Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » BitLocker Protection off: Update UEFI/BIOS to fix issues
  • feature photo quit vim
    How to Exit Linux Vim or Vi Editor Linux
  • Featured image   Network Access Permission...
    Fix You Might Not Have Permission to Use This Network Resource Error Network | Monitoring
  • Feature image LSA
    How to configure additional LSA Protection Security | Vulnerability Scans and Assessment
  • windows admin center banner 825x400 1
    Fix failed to create new Scheduled Task RemoteException Windows Server
  • maxresdefault
    Install and manage IP Address Management on Windows Server Windows
  • 980239e9 cisco logo 2
    LACP Configuration on Cisco 3650 Switch Network | Monitoring
  • VMware
    How to install Windows Server 2022 on VMware Workstation Virtualization
  • screenshot 2020 03 07 at 22.25.21
    How to configure the FrontFace Lockdown Tool Windows

BitLocker Protection off: Update UEFI/BIOS to fix issues

Posted on 05/11/202418/11/2024 Christian By Christian No Comments on BitLocker Protection off: Update UEFI/BIOS to fix issues
BitLocker Protection off_Update UEFI-BIOS to fix issues

When BitLocker Protection is “off” means that BitLocker encryption is currently disabled on the drive. In my case, it is disabled and the encryption did not succeeded in the first place. Therefore, we will limit our solution to this use-case. In this article, we shall discuss “BitLocker Protection off: Update UEFI/BIOS to fix issues”. Please see How to Disable BitLocker on Windows 10, how to Change BitLocker Password in Windows, and How to correctly disable BitLocker on Windows Server.

Note: There could be numerous reasons in which many endpoints report a “BitLocker protection status” set to “Off” despite encryption being enabled or disabled.

BitLocker provides information about all drives on the computer; whether or not they are BitLocker-protected, including as you can also see from the image below:

  • Key protector
  • Size
  • BitLocker version
  • Conversion status
  • Percentage encrypted
  • Encryption method
  • Protection status
  • Lock status
  • Identification field
BitLocker Status - Protection Off

Note: You could employing other troubleshooting steps to see if the Group Policies are correctly applied or if you have a hardware/software failure that is not supported. The Windows Event Log will be helpful in this case.

Please see how to Analyze group policies applied to a user and computer account, and how to ‘Backup existing and new BitLocker Recovery Keys to Active Directory“.

What does the “Protection Off” signify

Let us explore what this error likely indicates before moving into the specific steps that resolved it. This approach helps to clarify the potential causes and provides a clearer understanding of the troubleshooting process.

  1. Drive is Not Encrypted: The data on the drive is not secured with BitLocker encryption, so it is stored in plaintext. Thereby, making it readable without any decryption keys. This is the scenario I have encountered.
  2. Decryption is Completed: If BitLocker was previously enabled on the drive and has since been turned off. This means the drive has been decrypted, and the data is no longer protected by BitLocker.
  3. Protection is Suspended: If BitLocker protection was suspended (for example, during system maintenance or Windows updates), it temporarily stores the decryption key in the system, allowing access to data without needing a PIN or recovery key. However, this is a temporary state, and BitLocker can be re-enabled.

Regardless of the likely cause of error. In this state, the data on the drive is vulnerable to unauthorized access. To re-enable BitLocker protection, would need to troubleshoot and fix the root issue before enabling BitLocker as needed or via a third party agent such as MBAM.

Please see How to Disable device encryption on Windows, how to Prevent OS Reinstallation: Change from legacy BIOS to UEFI, and how to Prevent Local Administrators from managing BitLocker with the manage-bde command.

Missing UEFI/BIOS Updates

Because there are numerous reasons, you have to troubleshoot to determine the root issue. Thankfully, you can search through my blog for MBAM or BitLocker archives in order to view more solutions or troubleshooting tips.

In my environment, I have been able to determine that the MBAM Agent could not enable BitLocker on to the PC because it was missing some critical UEFI updates.

This is because, BitLocker relies on the system’s Trusted Platform Module (TPM), which is closely integrated with BIOS or UEFI firmware. Below are some points to make you understand better.

  • BitLocker requires the TPM to store encryption keys securely. If the BIOS/UEFI firmware is outdated, it may lack the latest TPM features or security standards, leading to compatibility issues.
  • Older BIOS or UEFI versions may have security flaws that prevent BitLocker from ensuring a fully secure encryption process. Updates often patch vulnerabilities that could otherwise expose encryption keys or allow unauthorized access.

Please see Modern Standby: PC is automatically encrypted, and Reasons for BitLocker Recovery Prompt: Query the number of BitLocker recovery request.

Apply UEFI Updates

Note: When a device is protected by BitLocker, you can run the dell command updates and this will suspend BitLocker. But since we do not have encryption enabled in the first place. Also, in a referenced link above, when Windows updates are been applied, BitLocker is automatically suspend. BUT, when you manually apply BIOS/UEFI updates, you MUST manually suspend BitLocker else, you will be prompted with the “BitLocker Recovery Mode“

Since we have learned that firmware updates improve overall system stability and can fix issues with the TPM module. If the TPM isn’t functioning correctly due to outdated firmware, BitLocker won’t proceed with encryption.

Therefore, in this session, we shall discuss the fix view direct update and via the DELL Command Update. Launch the DELL Command update and click on when when the wizard opens up.

Dell Command Update

This will start checking for available updates as shown below.

checking updates

As you can see, there are critical and recommended updates found. Please select and install. You can also click to have your PC restarted automatically.

BIOS updates found

Updates are being downloaded and will be installed very shortly.

installing bios updates

As you can see above, I did not select to have the device restarted automatically. Therefore, I am being prompted.

restart dell command update

Device is currently being rebooted

PC restarting-apply latest firmware
Flash pprogress

Note: BitLocker requires Secure Boot (enabled in UEFI) to validate system integrity at startup. If the UEFI firmware does not support or properly configure Secure Boot, BitLocker encryption will also fail. Therefore, double check these settings below.

Enable TPM and other settings in BIOS

Since I am using MBAM to manage BitLocker, I will have to reapply GPO/Force on the device. The encryption would begin very shortly.

FAQs

Can I use BitLocker on external drives?

Yes, BitLocker can be used to encrypt external drives such as USB drives, external hard drives, and SSDs. This provides additional security for your data when it’s stored on portable devices.

Can other operating systems like macOS or Linux open BitLocker-encrypted drives?

No, BitLocker is a Windows-specific feature. Under normal circumstances, macOS and Linux cannot natively open or read BitLocker-encrypted drives without third-party tools or software.

What should I consider before encrypting an external drive with BitLocker?

If you plan to move the encrypted external drive between different operating systems or devices, you need to be aware that non-Windows systems (like macOS or Linux) will likely be unable to access the files unless specific tools or drivers are installed. It’s best to ensure that you will have access to the drive from a Windows device if you use BitLocker.

Can I access a BitLocker-encrypted external drive on another Windows computer?

Yes, as long as you have the correct password or recovery key, you can access the BitLocker-encrypted external drive on any other Windows computer that supports BitLocker.

What happens if I lose access to a BitLocker-encrypted drive?

If you forget your BitLocker password or lose the recovery key, you may be unable to access the data on the encrypted drive. It’s important to back up the recovery key in a secure location when encrypting the drive.

I hope you found the article on “BitLocker Protection off: Update UEFI/BIOS to fix issues” very useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to Create a Child and Tree Domain
Next Post: Why is BitLocker unable to encrypt Removable Drives via MBAM?

Related Posts

  • what is winrm
    WinRM cannot complete the operation, verify that the specified computer name is valid Windows
  • shut down 650x300 1
    How to prevent users from shutting down in a Virtual Machine Windows
  • Disable download in Microsoft Edge
    How to disable file download in Microsoft Edge Windows
  • BitLocker beviour when MBAM Agent is removed   No uninstall options in control panel to remove app
    BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel Windows
  • Windows 11 default Icons
    Windows Desktop Icon: How to Make Default System Icons Visible Windows
  • WonderFox Video Watermark
    Install and use WonderFox Video Watermark Windows

More Related Articles

what is winrm WinRM cannot complete the operation, verify that the specified computer name is valid Windows
shut down 650x300 1 How to prevent users from shutting down in a Virtual Machine Windows
Disable download in Microsoft Edge How to disable file download in Microsoft Edge Windows
BitLocker beviour when MBAM Agent is removed   No uninstall options in control panel to remove app BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel Windows
Windows 11 default Icons Windows Desktop Icon: How to Make Default System Icons Visible Windows
WonderFox Video Watermark Install and use WonderFox Video Watermark Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • feature photo quit vim
    How to Exit Linux Vim or Vi Editor Linux
  • Featured image   Network Access Permission...
    Fix You Might Not Have Permission to Use This Network Resource Error Network | Monitoring
  • Feature image LSA
    How to configure additional LSA Protection Security | Vulnerability Scans and Assessment
  • windows admin center banner 825x400 1
    Fix failed to create new Scheduled Task RemoteException Windows Server
  • maxresdefault
    Install and manage IP Address Management on Windows Server Windows
  • 980239e9 cisco logo 2
    LACP Configuration on Cisco 3650 Switch Network | Monitoring
  • VMware
    How to install Windows Server 2022 on VMware Workstation Virtualization
  • screenshot 2020 03 07 at 22.25.21
    How to configure the FrontFace Lockdown Tool Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,834 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.