Win11 with Bitlocker - disable TPM

Anonymous
2024-07-27T21:29:39+00:00

Hello.

I have a Win 11 system with Bitlocker enabled on the OS drive with the key stored in TPM. I would like to stop using TPM to store the key and store it on the drive - having it encrypted with a PIN/password only. I'm aware of the risks (brute force attacks), but this is really not the vector I'm protecting against. I want to keep TPM enabled in UEFI. I'm dual booting and I want to use the chip with the other OS. Of course, dual booting often breaks the verification process and I'm asked to enter the recovery key, which is quite tedious.

I already tried to check the "Allow Bitlocker without a compatible TPM ..." option in "Require additional authentication at startup", enabled "Allow enhanced PINs for startup" and set a PIN in the Bitlocker management. On boot, I'm asked for the PIN, but the TPM is used afterwards to fetch the key! I know it because I'm asked for the recovery after entering the pin as the TPM does not provide system with the key - TPM verification failed because of dual boot.

Thank you for your help.

*** Moved from Windows / Windows 11 / Security and privacy ***

Windows for business Windows Client for IT Pros Devices and deployment Recovery key

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes
Accepted answer
  1. Anonymous
    2024-08-29T02:33:27+00:00

    Hello,

    This policy can allow BitLocker without TPM.

    Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives > Require additional authentication at startup.

    Enable this option: Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive).

    Best regards,

    Molly

    1 person found this answer helpful.
    0 comments No comments

8 additional answers

Sort by: Most helpful
  1. Anonymous
    2024-07-30T01:17:57+00:00

    Hello,

    Thank you for posting in Microsoft Community forum.

    Based on the description, I understand your question is related to disable TPM.

    Open group policy, navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.

    Double-click on Require additional authentication at startup.

    Select Enabled and check the option Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive).

    Click OK to apply the changes.

    Go back to Control Panel > System and Security > BitLocker Drive Encryption.

    Click on “Turn on BitLocker” next to the OS drive.

    When prompted, choose to use a password or PIN for startup.

    Follow the prompts to set up BitLocker with your chosen authentication method.

    Restart your computer to ensure that BitLocker prompts you for the PIN/password at startup and does not rely on the TPM for key retrieval.

    Have a nice day. 

    Best Regards,

    Molly

    0 comments No comments
  2. Anonymous
    2024-07-31T06:59:36+00:00

    Hi,

    I actually did that but in a different order. I set the "Allow BitLocker without a compatible TPM" with Bitlocker already activated.

    Are you saying I have to disable bitlocker, set the option and re-enable it?

    thanks

    0 comments No comments
  3. Anonymous
    2024-08-02T06:44:43+00:00

    Hello,

    Yes, you can try backup and reenable it, check if the new policy works.

    Best regards,

    Molly

    0 comments No comments
  4. Anonymous
    2024-08-15T17:46:19+00:00

    I have tried suspending Bitlocker, that didn't help. By disabling you really mean decrypting the whole drive? That seems like a brutal solution to me.

    0 comments No comments