Jump to content

Recommended Posts

Posted

I don't know much about Bitlocker but need to turn it on on eight laptops. One laptop was built, then Acronised, then downloaded on to the other seven. Each was then renamed and added to the domain. Windows 10 LTSC. Server is 2012 (Yes I know, that's changing next year). They are Dell laptops. In the BIOS at the moment TPM 2.0 is on, Secure Boot is off, Boot list option is Legacy (not UEFI) and in Advanced Boot Options "Enable Legacy Option ROMs" is enabled. Now I know some of those settings are wrong for a perfect Bitlocker setup, but I thought you could still use it and it would just want a password/USB stick at boot? Am I wrong on that? If I try and turn on Bitlocker it simply says "The startup options on this PC are configured incorrectly." but doesn't tell me which ones or what they should be set to.

 

Please help! I really don't want to have to rebuild these again. Eight latops is a lot to do one at a time, but not enough to warrant a SCCM/whatever install!

 

Thank you

 

Stuart

Posted (edited)
at the moment TPM 2.0 is on, Secure Boot is off, Boot list option is Legacy (not UEFI) and in Advanced Boot Options "Enable Legacy Option ROMs" is enabled.

With TPM 2.0 devices you need to be in native UEFI mode and disable Legacy Option ROMs/CSM.

 

https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/tpm-recommendations#why-tpm-20

 

gY0Nvfm.png

 

To avoid rebuilding the laptops you could try using MBR2GPT and then switching them into UEFI mode.

 

Another option would be to use Dell's TPM 2.0 to 1.2 downgrade utility if they are Latitudes?

Edited by Arthur
  • Thanks 1
Posted

 

I've fallen at the first on that one. "Step One: Enable BitLocker (If You Haven’t Already)". I can't, it's when I try and enable it that it tells me to push off!

 

- - - Updated - - -

 

With TPM 2.0 devices you need to be in native UEFI mode and disable Legacy Option ROMs/CSM.

 

https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/tpm-recommendations#why-tpm-20

 

gY0Nvfm.png

 

To avoid rebuilding the laptops you could try using MBR2GPT and then switching them into UEFI mode.

 

Another option would be to use Dell's TPM 2.0 to 1.2 downgrade utility if they are Latitudes?

 

They are Vostros. I'll give the mbr-gpt thing a go though.

Posted

I successfully ran the mbr2gpt utility, then booted in to the BIOS and set it to UEFI rather than Legacy and tried Bitlocker again. It then passed the first bit and said it was going to encrypt, then failed saying "file not found". I did a little Googling and as a result of that I renamed the file called "reagent.xml" to "reagent.old" and the drive is now encrypting.

 

Thanks to all for your input.

 

Stuart

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...