Jump to content

Recommended Posts

Posted

Hi all i want to bitlocker a laptop with windows 7 enterprise on it, the bios tells me that it is tpm enabled and visible however i get an error when i try to turn on bit locker, i am worried that if clear the tpm it will require me to reinstall (its happened to me before that after i installed windows and then enabled tpm windows would not boot), is there a way around this?

 

As always thanks in advance

Posted

I have had this issue a lot with Windows 7 and Lenovo laptops and desktops.

In the end, I cleared the TPM and run the BitLocker Wizard to fix the issue.

Posted
I get an error when I try to turn on bitlocker

Are you able to post the error message you are getting?

 

How old is the laptop? Is it fairly new so has a v2.0 TPM rather than v1.2?

Posted

the laptop is a hp g5 the tpm is version 2 the error tpm.jpg

 

picture attached..

Just to clarify steps

1. the machine was imaged using legacy boot

2. we decided we need to bitlocker

3. we turn on secure boot in bios

4. windows does not boot

5. we turn off secure boot and enable legacy and windows boots

 

I know that if I turn on secure boot and reimage and then revert to legacy it will all be fine and boot but I want to know if I get around the whole reimage step

Posted (edited)
the laptop is a hp g5 the tpm is version 2

Thanks! It makes sense now why you aren't able to enable Bitlocker.

 

HP doesn't appear to support downgrading the TPM firmware for your laptop model so you can't go that route (since it would have been the easiest).

 

https://support.hp.com/gb-en/document/c05192291

 

Therefore you are going to need to install the following hotfix which adds TPM 2.0 support to Windows 7...

 

https://support.microsoft.com/en-gb/help/2920188/update-to-add-support-for-tpm-2-0-in-windows-7-and-windows-server-2008

 

SecureBoot isn't required for Bitlocker and not supported by Windows 7 anyway. That's why the laptop fails to boot with it enabled. :)

Edited by Arthur
Posted
The laptop claims it already is tpm 2.0 compliant, however I applied the hotfix with no joy ..

You're going to also need to install Windows 7 in UEFI mode with a GPT partitioned HDD/SSD...

 

https://kb.stonegroup.co.uk/using-bitlocker-on-skylake-and-newer-systems-how-can-i-use-tpm-20-on-windows-7_592.html

 

TPM is a method of storing the encryption key used by Bitlocker to protect the contents of the Windows drive. Typically the new Skylake platform systems and newer have moved from TPM 1.2 to TPM 2.0. This is natively supported by Windows 10.

 

If you want to use TPM 2.0 on Windows 7 then this is possible, but only with the following:

 

  • You must use Windows 7 x64. 32-bit / x86 versions of Windows 7 do not support TPM 2.0
  • You need to install Windows 7 in UEFI mode. This is a BIOS setting that has to be made before you partition the hard drive or install Windows. Systems installed in UEFI mode will have a GPT partitioned hard disk.
  • In addition to enabling UEFI mode, you may need to disable Secure boot in the BIOS setup, to enable Windows 7 booting.
  • The Windows 7 hotfix for Microsoft Knowledgebase article 2920188 must be installed. If you have all of the latest Windows updates, then this should already be included.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...