Jump to content

Recommended Posts

Posted

Hi all,

 

I have a nightmarish scenario involving Bitlocker, a headteacher who doesn't want (one of his two) laptops to be domain-joined and borkage.

 

The laptop is an ASUS X550C; a few years old but it does what he needs it to do (most of the time). The machine to date hasn't been Bitlockered BUT is used for processing student data and so when it came in for updates over the summer Bitlocker was high on my list of priorities.

 

So, I take a backup of the user's files, amend the local policies as necessary, start the Bitlocker wizard, enter the Bitlocker password, save the recovery key to a known good USB stick, restart the machine aaaaaaand... the whole thing falls flat on its face. The password I've set doesn't work and WORSE the recovery key that the same machine has saved to my USB stick also does not work. I'm not sure if we're talking about something caused by a tired drive (possible given the age) or if the problem has been caused by the fact that it's a consumer-grade heap that was never really intended to play nice with Bitlocker or Windows 10...

 

So... I have the user's data backed up but it's a standalone that's been in use for a good length of time and I don't want to waste at least half a day manually rebuilding the thing unless I absolutely have to. I've pulled the drive and scanned it with a data recovery tool and the partition is effectively intact and is NOT encrypted (as it failed during the initial reboot it never started actually encrypting anything). I've test-recovered a few files and they're a perfect match.

 

So... is it possible to mark a partition such as this as NOT being Bitlocker-encrypted in order to regain access in this scenario and has anyone had any success doing so?

 

...or am I just bashing my head against a brick wall? :doh:

 

Cheers in advance!

Posted (edited)

You could try doing it via commandline and see what it says in regards to it

 

e.g.

manage-bde –off D:

 

Sometimes had external USBs that would work doing it that way, even though it thinks it wasn't fully encrypted as it's still provisioning

 

Edit - There is more "forceful" commands too but might be worth trying that before forcing it into recovery etc

 

Edit 2 - Might have to do it with an unlock password too via commandline, but try that and see if it even thinks its encrypted first :p

 

Steve

Edited by Steve21
Posted
id be careful with x550c's ive got a few set up with tpm and pin and they fairly often for no reason ive been able to work out ask for the recovery key as they think the key has been typed wrong too many times so i need to pause bitlocker fiddle and reapply it)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...