BitLocker Drive Encryption Failure

Anonymous
2024-07-31T16:12:39+00:00

I have a device managed via Intune and silent BitLocker encryption is the only thing showing as non-compliant.

In review the device, BitLocker encryption has failed, i see it throws out this prompt:

I went through the device local GP settings and all settings are as they should be per below:

in review event logs I get the following:

summarize

Event ID: 834 BitLocker determined that the TCG log is invalid for use of Secure Boot. The filtered TCG log for PCR[7] is included in this event.

Event ID: 778 The BitLocker volume C: was reverted to an unprotected state.

Event ID: 851 Failed to enable Silent Encryption. Error: The Group Policy settings for BitLocker startup options are in conflict and cannot be applied. Contact your system administrator for more information..

Event ID: 835 BitLocker cannot use Secure Boot for integrity because the expected TCG Log entry for the OS Loader Authority has invalid structure. The event is expected to be an EV_EFI_VARIABLE_AUTHORITY event. The event data must be formatted as an EFI_VARIABLE_DATA structure with VariableName set to EFI_IMAGE_SECURITY_DATABASEGUID and UnicodeName set to 'db'.

Event ID: 851 Failed to enable Silent Encryption. Error: BitLocker Drive Encryption is already performing an operation on this drive. Please complete all operations before continuing..

I have seen one online documentation advising to go into RegEdit and change any value data of 0 or 1 and delete these entries. Is this really the only fix or could it break the policies. What about any value with 2?

Windows for home | Windows 10 | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. paulr0511 39,635 Reputation points Independent Advisor
    2024-07-31T17:46:52+00:00

    Good day Juan! I would suggest to post this query to our neighbor forum from the link below as this is best suited in there. They are more oriented on with regards to this type queries/issues and there will be IT Pros and Gurus/System Admins/IT Admins and the likes who has the same deployment or setup in this type of environment and are available that will be able to fulfill your query out there.

    https://learn.microsoft.com/en-us/answers/ask

    Regards,

    Paul R.

    0 comments No comments
  2. Anonymous
    2024-08-01T23:22:53+00:00

    thanks

    i was able to resolve by removing to FVE keys and changing UseTPM value from 1 to 2

    0 comments No comments
  3. paulr0511 39,635 Reputation points Independent Advisor
    2024-08-02T04:05:10+00:00

    Glad to know that this has been sorted out and have a good weekend ahead Juan.

    0 comments No comments