Bitlocker startup

Casper 0 Reputation points
2026-08-24T15:59:48.7966667+00:00

Hello,
After a Windows 11 update my pc keeps booting on Bitlocker. If I choose N it would boot up normally. I checked my drive and its not encrypted. I tried disabling it on services.msc but it still boots on bitlocker. Any advice how can I startup normally without going through bitlocker? Thanks :)f5c04138-3ea2-4b9d-a7ba-7beb2cbc165a

Screenshot_536

Windows for home | Windows 11 | Windows update
0 comments No comments

2 answers

Sort by: Most helpful
  1. Clary-N 15,095 Reputation points Microsoft External Staff Moderator
    2026-08-25T02:50:55.6966667+00:00

    Hi Casper,

    I wanted to follow up and see if you've had a chance to try the AI Answer's suggestions yet. If so, could you let me know how it went and whether the TPM/fTPM prompt still appears on every startup?

    As an additional check, I recommend opening Run (Win + R), typing tpm.msc and confirming whether Windows reports that the TPM is ready for use or displays any warnings or errors. You can also check Settings > Privacy & Security > Device Encryption to confirm whether Device Encryption is enabled on the device.

    Since you mentioned the issue started after a Windows 11 update, could you also share your Windows version and OS Build by pressing Win + R, typing winver and posting a screenshot of the result?

    If you have not made any hardware changes and the issue began immediately after the update, it may also be worth checking whether a BIOS/UEFI update is available from your PC or motherboard manufacturer, as TPM-related startup prompts can sometimes be resolved through firmware updates.

    I look forward to your update.


    If you have extra questions about this answer, please click "Comment".  

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-08-24T16:00:11.78+00:00

    That screen is a TPM/fTPM reset prompt from firmware, not Windows BitLocker asking to unlock an encrypted drive. The command output shown confirms the C: drive is fully decrypted, Protection Off, and has no key protectors.

    The prompt appears because TPM-related boot measurements changed. BitLocker recovery can be triggered by changes such as:

    • changing boot configuration settings
    • changing BIOS or UEFI firmware or other early boot components
    • adding or removing hardware

    Since the drive is not encrypted, disabling the BitLocker service in services.msc will not stop this firmware TPM prompt.

    Use this path:

    1. Check BIOS/UEFI settings
      • Open firmware setup during startup.
      • Verify TPM/fTPM is enabled.
      • Verify boot mode is UEFI.
      • Verify the internal hard drive is first in boot order.
      • If the system is used with removable media attached, disconnect it and test again.
    2. If the prompt continues and no encrypted drives need old TPM keys, reset the TPM
      • This is the action the firmware screen is offering.
      • In Windows, the documented path is Windows Security > Device security > Security processor details > Security processor troubleshooting > Clear TPM.
      • Warning: clearing/resetting TPM can remove TPM-stored keys. Only do this if there is no BitLocker-protected drive or other needed TPM-protected data that depends on the current TPM state.
    3. Restart and test normal boot
      • After TPM reset and with stable BIOS settings, the repeated startup prompt should stop.
    4. If this started right after a BIOS/firmware update
      • That aligns with documented BitLocker/TPM behavior. Firmware and boot-environment changes can trigger recovery-related prompts.

    If access to advanced startup options is needed during troubleshooting, Windows startup settings are available through Windows RE > Troubleshoot > Advanced options > Startup Settings > Restart. On encrypted devices, a BitLocker key is required to continue there, but the shown manage-bde output indicates the OS drive itself is not currently encrypted.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.