Bitlocker issue

William Rubial 20 Reputation points
2025-06-12T14:56:04.4266667+00:00

I use bitlocker on my PC. Recentely I actived by GPO bitlocker unlock before windows boot up. I use a pendrive to unlock bitlocker. I've tryed to encrypt this pendrive to improve security, but it doesnt read because its encrypted. Is there any solution?

Windows for business Windows Client for IT Pros User experience Other
0 comments No comments
{count} votes

Accepted answer
  1. Beatrix 880 Reputation points Independent Advisor
    2025-06-15T12:21:45.26+00:00

    Hi William,

    You can't encrypt the USB drive used for BitLocker pre-boot unlock, as it needs to remain unencrypted. This is because the BitLocker pre-boot environment (before Windows loads) lacks the necessary drivers or decryption capabilities to access an encrypted USB drive. The startup key must be stored in a raw, readable format for BitLocker to recognize it during boot.

    I highly recommend two alternative approaches that offer a good balance between security and usability:

    Option 1: Continue using the unencrypted USB for BitLocker, but store it securely when not in use (e.g., on a keychain or in a locked drawer).

    Option 2 (more secure): Switch to using TPM + PIN or TPM + USB key, so you're not relying solely on the USB drive.

    Hope this helps you move forward and feel free to reach out if you have any questions!


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.