Bitlocker Recovery Screen occurring after windows updates

David Price 1 Reputation point
2020-10-01T08:26:29.927+00:00

Various users across our clients have been getting bitlocker recovery screens after doing windows updates to their devices. It appears that the updates also include a type of firmware update. We have also tested and were able to replicate this in house.

I have been looking into the matter but it doesn't appear to be clear as to whether this is intended. Does Windows update know to suspend bitlocker when applying firmware changes?

All our clients use Dell devices on the latest features update of Windows 10, all of which have TPM chips.

This causes a lot of disruption as we have to get these users to power cycle their devices to reset hardware and get logged back on. If that fails, provide them with the bitlocker key to get them logged on.

This appears to have started this year when Microsoft added the feature to allow windows to update drivers.

As we have so a large quantity of users, it is not practical to go around and manually suspend bitlocker, nor is it acceptable to allow users or have ourselves hold back updates as this impacts security and compliance for them and starts causing problems with device compliancy in Intune.

Do we have an idea of what can be causing this? Is windows meant to suspend bitlocker and that isn't happening?
Why is windows doing firmware upgrades that will force bitlocker recovery to prompt when it can't suspend bitlocker?

This is becoming a growing a problem and we need to get to the bottom of this. I am sorry if there is similar threads to this problem, but the ones I found either didn't have a response, had a solution that did not work with our requirements or wasn't within the same scope.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,914 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jenny Feng 14,131 Reputation points
    2020-10-01T09:28:14.943+00:00

    @David Price
    Hi,

    From the official article:
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-upgrading-faq
    Users need to suspend BitLocker for Non-Microsoft software updates, such as:

    Computer manufacturer firmware updates
    TPM firmware updates
    Non-Microsoft application updates that modify boot components

    If these types of upgrades or updates are applied without suspending BitLocker, your computer will enter recovery mode when restarting and will require a recovery key or password to access the computer.

    Hope above information can help you.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.