Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows » BitLocker Protection off: Update UEFI/BIOS to fix issues
  • How to create a Recovery Partition in Microsoft Windows
    How to create a Recovery Partition in Microsoft Windows 10/11 Windows
  • KIOSK AssignedAccess
    How to set up a Single App Kiosk Mode Configuration using a Local Account / MDM Bridge WMI Provider Windows
  • google chrome web browser download icon png favpng 2fg4fswmttnwqnvax7lrd1hxp
    How to remove Quick Access from Google Drive Online Windows
  • multcloud
    Best Way to Backup Dropbox to Box JIRA|Confluence|Apps
  • ansible logo600 591x296 1
    Ansible_user=UNREACHABLE {Failed to connect to the host via SSH: SSH: Could not resolve hostname (Name or service not known, unreachable true) Configuration Management Tool
  • proxmox
    Clone a Proxmox Container: CT Restoration Guide Virtualization
  • Screenshot 2020 05 16 at 17.13.18
    What is Jira re-indexing and why you should perform it JIRA|Confluence|Apps
  • Featured image MSDT.
    How to restrict additional Microsoft Support Diagnostic Tool Downloads on Windows Windows

BitLocker Protection off: Update UEFI/BIOS to fix issues

Posted on 05/11/202418/11/2024 Christian By Christian No Comments on BitLocker Protection off: Update UEFI/BIOS to fix issues
BitLocker Protection off_Update UEFI-BIOS to fix issues

When BitLocker Protection is “off” means that BitLocker encryption is currently disabled on the drive. In my case, it is disabled and the encryption did not succeeded in the first place. Therefore, we will limit our solution to this use-case. In this article, we shall discuss “BitLocker Protection off: Update UEFI/BIOS to fix issues”. Please see How to Disable BitLocker on Windows 10, how to Change BitLocker Password in Windows, and How to correctly disable BitLocker on Windows Server.

Note: There could be numerous reasons in which many endpoints report a “BitLocker protection status” set to “Off” despite encryption being enabled or disabled.

BitLocker provides information about all drives on the computer; whether or not they are BitLocker-protected, including as you can also see from the image below:

  • Key protector
  • Size
  • BitLocker version
  • Conversion status
  • Percentage encrypted
  • Encryption method
  • Protection status
  • Lock status
  • Identification field
BitLocker Status - Protection Off

Note: You could employing other troubleshooting steps to see if the Group Policies are correctly applied or if you have a hardware/software failure that is not supported. The Windows Event Log will be helpful in this case.

Please see how to Analyze group policies applied to a user and computer account, and how to ‘Backup existing and new BitLocker Recovery Keys to Active Directory“.

What does the “Protection Off” signify

Let us explore what this error likely indicates before moving into the specific steps that resolved it. This approach helps to clarify the potential causes and provides a clearer understanding of the troubleshooting process.

  1. Drive is Not Encrypted: The data on the drive is not secured with BitLocker encryption, so it is stored in plaintext. Thereby, making it readable without any decryption keys. This is the scenario I have encountered.
  2. Decryption is Completed: If BitLocker was previously enabled on the drive and has since been turned off. This means the drive has been decrypted, and the data is no longer protected by BitLocker.
  3. Protection is Suspended: If BitLocker protection was suspended (for example, during system maintenance or Windows updates), it temporarily stores the decryption key in the system, allowing access to data without needing a PIN or recovery key. However, this is a temporary state, and BitLocker can be re-enabled.

Regardless of the likely cause of error. In this state, the data on the drive is vulnerable to unauthorized access. To re-enable BitLocker protection, would need to troubleshoot and fix the root issue before enabling BitLocker as needed or via a third party agent such as MBAM.

Please see How to Disable device encryption on Windows, how to Prevent OS Reinstallation: Change from legacy BIOS to UEFI, and how to Prevent Local Administrators from managing BitLocker with the manage-bde command.

Missing UEFI/BIOS Updates

Because there are numerous reasons, you have to troubleshoot to determine the root issue. Thankfully, you can search through my blog for MBAM or BitLocker archives in order to view more solutions or troubleshooting tips.

In my environment, I have been able to determine that the MBAM Agent could not enable BitLocker on to the PC because it was missing some critical UEFI updates.

This is because, BitLocker relies on the system’s Trusted Platform Module (TPM), which is closely integrated with BIOS or UEFI firmware. Below are some points to make you understand better.

  • BitLocker requires the TPM to store encryption keys securely. If the BIOS/UEFI firmware is outdated, it may lack the latest TPM features or security standards, leading to compatibility issues.
  • Older BIOS or UEFI versions may have security flaws that prevent BitLocker from ensuring a fully secure encryption process. Updates often patch vulnerabilities that could otherwise expose encryption keys or allow unauthorized access.

Please see Modern Standby: PC is automatically encrypted, and Reasons for BitLocker Recovery Prompt: Query the number of BitLocker recovery request.

Apply UEFI Updates

Note: When a device is protected by BitLocker, you can run the dell command updates and this will suspend BitLocker. But since we do not have encryption enabled in the first place. Also, in a referenced link above, when Windows updates are been applied, BitLocker is automatically suspend. BUT, when you manually apply BIOS/UEFI updates, you MUST manually suspend BitLocker else, you will be prompted with the “BitLocker Recovery Mode“

Since we have learned that firmware updates improve overall system stability and can fix issues with the TPM module. If the TPM isn’t functioning correctly due to outdated firmware, BitLocker won’t proceed with encryption.

Therefore, in this session, we shall discuss the fix view direct update and via the DELL Command Update. Launch the DELL Command update and click on when when the wizard opens up.

Dell Command Update

This will start checking for available updates as shown below.

checking updates

As you can see, there are critical and recommended updates found. Please select and install. You can also click to have your PC restarted automatically.

BIOS updates found

Updates are being downloaded and will be installed very shortly.

installing bios updates

As you can see above, I did not select to have the device restarted automatically. Therefore, I am being prompted.

restart dell command update

Device is currently being rebooted

PC restarting-apply latest firmware
Flash pprogress

Note: BitLocker requires Secure Boot (enabled in UEFI) to validate system integrity at startup. If the UEFI firmware does not support or properly configure Secure Boot, BitLocker encryption will also fail. Therefore, double check these settings below.

Enable TPM and other settings in BIOS

Since I am using MBAM to manage BitLocker, I will have to reapply GPO/Force on the device. The encryption would begin very shortly.

FAQs

Can I use BitLocker on external drives?

Yes, BitLocker can be used to encrypt external drives such as USB drives, external hard drives, and SSDs. This provides additional security for your data when it’s stored on portable devices.

Can other operating systems like macOS or Linux open BitLocker-encrypted drives?

No, BitLocker is a Windows-specific feature. Under normal circumstances, macOS and Linux cannot natively open or read BitLocker-encrypted drives without third-party tools or software.

What should I consider before encrypting an external drive with BitLocker?

If you plan to move the encrypted external drive between different operating systems or devices, you need to be aware that non-Windows systems (like macOS or Linux) will likely be unable to access the files unless specific tools or drivers are installed. It’s best to ensure that you will have access to the drive from a Windows device if you use BitLocker.

Can I access a BitLocker-encrypted external drive on another Windows computer?

Yes, as long as you have the correct password or recovery key, you can access the BitLocker-encrypted external drive on any other Windows computer that supports BitLocker.

What happens if I lose access to a BitLocker-encrypted drive?

If you forget your BitLocker password or lose the recovery key, you may be unable to access the data on the encrypted drive. It’s important to back up the recovery key in a secure location when encrypting the drive.

I hope you found the article on “BitLocker Protection off: Update UEFI/BIOS to fix issues” very useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to Create a Child and Tree Domain
Next Post: Why is BitLocker unable to encrypt Removable Drives via MBAM?

Related Posts

  • feature functionapp
    Deploy a function app from Visual Studio to Azure Platform AWS/Azure/OpenShift
  • image 19
    Download your MySQL database from Azure to a local PC with MySQL Workbench AWS/Azure/OpenShift
  • BitLocked suspended and resumed
    Query MBAM-protected Client for non-compliance [Part 2] Windows
  • image 23
    Copy Deployment Share between Servers without using linked Deployment Shares Windows
  • GPO Blocked Downloads 3
    How to Block downloads on Microsoft Edge using GPO on Windows Server 2019 and 2022 Windows
  • image 81
    How to generate your trial SSL Certificate using DigiCert PKI platform Windows

More Related Articles

feature functionapp Deploy a function app from Visual Studio to Azure Platform AWS/Azure/OpenShift
image 19 Download your MySQL database from Azure to a local PC with MySQL Workbench AWS/Azure/OpenShift
BitLocked suspended and resumed Query MBAM-protected Client for non-compliance [Part 2] Windows
image 23 Copy Deployment Share between Servers without using linked Deployment Shares Windows
GPO Blocked Downloads 3 How to Block downloads on Microsoft Edge using GPO on Windows Server 2019 and 2022 Windows
image 81 How to generate your trial SSL Certificate using DigiCert PKI platform Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • How to create a Recovery Partition in Microsoft Windows
    How to create a Recovery Partition in Microsoft Windows 10/11 Windows
  • KIOSK AssignedAccess
    How to set up a Single App Kiosk Mode Configuration using a Local Account / MDM Bridge WMI Provider Windows
  • google chrome web browser download icon png favpng 2fg4fswmttnwqnvax7lrd1hxp
    How to remove Quick Access from Google Drive Online Windows
  • multcloud
    Best Way to Backup Dropbox to Box JIRA|Confluence|Apps
  • ansible logo600 591x296 1
    Ansible_user=UNREACHABLE {Failed to connect to the host via SSH: SSH: Could not resolve hostname (Name or service not known, unreachable true) Configuration Management Tool
  • proxmox
    Clone a Proxmox Container: CT Restoration Guide Virtualization
  • Screenshot 2020 05 16 at 17.13.18
    What is Jira re-indexing and why you should perform it JIRA|Confluence|Apps
  • Featured image MSDT.
    How to restrict additional Microsoft Support Diagnostic Tool Downloads on Windows Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.