@Warren Stevens, Thanks for posting in Q&A. From the article, it mentioned when "TPM startup PIN or key" is set, BitLocker can't silently enable on the device, and instead requires interaction from the end user. Please confirm if you want this.
Meanwhile for the requirement for TPM startup PIN or key, after checking the BitLocker documents, I find the device must have TPM 1.2 or later versions. A device with a TPM must also have a Trusted Computing Group (TCG)-compliant BIOS or UEFI firmware. The BIOS or UEFI firmware establishes a chain of trust for the preboot startup, and it must include support for TCG-specified Static Root of Trust Measurement. You can see more details in the following link:
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.