Share via

Bitlocker TMP key release moment

nmbrt 21 Reputation points
2022-04-22T12:30:26.217+00:00

Hello,

When does the TPM release the BitLocker key? In the case of protection with TPM only.

Let's say my computer is turned off, with only the TPM protection. If I turn it on without entering my user session, is the VMK in my RAM?

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments

Answer accepted by question author

Limitless Technology 40,101 Reputation points
2022-04-26T10:31:29.12+00:00

Hello,

Thank you for reaching out.

That would not be possible to access the encrypted data if the appropriate encryption key was not stored in the computer’s volatile memory (RAM). While the BitLocker volume is mounted, the volume master key (VMK) resides in the computer’s RAM.

It is important to understand that a fully encrypted BitLocker volume will be automatically mounted and unlocked during the Windows boot process, long before the user signs in to the system with their Windows credentials. The TPM module will release the encryption metadata and decrypt the protected volume master key (VMK) automatically during the boot.


--If the reply was helpful, please don’t forget to upvote or accept as answer. --

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. MTG 1,261 Reputation points
    2022-04-25T10:52:10.217+00:00

    Yes, it is.
    It's release right before the OS starts, else, c: would not be accessible.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.