How to enable BitLocker PIN on startup on a Microsoft Surface Laptop 7

BirendraN 0 Reputation points
2024-12-17T03:59:09.6733333+00:00

I would be grateful if any MVPs could reply whose focus is on Security & BitLocker.

Issue

  • I have just purchased a Microsoft Surface Laptop 7 with Windows 11 Home installed. This is a traditional “clamshell” laptop i.e. it has a keyboard and screen.
  • I updated the OS by purchasing Windows Pro which is now done.
  • BitLocker is enabled
  • The issue I have is that I cannot setup BitLocker to mandate that a BitLocker PIN is required when the PC boots up.
  • I have set the appropriate GPO for BitLocker to set "Require Startup PIN with TPM" .
  • This then does give the option in Manage BitLocker to create a startup PIN.
  • But when I click that option, it fails with this error: "ERROR: An error occurred (code 0x803100b5): No pre-boot keyboard detected. The user may not be able to provide required input to unlock the volume."

 

My thoughts.

  1. This is a traditional clam-shell laptop but my hypothesis is that Microsoft may treat it as a slate (tablet device). Indeed when running System Information I see "Platform Role Slate"
  2. I have also come across in my research the BitLocker GPO “Enable use of Bitlocker authentication requiring preboot keyboard input on slates”
  3. I am loathe to try that though because reading that GPO it clearly states that an alternative USB Keyboard would be required to provide the BitLocker PIN. I cannot assume that I would be able to use the keyboard on the Surface laptop itself, which is what I want of course.

Thanks

Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.