Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM

Posted on 30/12/202018/09/2024 IT Expert By IT Expert No Comments on Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
  1. Home
  2. Windows
  3. Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Device TPM compatibility

The trusted platform module (TPM) is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline. In this article, you will learn how to fix your device that cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM. Please see how to delegate permissions for backing up TPM password, and How to clear the TPM via the management console or Windows Defender Center App.

BitLocker offers the option to lock the normal startup process until the user supplies a personal identification number (PIN). Or inserts a removable USB device, such as a flash drive, that contains a startup key. This makes it possible to allow BitLocker without needing a compatible TPM.

These additional security measures provide multifactor authentication and assurance that the computer will not start. Or resume hibernation until the correct PIN or startup key is presented. Below is a YouTube Video on how to Fix the device that cannot use a TPM module.

Play

Kindly refer to the following TPM related guides: How to upgrade Windows 10 with an unsupported CPU and TPM 1.0 to Windows 11​, and How to Install Windows 11 in Oracle VirtualBox with no TPM Support, 

Here is an example of an FDE solution with PBA “how to download DriveLock software and install DriveLock” that I have tested. kindly take a look at this guide as well “Important DriveLock components to master.

BitLocker without TPM USB key

Note: Furthermore, On devices without TPM version 1.2 and above. You can still use BitLocker to encrypt the Windows OS drive without a compatible TPM. However, this implementation will require the user to insert a USB startup key to start the computer.

However, resume from hibernation and does not provide the pre-startup system integrity verification offered by BitLocker working with a TPM.

Note: Moreover, There is no dare consequence of having BitLocker without a TPM. The difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

The following error below was prompted when I tried simulating what could happen on devices without TPM. "This device can't use a Trusted Platform Module. Your administrator must select the "Allow BitLocker without a compatible TPM" option in the "Require additional authentication at startup" policy for OS volumes".
BitLocker without TPM

To resolve this error, we must configure the local Group Policy settings to “Allow BitLocker without a compatible TPM”. In addition, For more information on Group Policy.

Please see the following guides “what is Group Policy Object and how can it be launched“, how to analyze group policies applied to a user and computer account, and for a comprehensive list of articles I have written on GPO, please visit the following link.

Nonetheless, There are numerous ways to launch the Group Policy Editor in Windows 10.
– Open the Group Policy Editor by pressing the Windows Key + R and type “gpedit.msc”
– Or from the Windows search box, type “gpedit.msc” and press Enter.

Trusted Platform Module issues

This will open the Local Group Policy Editor as shown below

TPM bypass for BitLocker
Local Group Policy Editor

Navigate to the following path as shown below. – Computer Configuration – Administrative Templates – Windows Components – BitLocker Drive Encryption – Operating System Drives

On the right pane of the window, you will see an option called “Require additional authentication at startup”. Double-click on that option.

This is currently set to “Not Configured”. We will have to change this by selecting the “Enabled” radio button.  

This will check the Allow BitLocker without a compatible TPM box by default as shown below.

Click on Okay. As you can see the policy has been enabled.

Now you can now proceed and continue with your BitLocker activation as described in this guide “How to enable BitLocker on Windows 10” or this link.

Note: These Group Policy changes take effect immediately,, there is no need for reboot or apply GPupdate. See this guide for more information on GPUpdate Switches: GPUpdate vs GPUpdate force

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, Container encryption, Encryption, encrytp, File and Folder Encryption Software, Full Disk Encryption, TPM, Windows 10

Post navigation

Previous Post: Full Disk Encryption with PBA or without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption and Container Encryption
Next Post: Enable or disable BitLocker Drive Encryption on Windows

Related Posts

  • Banner
    How to Stop OneDrive from Starting Up Automatically on Windows 11 Windows
  • Interactive logon Message for Users
    Display interactive logon messages for Windows PCs via GPO Windows
  • img 5be0c6cdb96d8
    Is BitLocker Enabled? How to view BitLocker Disk Encryption Status in Windows Windows
  • Banner
    Enabling and Configuring WinRM via GPO Windows
  • MBAM
    The web application “Administration Portal” cannot be enabled because one or more software dependencies are not met Windows
  • schedulepythontasksinWindows
    Run Python Script via Windows Task Scheduler Windows

More Related Articles

Banner How to Stop OneDrive from Starting Up Automatically on Windows 11 Windows
Interactive logon Message for Users Display interactive logon messages for Windows PCs via GPO Windows
img 5be0c6cdb96d8 Is BitLocker Enabled? How to view BitLocker Disk Encryption Status in Windows Windows
Banner Enabling and Configuring WinRM via GPO Windows
MBAM The web application “Administration Portal” cannot be enabled because one or more software dependencies are not met Windows
schedulepythontasksinWindows Run Python Script via Windows Task Scheduler Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Modernstanby
    Modern Standby: PC is automatically encrypted Windows
  • zoom
    How to install Zoom on macOS Mac
  • Wordpress banner
    Fix WordPress Error “The Link You Followed Has Expired” Web Server
  • WhatsApp
    How to retrieve deleted WhatsApp messages on iPhone JIRA|Confluence|Apps
  • exchange 2016 1
    Failed Edge Transport: Easy Guide For Removal Network | Monitoring
  • 05kvj2jzbpj1ugp4etb4gdf 19.fit scale.size 2698x1517 e1690630247655
    Various methods to launch the Event Viewer Windows Server
  • Windows Productivity Tips
    Windows Productivity Tips To Get The Most Out Of Your PC Windows
  • banner
    Various ways to restart an AWS EC2 instance AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,796 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.