How to get BitLocker to work for C drive

If you cannot enable BitLocker for a disk in Windows 10, with error: “This device cannot use a trusted platform drive”, see below how to fix it.

BitLocker is a built-in Windows feature from Windows Vista onwards. It helps you encrypt the operating system as well as fixed drives, so you can protect your data on these drives.

Enabling BitLocker protection for a drive is very simple. You must go from exploring files to "My Computer" (Windows Vista / 7) or "This Computer" (Windows 8 / 8.1 / 10) and right-click the drive you want to protect.

In the context menu that will right-click, select "Enable BitLocker" and then follow the steps in Windows.

Some computers may not allow Windows to proceed with and send you the following error message:

This device cannot use a trusted platform unit. Your administrator must set the option "Allow BitLocker without TPM compatible" in the "Requires extra authentication at startup" policy for operating system volumes.

Η Trusted Module aka TPM is the technology that offers security functions with its cooperation material. Generally TPM chips (integrated circuits) are such advanced technologies that they have security mechanisms that are immune to malware. You can find more information about TPM on Wikipedia.

But let's see what TPM means (Reliable Platform Module) in the context of this error. This error will only appear when your system does not contain TPM-supported hardware. It generally happens with older machines. And in this case, BitLocker must encrypt the drive without TPM. When encrypting a drive without a TPM, you must use a password at boot time or a USB drive.

Upon completion of BitLocker, the basic information that makes up thw drive encryption will be stored on a USB drive and using it, you can access the data of the encrypted drive.

Therefore, to use BitLocker without TPM and to bypass this error, follow these steps:
NOTE: The following steps only work on Pro and Enterprise versions of Windows 10 / 8.1 / 8 / 7.

1. Press Win + R at the same time and in the run window that appears, type gpedit.msc and press OK. The "Local Group Policy Editor" window will open.

2. In this window go to:
PC settings > templates s > Windows Components > BitLocker Drive Encryption > Operating System Drives (Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives)

3. In the right pane of the operating system drives, look for the setting called "Requiring Extra Authentication at Startup" and double-click it to modify it.

4.
Then, in the Configuration Policy window, select "Enabled" (top left). Also make sure that in the same window you have checked “Allow BitLocker without TPM compatible (requires password or boot key on USB flash drive). Click the Apply button, and then click OK. Turn off the local group policy editor.

You can now try to encrypt the same drive as BitLocker again and it should work this time.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).