Sheridan Posted December 6, 2017 Posted December 6, 2017 Maybe I'm missing something but we have GPOs that set Enhanced PINs for Bitlocker, yet on a brand new business HP laptop (with TPM 2 chip) we only get the pin/usb/autmatically unlock options when enabling it. Ideally I'd like the password on boot option to unlock but it just won't appear - the GPO is being applied correctly. If it detects tpm does it disable this option?
kennysarmy Posted December 6, 2017 Posted December 6, 2017 Maybe I'm missing something but we have GPOs that set Enhanced PINs for Bitlocker, yet on a brand new business HP laptop (with TPM 2 chip) we only get the pin/usb/autmatically unlock options when enabling it. Ideally I'd like the password on boot option to unlock but it just won't appear - the GPO is being applied correctly. If it detects tpm does it disable this option? According to this you can have pin / usb and use TPM https://www.youtube.com/watch?v=OwUpH1uMZFQ
Sheridan Posted December 6, 2017 Author Posted December 6, 2017 Its seems that if TPM is detected only PIN/USB is allowed - if you disable the TPM (in the bios) then you can specify to have a password (not pin) at boot. I know TPM is probably better but as we widely used truecrypt staff are familiar with the password on boot option.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now