newpersn Posted February 5, 2019 Posted February 5, 2019 (edited) We have Dell Latitude E5470 with Docking stations. (Laptops are Windows 7 Ent) I'm sure i've had bitlocker working with the docks before (during testing) but we are doing the whole site bitlocker. (All data is redirected back to the servers) I just tired bitlocking a spare laptop and it failed when docked. These laptops have TPM chips in. What other settings in GP do i need to set? Thanks Edited February 5, 2019 by newpersn
Arthur Posted February 5, 2019 Posted February 5, 2019 I just tired bitlocking a spare laptop and it failed when docked. These laptops have TPM chips in. By 'failed' do you mean you get prompted for the recovery key when docked or does Windows not encrypt the drive? I seem to remember when I was using Windows 7 I had to downgrade the TPM firmware from v2.0 to v1.2 to get BitLocker to work properly. Have you tried any of the laptops with Windows 10 installed (plus UEFI and Secure Boot enabled in the BIOS)?
newpersn Posted February 5, 2019 Author Posted February 5, 2019 By 'failed' do you mean you get prompted for the recovery key when docked or does Windows not encrypt the drive? I seem to remember when I was using Windows 7 I had to downgrade the TPM firmware from v2.0 to v1.2 to get BitLocker to work properly. Have you tried any of the laptops with Windows 10 installed (plus UEFI and Secure Boot enabled in the BIOS)? Sorry. Yes it asks for recovery key. I believe the bios is the original that was shipped with the laptop. I will try the latest release. Laptops are set to legacy with Secure boot turned off. Unforcity there is no scope to move to Windows 10 currently (decision that has come above at this time.)
newpersn Posted February 11, 2019 Author Posted February 11, 2019 Anyone? I'm sure i seen some where of some options that needed changing.
Arthur Posted February 11, 2019 Posted February 11, 2019 Do you have the KB2920188 hotfix installed? If not, did you downgrade the TPM firmware from 2.0 to 1.2 (it's separate from the BIOS upgrade)? When in legacy mode you need 1.2 for BitLocker to work properly in Windows 7. www.tombullock.co.uk/2018/03/12/dell-xps-13-asking-for-bitlocker-key-every-startup/ I’ve recently been encrypting our fleet of Dell XPS 13 laptops ready for GDPR compliance come May 2018. I have had some issues with the machine asking for the bitlocker recovery key on each startup and from what I can tell this involves a TPM level 2.0 being used when Secure boot mode is off and Legacy boot options are used. A TPM 2.0 does not like secure boot off and legacy boot options, so I found the solution (for me at least, on Dell XPS 13 9360 units) was to use the Dell TPM Switcher Utility and downgrade the TPM from 2.0 to 1.2. This has to be done from Windows, but I found disabling Bitlocker, downgrading the TPM, and then enabling BitLocker resolves the issue. https://forums.lenovo.com/t5/Enterprise-Client-Management/Bitlocker-issue-with-T470-Tpm-2-0-Windows-10/td-p/3700179 The discrete TPM 2.0 chip is designed to work in UEFI boot mode only. The TPM will not be enabled and prevents Bitlocker from working properly if you try to install Windows in legacy boot mode.
sted Posted February 12, 2019 Posted February 12, 2019 it might see it as a usb device / network card and change the boot order(ive had it before where an sd card left in made bitlocker think the boot order had changed). it might be worth disabling all boot options but hdd and see if that fixes it
newpersn Posted February 12, 2019 Author Posted February 12, 2019 it might see it as a usb device / network card and change the boot order(ive had it before where an sd card left in made bitlocker think the boot order had changed). it might be worth disabling all boot options but hdd and see if that fixes it Whys does it take so long to decrypt.....
newpersn Posted February 12, 2019 Author Posted February 12, 2019 All seems to work when i tested it now. Update Bios, Changed boot order to SSD 1st and NIC 2nd. Cleared any TPM settings and start encrypt and it works on and off the dock.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now