Bitlocker issue after windows update


  1. Posts : 18
    windows 7
       #1

    Bitlocker issue after windows update


    Hi Friends
    I need your expert help in solving a critical case details of which are as following-

    I got Thinkpad T490 laptop from one of my customer,
    It was having windows 10 Enterprise X64 preinstalled . After windows updates last week suddently Bitlocker has started apprearing and is asking to enter the key.

    As per customer he was not aware of what is Bitlocker so he has not activated it manually.
    He is not having microsoft account so no backup of keys is present.
    Manage-bde shows TPM+ Numeric key as protectors. Due to some reason windows is not fetching password from TPM.
    Recovery Key ID is - 632A9B3C-0470-4AEC-8618-FABC6C91DB85 -- can we guess something from this ID ?
    Bitlocker mentions that -
    " Bitlocker needs your Recovery key to unlock your drive because "Secure Boot " has been disabled. Either Secure Boot must be re -enabled or Bitlocker must be suspended.

    I tried to enable Secure Boot from thinkpad Bios but it was already enabled (UEFI only with CSM =No settings). I can't modify this settings except enable /disable Secure boot.
    I tried to load bios defaults but its of no use.
    There are many reasons for bitlocker provocation some very simple like change of keyboard type /firmware upgrade etc.
    What should I do now ? Has someone experienced same scenario earlier ?
    Contacting microsoft tech support they say its reponsibility of Lenovo since its OEM windows.
    While Lenovo tech support says its microsoft product and you must take support from them.
    So both of them are not going to help.
    Pls. help me since I have exhausted all options and can't do anything further.
    Here is attachment download link - (can't attach unfortunately)
    New folder.zip - Google Drive
    Last edited by chipsang; 07 Oct 2021 at 23:05. Reason: attachments
      My Computer


  2. Posts : 4,187
    Windows 11 Pro, 22H2
       #2

    Afraid I don't have much good news on this issue...

    So, you said that you can't modify settings except enable / disable secure boot. What happened when you re-enabled secure boot? Did you even do so? If not, that should be the first thing that you do.

    As for the recovery ID, that will not help you in any why whatsoever. The purpose of that ID is simply to provide a unique ID that will not change. The computer name and other identifiers may change, but if you recorded your Recovery ID along with the Recovery Key, you have a way of asking the user for the key associated with a particular ID which will never change.

    If turning Secure Boot back on does not resolve the issue for you, then the only other hope would be access to a backup.

    Otherwise, there is nothing anyone can do to recover from this. Not even Microsoft can resolve this. This is on purpose and by design.

    Sorry if this sounds harsh - just laying it out for you like it is so that you don't have any false hopes. If there was some workaround to bypassing BitLocker, then what's the point of having it?
      My Computers


  3. Posts : 18
    windows 7
    Thread Starter
       #3

    hsehestedt said:
    Afraid I don't have much good news on this issue...

    So, you said that you can't modify settings except enable / disable secure boot. What happened when you re-enabled secure boot? Did you even do so? If not, that should be the first thing that you do.

    As for the recovery ID, that will not help you in any why whatsoever. The purpose of that ID is simply to provide a unique ID that will not change. The computer name and other identifiers may change, but if you recorded your Recovery ID along with the Recovery Key, you have a way of asking the user for the key associated with a particular ID which will never change.

    If turning Secure Boot back on does not resolve the issue for you, then the only other hope would be access to a backup.

    Otherwise, there is nothing anyone can do to recover from this. Not even Microsoft can resolve this. This is on purpose and by design.

    Sorry if this sounds harsh - just laying it out for you like it is so that you don't have any false hopes. If there was some workaround to bypassing BitLocker, then what's the point of having it?
    Hi hsehestedt
    Thanks for all the help.
    I tried to disable secure boot and re enable it , but there is no change due to that.
    I feel this has something to do with laptop BIOS update but not sure.
    Other ways (like reading TPM chip directly) are beyond my capabilities .I am also giving up as nothing is left to do .
    Thanks again
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:57.
Find Us




Windows 10 Forums