i have Lenovo laptop of different models ( W530 & W540 & X1 Carbons)
Bitlocker GPO is enabled and since we started using X1 Carbons we are having an issue that if the battery dies or windows update is installed, upon reboot we need to provide a bitlocker key. this is not happening to any of our W530/W540 laptops.
is there a workaround to this that you guys know about?
thanks for all your help
* BitLockerSecurityNetwork SecurityEncryption
Last Comment
McKnife
8/22/2022 - Mon
Natty Greg
Here is a solution on EE toward your question, link below.
Windows updates don't require bitlocker recovery. To verify that, uninstall certain updates, restart, let them be redetected and reinstalled and you'll see. Only if windows update is used to push firmware updates for hardware components or the laptop mainboard, we could expect to run into BL recovery.
As for batteries dying: I have never heard that this would cause BL recovery but I think it's possible, although MS never mentions it. Please try to reproduce that to be sure.
IT Guy
ASKER
i will try to suspend and un-suspend to verify if that solution works - so far it seems updates and battery draining are the trigger points as per use description.
Please return to your question and give feedback on what is still unclear.
IT Guy
ASKER
apologies for taking so long -couple of ppl left my dept. so it looks like because i am using a docking station it maybe triggering bit locker as per this forum that suggested i update drivers + Bios but did not help me, issue still occurs
Yes, I often read that docking and undocking is in conflict with what a TPM chip is trying to prevent and monitor: hardware changing and tampering. You could only loosen what the TPM is monitoring, but that will also loosen bitlocker security. Are you willing to loosen it? Otherwise you would need to either live with it or change your hardware.
https://www.experts-exchange.com/questions/27232993/Is-the-bitlocker-recovery-key-needed-after-every-windows-update.html