Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows » This device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker
  • how to Configure Autologin for a VM in VMware Workstation
    Configure Autologin for a VM in VMware Workstation Virtualization
  • MSDTworkaround
    Microsoft Support Diagnostic Tool Vulnerability Fix Windows
  • screenshot 2020 03 14 at 16.23.23
    Change Windows Desktop icon shortcut for fast user switching Windows
  • ext
    The DriveLock server returned an invalid or unrecognized response Security | Vulnerability Scans and Assessment
  • MBAM Replacement
    MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
  • Screenshot 2020 08 14 at 23.03.54
    How to disable Taskbar Web Search in Windows 10 via GPO and Windows Registry Windows
  • settings app not working featured 800x400 1
    Disable or Remove Kiosk Mode Via the Local Settings Windows
  • screenshot 2020 03 31 at 22.22.43
    How to create, edit and delete a scheduled task via the Command Prompt Windows Server

This device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker

Posted on 04/11/201925/09/2023 Christian By Christian No Comments on This device cannot use a Trusted Platform Module, allow BitLocker without a compatible TPM when turning on Bitlocker
device compatibility

BitLocker is a full volume encryption feature included with Microsoft Windows versions starting with Windows Vista. It is designed to protect data by providing encryption for entire volumes. By default, it uses the AES encryption algorithm in cipher block chaining or XTS mode with a 128-bit or 256-bit key. See this guide for information on Full Disk Encryption with PBA / without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption, and Container Encryption, how to enable FileVault disk encryption on a Mac device, BitLocker Drive Encryption architecture, and implementation scenarios. and the concept of DriveLock with a focus on encryption.

VMs and Desktops that do not support TPM can still use and benefit from BitLocker, and also have their keys saved to Active Directory, Microsoft Azure, or to a USB stick.

BitLocker without TPM

Furthermore, While trying to install Bitlocker Drive Encryption to the C: on my Windows 10 machine. See this guide “how to fix your device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM”.

Trusted Platform Module

The following error was prompted on my Windows 10 Workstation, as shown in the image below.

BitLocker encryption

Let’s review the key term “TPM” and how to resolve this issue.

However, Trusted Platform Module (TPM) – This chip resides on newer processors with additional security features. With TPM, the encryption key is stored on the chip itself.

Note: If your chip does not support TPM, you can still use BitLocker, then you will have to save (store the keys) in a safe location such as Active Directory, Microsft Azure, or on a USB stick, etc. Kindly follow the procedures listed below to resolve this issue.

Nonetheless, To resolve this error, we must configure the local Group Policy settings to “Allow BitLocker without a compatible TPM.” Nevertheless, For more information on Group Policy, please see the following guides “what is Group Policy Object and how can it be launched“, how to analyze group policies applied to a user and computer account, and for a comprehensive list of articles I have written on GPO, please visit the following link.

Launch Group Policy and enable the following exception

- Using your keyboard ''Windows key+R'' or search for "run"
- Type: gpedit.msc then hit "ok" or press "Enter" on your keyboard
- Expand Administrative Templates then Windows Components 
- Bitlocker Drive Encryption then 
- Click Operating System Drives as shown below.

Therefore, Double-click or right-click “Require additional authentication at startup.”

click Edit and select enabled as shown below. 
- Select Enabled and 
- Check the box to allow BitLocker without compatible TPM in the Options section.
Note: Most times this option is selected by default.

The last steps involve enforcing the settings.

From the Start menu
- Type run or Press Windows Key + R to launch the run wizard
- Type cmd as shown below
- gpforce.exe /update and 
- Press Enter. 

That is all ;)

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, Encryption, Full Disk Encryption, TPM, Trusted Platform Module, Windows 10

Post navigation

Previous Post: Editions of MSSQL Server: What are the differences between various Editions of Microsoft SQL Server
Next Post: How to perform vulnerability scan on Microsoft SQL Server

Related Posts

  • BitLocker MBAM Frequently Asked Questions
    Disable the Sleep Mode: UEFI and TPM and BitLocker FAQs Windows
  • what is winrm
    WinRM cannot complete the operation, verify that the specified computer name is valid Windows
  • Comprehensive Guide to Passkeys on Windows Devices
    Comprehensive Guide to Passkeys on Windows Devices Windows
  • image 79
    How to import SSL Certificate to Windows Server using DigiCert Utility Windows
  • Temp Files
    Recover Temp Files using Disk Drill etc on Windows 10 and 11 Windows
  • maxresdefault
    How to stop Microsoft Edge from remembering your email ID Windows

More Related Articles

BitLocker MBAM Frequently Asked Questions Disable the Sleep Mode: UEFI and TPM and BitLocker FAQs Windows
what is winrm WinRM cannot complete the operation, verify that the specified computer name is valid Windows
Comprehensive Guide to Passkeys on Windows Devices Comprehensive Guide to Passkeys on Windows Devices Windows
image 79 How to import SSL Certificate to Windows Server using DigiCert Utility Windows
Temp Files Recover Temp Files using Disk Drill etc on Windows 10 and 11 Windows
maxresdefault How to stop Microsoft Edge from remembering your email ID Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a
 
  • how to Configure Autologin for a VM in VMware Workstation
    Configure Autologin for a VM in VMware Workstation Virtualization
  • MSDTworkaround
    Microsoft Support Diagnostic Tool Vulnerability Fix Windows
  • screenshot 2020 03 14 at 16.23.23
    Change Windows Desktop icon shortcut for fast user switching Windows
  • ext
    The DriveLock server returned an invalid or unrecognized response Security | Vulnerability Scans and Assessment
  • MBAM Replacement
    MBAM extended support ends April 2026: Find alternative solution Security | Vulnerability Scans and Assessment
  • Screenshot 2020 08 14 at 23.03.54
    How to disable Taskbar Web Search in Windows 10 via GPO and Windows Registry Windows
  • settings app not working featured 800x400 1
    Disable or Remove Kiosk Mode Via the Local Settings Windows
  • screenshot 2020 03 31 at 22.22.43
    How to create, edit and delete a scheduled task via the Command Prompt Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.