Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM

Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM

Posted on 30/12/202018/09/2024 Christian By Christian No Comments on Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM
Device TPM compatibility

The trusted platform module (TPM) is a hardware component installed in many newer computers by computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer has not been tampered with while the system was offline. In this article, you will learn how to fix your device that cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM. Please see how to delegate permissions for backing up TPM password, and How to clear the TPM via the management console or Windows Defender Center App.

BitLocker offers the option to lock the normal startup process until the user supplies a personal identification number (PIN). Or inserts a removable USB device, such as a flash drive, that contains a startup key. This makes it possible to allow BitLocker without needing a compatible TPM.

These additional security measures provide multifactor authentication and assurance that the computer will not start. Or resume hibernation until the correct PIN or startup key is presented. Below is a YouTube Video on how to Fix the device that cannot use a TPM module.

Kindly refer to the following TPM related guides: How to upgrade Windows 10 with an unsupported CPU and TPM 1.0 to Windows 11​, and How to Install Windows 11 in Oracle VirtualBox with no TPM Support, 

Here is an example of an FDE solution with PBA “how to download DriveLock software and install DriveLock” that I have tested. kindly take a look at this guide as well “Important DriveLock components to master.

BitLocker without TPM USB key

Note: Furthermore, On devices without TPM version 1.2 and above. You can still use BitLocker to encrypt the Windows OS drive without a compatible TPM. However, this implementation will require the user to insert a USB startup key to start the computer.

However, resume from hibernation and does not provide the pre-startup system integrity verification offered by BitLocker working with a TPM.

Note: Moreover, There is no dare consequence of having BitLocker without a TPM. The difference here is that the encryption key will be saved to a USB instead of being stored on the chip itself.

The following error below was prompted when I tried simulating what could happen on devices without TPM. "This device can't use a Trusted Platform Module. Your administrator must select the "Allow BitLocker without a compatible TPM" option in the "Require additional authentication at startup" policy for OS volumes".
BitLocker without TPM

To resolve this error, we must configure the local Group Policy settings to “Allow BitLocker without a compatible TPM”. In addition, For more information on Group Policy.

Please see the following guides “what is Group Policy Object and how can it be launched“, how to analyze group policies applied to a user and computer account, and for a comprehensive list of articles I have written on GPO, please visit the following link.

Nonetheless, There are numerous ways to launch the Group Policy Editor in Windows 10.
– Open the Group Policy Editor by pressing the Windows Key + R and type “gpedit.msc”
– Or from the Windows search box, type “gpedit.msc” and press Enter.

Trusted Platform Module issues

This will open the Local Group Policy Editor as shown below

TPM bypass for BitLocker
Local Group Policy Editor

Navigate to the following path as shown below. – Computer Configuration – Administrative Templates – Windows Components – BitLocker Drive Encryption – Operating System Drives

On the right pane of the window, you will see an option called “Require additional authentication at startup”. Double-click on that option.

This is currently set to “Not Configured”. We will have to change this by selecting the “Enabled” radio button.  

This will check the Allow BitLocker without a compatible TPM box by default as shown below.

Click on Okay. As you can see the policy has been enabled.

Now you can now proceed and continue with your BitLocker activation as described in this guide “How to enable BitLocker on Windows 10” or this link.

Note: These Group Policy changes take effect immediately,, there is no need for reboot or apply GPupdate. See this guide for more information on GPUpdate Switches: GPUpdate vs GPUpdate force

I hope you found this blog post helpful. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Bitlocker, Container encryption, Encryption, encrytp, File and Folder Encryption Software, Full Disk Encryption, TPM, Windows 10

Post navigation

Previous Post: Full Disk Encryption with PBA or without PBA, UEFI, Secure Boot, BIOS, File and Directory Encryption and Container Encryption
Next Post: Enable or disable BitLocker Drive Encryption on Windows

Related Posts

  • image 10
    How to use Microsoft SQL Server Management Studio to Export and Import your MsSQL database from Azure to local computer AWS/Azure/OpenShift
  • xxxxxx
    How to move the Taskbar to a second screen in Windows Windows
  • windows sign in options
    Sign-in options for Windows: Ditch Password for Enhanced Security Windows
  • csdfg
    What is Cortona: How to disable Cortana via the registry or GPO Windows
  • win10 usb
    How to prevent installation of removable devices Windows
  • Feature image  Error Code 0xC1900101 – 0x30018
    How to Fix Windows Update Error Code 0xC1900101 – 0x30018 Windows

More Related Articles

image 10 How to use Microsoft SQL Server Management Studio to Export and Import your MsSQL database from Azure to local computer AWS/Azure/OpenShift
xxxxxx How to move the Taskbar to a second screen in Windows Windows
windows sign in options Sign-in options for Windows: Ditch Password for Enhanced Security Windows
csdfg What is Cortona: How to disable Cortana via the registry or GPO Windows
win10 usb How to prevent installation of removable devices Windows
Feature image  Error Code 0xC1900101 – 0x30018 How to Fix Windows Update Error Code 0xC1900101 – 0x30018 Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • username
    Is my AD user or service account password correct? Run App as a different User and switch Users in Windows Windows
  • maxresdefault 2 2
    Fix Outlook Not Responding and Outlook Crashing or freezing Network | Monitoring
  • image 166
    How to deploy a .NET application to AWS Elastic Beanstalk using AWS Tool Kit AWS/Azure/OpenShift
  • Feature Image DNF vs APT
    What are the differences between dnf and apt package managers? Linux
  • ansiblebanner
    Install and configure Ansible on Azure Virtual Machine Configuration Management Tool
  • Task Scheduler Errors and Success Codes
    All Task Scheduler Errors and Success Codes Windows Server
  • printserver
    How to set up a Print Server on Windows Servers Windows
  • article 1280x720.166f8634
    How to install DHCP role on Windows Server 2019 Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,808 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.