Bitlocker
How to Use BitLocker Without a Trusted Platform Module (TPM)
TL;DR;
- Open the Local Group Policy Editor (Run
gpedit.msc) - In left pane navigate to:
Computer PolicyComputer ConfigurationAdministrative TemplatesWindows ComponentsBitLocker Drive EncryptionOperating System Drives
- Edit
Require additional authentication at startup - Switch to
Enabled - Ensure
Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)is enabled. - Clock
Ok.
Switching BitLocker protection methods without re-encrypting
In an admin prompt, to check “protectors” status:
manage-bde -protectors -get <drive>
Remove TMP (leaves recovery key intact):
manage-bde -protectors -delete <drive> -type TPM
Add password protector:
manage-bde -protectors -add <drive> -password
It might complain that:
ERROR: An error occurred (code 0x8031006a):
Group Policy settings do not permit the creation of a password.
If that is the case, follow the howto geek above to enable that policy.