Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » BitLocker Protection off: Update UEFI/BIOS to fix issues

BitLocker Protection off: Update UEFI/BIOS to fix issues

Posted on 05/11/202418/11/2024 Christian By Christian No Comments on BitLocker Protection off: Update UEFI/BIOS to fix issues
BitLocker Protection off_Update UEFI-BIOS to fix issues

When BitLocker Protection is “off” means that BitLocker encryption is currently disabled on the drive. In my case, it is disabled and the encryption did not succeeded in the first place. Therefore, we will limit our solution to this use-case. In this article, we shall discuss “BitLocker Protection off: Update UEFI/BIOS to fix issues”. Please see How to Disable BitLocker on Windows 10, how to Change BitLocker Password in Windows, and How to correctly disable BitLocker on Windows Server.

Note: There could be numerous reasons in which many endpoints report a “BitLocker protection status” set to “Off” despite encryption being enabled or disabled.

BitLocker provides information about all drives on the computer; whether or not they are BitLocker-protected, including as you can also see from the image below:

  • Key protector
  • Size
  • BitLocker version
  • Conversion status
  • Percentage encrypted
  • Encryption method
  • Protection status
  • Lock status
  • Identification field
BitLocker Status - Protection Off

Note: You could employing other troubleshooting steps to see if the Group Policies are correctly applied or if you have a hardware/software failure that is not supported. The Windows Event Log will be helpful in this case.

Please see how to Analyze group policies applied to a user and computer account, and how to ‘Backup existing and new BitLocker Recovery Keys to Active Directory“.

What does the “Protection Off” signify

Let us explore what this error likely indicates before moving into the specific steps that resolved it. This approach helps to clarify the potential causes and provides a clearer understanding of the troubleshooting process.

  1. Drive is Not Encrypted: The data on the drive is not secured with BitLocker encryption, so it is stored in plaintext. Thereby, making it readable without any decryption keys. This is the scenario I have encountered.
  2. Decryption is Completed: If BitLocker was previously enabled on the drive and has since been turned off. This means the drive has been decrypted, and the data is no longer protected by BitLocker.
  3. Protection is Suspended: If BitLocker protection was suspended (for example, during system maintenance or Windows updates), it temporarily stores the decryption key in the system, allowing access to data without needing a PIN or recovery key. However, this is a temporary state, and BitLocker can be re-enabled.

Regardless of the likely cause of error. In this state, the data on the drive is vulnerable to unauthorized access. To re-enable BitLocker protection, would need to troubleshoot and fix the root issue before enabling BitLocker as needed or via a third party agent such as MBAM.

Please see How to Disable device encryption on Windows, how to Prevent OS Reinstallation: Change from legacy BIOS to UEFI, and how to Prevent Local Administrators from managing BitLocker with the manage-bde command.

Missing UEFI/BIOS Updates

Because there are numerous reasons, you have to troubleshoot to determine the root issue. Thankfully, you can search through my blog for MBAM or BitLocker archives in order to view more solutions or troubleshooting tips.

In my environment, I have been able to determine that the MBAM Agent could not enable BitLocker on to the PC because it was missing some critical UEFI updates.

This is because, BitLocker relies on the system’s Trusted Platform Module (TPM), which is closely integrated with BIOS or UEFI firmware. Below are some points to make you understand better.

  • BitLocker requires the TPM to store encryption keys securely. If the BIOS/UEFI firmware is outdated, it may lack the latest TPM features or security standards, leading to compatibility issues.
  • Older BIOS or UEFI versions may have security flaws that prevent BitLocker from ensuring a fully secure encryption process. Updates often patch vulnerabilities that could otherwise expose encryption keys or allow unauthorized access.

Please see Modern Standby: PC is automatically encrypted, and Reasons for BitLocker Recovery Prompt: Query the number of BitLocker recovery request.

Apply UEFI Updates

Note: When a device is protected by BitLocker, you can run the dell command updates and this will suspend BitLocker. But since we do not have encryption enabled in the first place. Also, in a referenced link above, when Windows updates are been applied, BitLocker is automatically suspend. BUT, when you manually apply BIOS/UEFI updates, you MUST manually suspend BitLocker else, you will be prompted with the “BitLocker Recovery Mode“

Since we have learned that firmware updates improve overall system stability and can fix issues with the TPM module. If the TPM isn’t functioning correctly due to outdated firmware, BitLocker won’t proceed with encryption.

Therefore, in this session, we shall discuss the fix view direct update and via the DELL Command Update. Launch the DELL Command update and click on when when the wizard opens up.

Dell Command Update

This will start checking for available updates as shown below.

checking updates

As you can see, there are critical and recommended updates found. Please select and install. You can also click to have your PC restarted automatically.

BIOS updates found

Updates are being downloaded and will be installed very shortly.

installing bios updates

As you can see above, I did not select to have the device restarted automatically. Therefore, I am being prompted.

restart dell command update

Device is currently being rebooted

PC restarting-apply latest firmware
Flash pprogress

Note: BitLocker requires Secure Boot (enabled in UEFI) to validate system integrity at startup. If the UEFI firmware does not support or properly configure Secure Boot, BitLocker encryption will also fail. Therefore, double check these settings below.

Enable TPM and other settings in BIOS

Since I am using MBAM to manage BitLocker, I will have to reapply GPO/Force on the device. The encryption would begin very shortly.

FAQs

Can I use BitLocker on external drives?

Yes, BitLocker can be used to encrypt external drives such as USB drives, external hard drives, and SSDs. This provides additional security for your data when it’s stored on portable devices.

Can other operating systems like macOS or Linux open BitLocker-encrypted drives?

No, BitLocker is a Windows-specific feature. Under normal circumstances, macOS and Linux cannot natively open or read BitLocker-encrypted drives without third-party tools or software.

What should I consider before encrypting an external drive with BitLocker?

If you plan to move the encrypted external drive between different operating systems or devices, you need to be aware that non-Windows systems (like macOS or Linux) will likely be unable to access the files unless specific tools or drivers are installed. It’s best to ensure that you will have access to the drive from a Windows device if you use BitLocker.

Can I access a BitLocker-encrypted external drive on another Windows computer?

Yes, as long as you have the correct password or recovery key, you can access the BitLocker-encrypted external drive on any other Windows computer that supports BitLocker.

What happens if I lose access to a BitLocker-encrypted drive?

If you forget your BitLocker password or lose the recovery key, you may be unable to access the data on the encrypted drive. It’s important to back up the recovery key in a secure location when encrypting the drive.

I hope you found the article on “BitLocker Protection off: Update UEFI/BIOS to fix issues” very useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to Create a Child and Tree Domain
Next Post: Why is BitLocker unable to encrypt Removable Drives via MBAM?

Related Posts

  • screenshot 2020 03 14 at 22.47.56
    How to block apps from running in Windows Windows
  • ADDS vs AD LDS
    Differences between AD LDS and AD DS Windows
  • image 6
    Set Browers and Windows to reopen Apps on Startup Windows
  • EnableDisableTPMAutoProv
    Waiting for TPM Auto Provisioning: How to Enable or Disable TPM Auto-provisioning Windows
  • Windows 11 default Icons
    Windows Desktop Icon: How to Make Default System Icons Visible Windows
  • Featured image 5
    How to uninstall and prevent the installation of Microsoft Teams on Windows Windows

More Related Articles

screenshot 2020 03 14 at 22.47.56 How to block apps from running in Windows Windows
ADDS vs AD LDS Differences between AD LDS and AD DS Windows
image 6 Set Browers and Windows to reopen Apps on Startup Windows
EnableDisableTPMAutoProv Waiting for TPM Auto Provisioning: How to Enable or Disable TPM Auto-provisioning Windows
Windows 11 default Icons Windows Desktop Icon: How to Make Default System Icons Visible Windows
Featured image 5 How to uninstall and prevent the installation of Microsoft Teams on Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • SQL Loves Linux 2 Twitter 002 640x358 1
    Install Microsoft SQL Server 2019 and MSSQL Command line tools on Ubuntu Linux Oracle/MSSQL/MySQL
  • Featured Image 1
    How to enable or disable a Remote WMI Connection in Windows Windows
  • How to create a Recovery Partition in Microsoft Windows
    How to create a Recovery Partition in Microsoft Windows 10/11 Windows
  • screenshot 2020 02 23 at 10.50.09
    Perform Pleasant Password Self-serve Reset using the “link” Virtualization
  • windows 10 lock screen
    How to reset your lost or forgotten Windows 10 Password Windows
  • Logon fsilure errors
    Logon Failure Reasons for Windows Event Viewer Windows Server
  • hero azure activedirectory
    How to add and verify a custom domain name to Azure Active Directory AWS/Azure/OpenShift
  • maxresdefault 1
    DriveLock Components: Important DriveLock components to master Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,824 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.