• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.
  • The forums have been upgraded with support for dark mode. By default it will follow the setting on your system/browser. You may override it by scrolling to the end of the page and clicking the gears icon.

Microsoft re enables bitlocker, locked my computer and deleted the windows hello pin after installing 23H2.

Joined
Feb 6, 2021
Messages
3,122 (1.99/day)
Location
Germany
Processor AMD Ryzen 9 9950X3D
Motherboard ASRock B850M PRO-A
Cooling Corsair Nautilus 360 RS
Memory 2x32GB Kingston Fury Beast 6000 CL30
Video Card(s) PowerColor Hellhound RX 9070 XT
Storage 1TB Samsung 990 Pro, 2TB Samsung 990 Pro, 4TB Samsung 990 Pro
Display(s) LG 27GS95QE-B, MSI G272QPF E2
Case Lian Li DAN Case A3 Black Wood Edition
Audio Device(s) Bose Companion Series 2 III, Sennheiser GSP600 and HD599 SE - Creative Soundblaster X4
Power Supply Corsair RM1000X ATX 3.1
Mouse Razer Deathadder V3
Keyboard Razer Black Widow V3 TKL
VR HMD Oculus Rift S
brother bought a new laptop, got his old one and wiped it.
fresh W11 Pro installation, manually disabled bitlocker and checked a couple times that it is actually disabled. (wasn't the first time i found it to be enabled again after a couple weeks)
yesterday it installed 23H2 and it restarted for like 45 minutes... now bitlocker was automatically enabled again and this time it just reset my windows hello credentials and denied access to my own fucking computer.
after finding the uploaded bitlocker key from my PC, the windows pin was reset, i couldn't log in and it required an internet connection, email verification and a new pin just to get back to the desktop.

what is wrong with this company? it's like paying rent for restricted access to my own property.
and how can i make sure that this shit stays disabled? (happened so far only on OEM devices like HP, Dell and Lenovo Laptops and not desktop DIY PCs.)
 
Last edited:
I have a better one. I moved my MP700 to a different M2 slot and now Gamepass is asking me to reinstall Forza 8.
 
Hi,
IDK that's messed up and I did just clean install 22h2 on purpose
Thankfully acer did not activate bitlocker out the box.

Besides having backup/ clone system images.. :/
Personally AI just for 23h2 I'll mass
But If I do I'll mount the iso rufus produces for sure.

I have a better one. I moved my MP700 to a different M2 slot and now Gamepass is asking me to reinstall Forza 8.
I think acer has the os on the wrong m.2 slot
OS shows as disk 2 and data shows disk 1 :confused:

On my z490 it's the opposite disk 1 os disk 2 data.
 
I just use Rufus to burn the image to USB and disable BitLocker entirely.
 
Hi,
Was this on 11 pro or home
I opted for a cheap pro key.
 
what is wrong with this company?
Microsoft's workforce is getting progressively younger; employees leave or are poached by other companies as they get more experience and are replaced by kids fresh out of college.

Result is a "five monkeys" type situation.
 
Since this is Pro, I assume you tried setting “Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Removable Data Drives” to Disable in gpedit to force Windows to not use it? If not, might be the play.
Edit: Also trying “Computer Configuration -> Administrative Templates -> Windows Components – > BitLocker Drive Encryption -> Fixed Data Drives” and stopping it for using it for fixed drives, that too.
 
Hi,
Don't insult monkeys even if it's only 5 :p
 
@GerKNG Pretty sure this is how my Kingston KC3000 1tb got fucked up before I did the RMA on it, bitlocker encrypted it without my permission, then I went to clean install Linux one day and the two OS's waged a war somehow, cause Linux was trying to overwrite it, and then it just all got fucked up from there I guess. No idea. BUt I RMA'd got a new drive, and Win 10 Home has been treating me good ever since, I am not upgrading my OS until 2026, fuck that noise.
 
One of the worst things about Windows 11 is how NVME drives are handled. I had a NV2 in the system and upgraded to 4 TB version. I have one of those M2 adapters and wanted to use that with the old drive. I first tried it in the Case supplied USB C slot and though it recognized the drive it said it was a CD drive. I put it into one of the USB C slots on the MB and was able to format it. With the drive formatted I tried to use it via USB on my Windows 10 machine and the drive showed up with no capacity. I took it back to the Windows 11 machine and put it back in the same USB C slot as before but the issue persisted. Even using Seagate Disk Wizard does not work as the drive is not seen as part of the array. I will probably have to reset the TPM to get the drive recognized. I never had this issue with Windows 7 or 10.
 
One of the worst things about Windows 11 is how NVME drives are handled. I had a NV2 in the system and upgraded to 4 TB version. I have one of those M2 adapters and wanted to use that with the old drive. I first tried it in the Case supplied USB C slot and though it recognized the drive it said it was a CD drive. I put it into one of the USB C slots on the MB and was able to format it. With the drive formatted I tried to use it via USB on my Windows 10 machine and the drive showed up with no capacity. I took it back to the Windows 11 machine and put it back in the same USB C slot as before but the issue persisted. Even using Seagate Disk Wizard does not work as the drive is not seen as part of the array. I will probably have to reset the TPM to get the drive recognized. I never had this issue with Windows 7 or 10.
I think this is why Samsung uses their own driver, but I could be wrong.
 
I think this is why Samsung uses their own driver, but I could be wrong.

Good to know, I might role Samsung when I upgrade to gen5 or gen6 in a few years.
 
Microsoft's workforce is getting progressively younger; employees leave or are poached by other companies as they get more experience and are replaced by kids fresh out of college.

Result is a "five monkeys" type situation.
Honestly though... this happens everywhere. Doesn't explain it.

I fulfill a senior role at my company amidst juniors, and even mediors, whatever that may be; and yes, talent / knowledge drain is a thing, but its a thing that can be managed. Surely at MS they manage that...

Hi,
Don't insult monkeys even if it's only 5 :p
Monkeys DO beta test in the wild too...
 
Honestly though... this happens everywhere. Doesn't explain it.

I fulfill a senior role at my company amidst juniors, and even mediors, whatever that may be; and yes, talent / knowledge drain is a thing, but its a thing that can be managed. Surely at MS they manage that...
Sure it can be managed. But just think, we can instead lower our spending by 0.457% and improve our quarterly forecast! Surely you can see that the choice is obvious.
 
Sure it can be managed. But just think, we can instead lower our spending by 0.457% and improve our quarterly forecast! Surely you can see that the choice is obvious.

Today's MS is not the same thing as it was back in Joel Spolsky's time.

Do you guys understand what you're saying? And do you understand what I'm saying? Our opinions are not far apart - I just don't subscribe to the idea that in a corporate environment like this, not every move that goes to the public goes unvetted. Everything corporate does is intentional. They know we'll swallow it. They know they can get away with it. They do it.

I work at a company on national scale and even we vet, test and then test again everything. This topic is about the way Windows works wrt to authentication and security. You can be damn sure this is either intentional or such an edge case it was never picked up on.
 
There is a group policy useful for Windows 11, to prevent automated bitlocker, if you interested I will post it.
 
Do you guys understand what you're saying? And do you understand what I'm saying? Our opinions are not far apart - I just don't subscribe to the idea that in a corporate environment like this, not every move that goes to the public goes unvetted. Everything corporate does is intentional. They know we'll swallow it. They know they can get away with it. They do it.
And I do not disagree with you at all, I am just being glib about it. OF COURSE they think, nay, know that whatever they do, however low their level of QC drops, the public will absolutely swallow it. They are a de-facto monopoly in the space of desktop PC OS. Both in the home and in the business world. They assume, perhaps rightly, that they are in a position where they can do practically whatever. And, unless Rapture comes and the “Year of Linux Desktop is next year” stops being a sad meme, this doesn’t look to change.
 
There is a group policy useful for Windows 11, to prevent automated bitlocker, if you interested I will post it.
Hi,
Yeah I'm not seeing anything about disabling bitlocker here ? @W1zzard
Only this bit not sure it's the same or not ?
Code:
rem Disable automatic TCG/Opal disk locking on supported SSD drives with PSID
reg add HKLM\Software\Policies\Microsoft\Windows\EnhancedStorageDevices /v TCGSecurityActivationDisabled /t REG_DWORD /d 1 /f

Did run across this but back in April
 
I listed my suggested policies couple of comments back.
 
I listed my suggested policies couple of comments back.
Hi,
MS rarely follows GP.

By the way I didn't read any that helped turn bl off just jumps from hardware to software usage of it.

I asked the dude on 11f and said I got E & F to if this would work and he said it should
Code:
reg add "HKLM\System\CurrentControlSet\Control\BitLocker" /v "PreventDeviceEncryption" /t REG_DWORD /d "1" /f
fsutil behavior set disableencryption 1
manage-bde -off C:
manage-bde -off D:
manage-bde -off E:
manage-bde -off F:
cipher /d /e /f /s:C:\
sc config EFS start= disabled
sc config BDESVC start= disabled
 
Last edited:
One of the worst things about Windows 11 is how NVME drives are handled. I had a NV2 in the system and upgraded to 4 TB version. I have one of those M2 adapters and wanted to use that with the old drive. I first tried it in the Case supplied USB C slot and though it recognized the drive it said it was a CD drive. I put it into one of the USB C slots on the MB and was able to format it. With the drive formatted I tried to use it via USB on my Windows 10 machine and the drive showed up with no capacity. I took it back to the Windows 11 machine and put it back in the same USB C slot as before but the issue persisted. Even using Seagate Disk Wizard does not work as the drive is not seen as part of the array. I will probably have to reset the TPM to get the drive recognized. I never had this issue with Windows 7 or 10.
lol, just disable this tpm thing, it annoys me asf whenever i upgrade some cpu...
 
lol, just disable this tpm thing, it annoys me asf whenever i upgrade some cpu...
Hi,
Not usually an option on a locked laptop sadly. I can't :cry:
 
So someone finally got bit by this. I knew auto-bitlocker encryption was going to bite someone.
 
Back
Top