Avatar of IT Guy
IT Guy
 asked on

Bitlocker request key after every windows update

i have Lenovo laptop of different models ( W530 & W540 & X1 Carbons)

Bitlocker GPO is enabled and since we started using X1 Carbons we are having an issue that if the battery dies or windows update is installed, upon reboot we need to provide a bitlocker key. this is not happening to any of our W530/W540 laptops.

is there a workaround to this that you guys know about?

thanks for all your help
* BitLockerSecurityNetwork SecurityEncryption

Avatar of undefined
Last Comment
McKnife

8/22/2022 - Mon
Natty Greg

McKnife

Windows updates don't require bitlocker recovery. To verify that, uninstall certain updates, restart, let them be redetected and reinstalled and you'll see. Only if windows update is used to push firmware updates for hardware components or the laptop mainboard, we could expect to run into BL recovery.

As for batteries dying: I have never heard that this would cause BL recovery but I think it's possible, although MS never mentions it. Please try to reproduce that to be sure.
IT Guy

ASKER
i will try to suspend and un-suspend to verify if that solution works - so far it seems updates and battery draining are the trigger points as per use description.
Your help has saved me hundreds of hours of internet surfing.
fblack61
McKnife

Please return to your question and give feedback on what is still unclear.
IT Guy

ASKER
apologies for taking so long -couple of ppl left my dept. so it looks like because i am using a docking station it maybe triggering bit locker as per this forum that suggested i update drivers + Bios but did not help me, issue still occurs

 https://forums.lenovo.com/t5/ThinkPad-X-Series-Laptops/Bitlocker-configuration-in-X1-Carbon-using-Win8-1-and-OneLink/m-p/1566906#M52604
McKnife

Yes, I often read that docking and undocking is in conflict with what a TPM chip is trying to prevent and monitor: hardware changing and tampering. You could only loosen what the TPM is monitoring, but that will also loosen bitlocker security. Are you willing to loosen it? Otherwise you would need to either live with it or change your hardware.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
IT Guy

ASKER
i think its an option i can look into - how do i loosen security from TPM chip?
SOLUTION
McKnife

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
IT Guy

ASKER
thanks - testing now
IT Guy

ASKER
ok so here is the update so far

the laptops BIOS is in Legacy Mode, microsoft suggested to change to UEFI mode to resolve the issue
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
ASKER CERTIFIED SOLUTION
McKnife

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.