cxbx
How Much Is Mink V3
Acadis Portal Missouri
Alpha Asher Chapter 130
Dollar Tree's 1,000 store closure tells the perils of poor acquisitions
Trizzle Aarp
Henry Ford’s Greatest Achievements and Inventions - World History Edu
Ukraine-Krieg - Militärexperte: "Momentum bei den Russen"
Isabella Duan Ahn Stanford
Sig Mlok Bayonet Mount
Thotsbook Com
Value Village Silver Spring Photos
Craigslist Chautauqua Ny
Okta Hendrick Login
O.c Craigslist
Suzanne Olsen Swift River
La Fitness Oxford Valley Class Schedule
7 National Titles Forum
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 5767

Rating: 4 / 5 (41 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.