Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows » Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM

Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM

Posted on 30/12/202018/09/2024 Christian By Christian No Comments on Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Device TPM compatibility

The trusted platform module (TPM) is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline. In this article, you will learn how to fix your device that cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM. Please see how to delegate permissions for backing up TPM password, and How to clear the TPM via the management console or Windows Defender Center App.

BitLocker offers the option to lock the normal startup process until the user supplies a personal identification number (PIN). Or inserts a removable USB device, such as a flash drive, that contains a startup key. This makes it possible to allow BitLocker without needing a compatible TPM.

These additional security measures provide multifactor authentication and assurance that the computer will not start. Or resume hibernation until the correct PIN or startup key is presented. Below is a YouTube Video on how to Fix the device that cannot use a TPM module.

Kindly refer to the following TPM related guides: How to upgrade Windows 10 with an unsupported CPU and TPM 1.0 to Windows 11​, and How to Install Windows 11 in Oracle VirtualBox with no TPM Support, 

Here is an example of an FDE solution with PBA “how to download DriveLock software and install DriveLock” that I have tested. kindly take a look at this guide as well “Important DriveLock components to master.

BitLocker without TPM USB key

Note: Furthermore, On devices without TPM version 1.2 and above. You can still use BitLocker to encrypt the Windows OS drive without a compatible TPM. However, this implementation will require the user to insert a USB startup key to start the computer.

However, resume from hibernation and does not provide the pre-startup system integrity verification offered by BitLocker working with a TPM.

Note: Moreover, There is no dare consequence of having BitLocker without a TPM. The difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

The following error below was prompted when I tried simulating what could happen on devices without TPM. "This device can't use a Trusted Platform Module. Your administrator must select the "Allow BitLocker without a compatible TPM" option in the "Require additional authentication at startup" policy for OS volumes".
BitLocker without TPM

To resolve this error, we must configure the local Group Policy settings to “Allow BitLocker without a compatible TPM”. In addition, For more information on Group Policy.

Please see the following guides “what is Group Policy Object and how can it be launched“, how to analyze group policies applied to a user and computer account, and for a comprehensive list of articles I have written on GPO, please visit the following link.

Nonetheless, There are numerous ways to launch the Group Policy Editor in Windows 10.
– Open the Group Policy Editor by pressing the Windows Key + R and type “gpedit.msc”
– Or from the Windows search box, type “gpedit.msc” and press Enter.

Trusted Platform Module issues

This will open the Local Group Policy Editor as shown below

TPM bypass for BitLocker
Local Group Policy Editor

Navigate to the following path as shown below. – Computer Configuration – Administrative Templates – Windows Components – BitLocker Drive Encryption – Operating System Drives

On the right pane of the window, you will see an option called “Require additional authentication at startup”. Double-click on that option.

This is currently set to “Not Configured”. We will have to change this by selecting the “Enabled” radio button.  

This will check the Allow BitLocker without a compatible TPM box by default as shown below.

Click on Okay. As you can see the policy has been enabled.

Now you can now proceed and continue with your BitLocker activation as described in this guide “How to enable BitLocker on Windows 10” or this link.

Note: These Group Policy changes take effect immediately,, there is no need for reboot or apply GPupdate. See this guide for more information on GPUpdate Switches: GPUpdate vs GPUpdate force

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, Container encryption, Encryption, encrytp, File and Folder Encryption Software, Full Disk Encryption, TPM, Windows 10

Post navigation

Previous Post: Full Disk Encryption with PBA or without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption and Container Encryption
Next Post: Enable or disable BitLocker Drive Encryption on Windows

Related Posts

  • banner
    Fix npm install hangs on “sill idealTree buildDeps” Linux
  • WCD
    Join Bulk Devices using a Provisioning Package to Azure AWS/Azure/OpenShift
  • image 8
    Enable or disable Core Isolation Memory Integrity in Windows 10 and 11 Windows
  • you need the right to sign in through Remote Desktop Services
    Fix you need the right to sign in through Remote Desktop Services Windows
  • Featured image 1
    How to Disable Internet Explorer with Group Policy & Registry Windows
  • banner
    How to Edit Windows Hosts File via PowerToy Editor Utility Web Server

More Related Articles

banner Fix npm install hangs on “sill idealTree buildDeps” Linux
WCD Join Bulk Devices using a Provisioning Package to Azure AWS/Azure/OpenShift
image 8 Enable or disable Core Isolation Memory Integrity in Windows 10 and 11 Windows
you need the right to sign in through Remote Desktop Services Fix you need the right to sign in through Remote Desktop Services Windows
Featured image 1 How to Disable Internet Explorer with Group Policy & Registry Windows
banner How to Edit Windows Hosts File via PowerToy Editor Utility Web Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • portainer feature
    How to Install Docker Portainer on Linux Containers
  • images 7
    The plugin filter file/etc/ansible/plugin_filters(yml) does not exist – Skipping Configuration Management Tool
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • Complete Guide on TestRail as a Test Management Tool   banner
    Complete Guide on TestRail as a Test Management Tool Security | Vulnerability Scans and Assessment
  • How to pause updates and why
    How to Pause Windows Update via Windows Settings Windows
  • Screenshot 2022 04 02 at 22.17.10
    How to Install Kubectl on Windows 11 Windows
  • Was ist Windows Server und wie unterscheidet er sich vom normalen Windows
    Create a certificate template for BitLocker Network Unlock Windows Server
  • Laps in Windows
    How to Reset Services Restore Mode (DSRM) Password Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,813 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.