Start a Conversation

Solved!

Go to Solution

4372

January 27th, 2021 03:00

BitLocker Issues and Cannot Clear/Reset TPM

Hi,

On a new Precision 5550 (BIOS version 1.6.1) I am trying to encrypt the HDD using BitLocker. However, BitLocker encryption never starts, and upon reboot and logging back into Windows the following message is displayed;

"BitLocker could not be enabled.
The BitLocker encryption key cannot be obtained.
Verify that the trusted Platform Module (TPM) is enabled and ownership has been taken. If this computer does not have TPM, verify that the USB drive is inserted and available.

c: was not encrypted."

 

I have tried;

  • Running Dell Command Update for any missing updates
  • Turning off TPM Auto-Provisioning (via Powershell)
  • Removing BIOS password
  • Turning off TPM in the BIOS rebooting, then re-enabling
  • Trying to clear TPM using tpm.msc
  • Trying to clear TPM using "Settings" (I assume it just calls tpm.msc under the bonnet)

 

Checking TPM.msc it states that "TPM is ready for us"

Checking the BIOS TPM 2.0 s enabled, along with Attestation and Key Storage.

 

When selecting this option and rebooting, I am expecting something similar to the following to appear on the screen during boot;

"A configuration change was requested to enable, activate, clear, enable, and activate the TPM

This action will clear and turn on the computer's TPM (Trusted platform Module)

WARNING: This request will remove any keys stored in the TPM

Press F12 to enable, activate, clear, enable, and activate the TPM
Press ESC to reject this change request and continue"

Nothing appears, and the Windows login screen appears.

 

For reference this is a new Precision 5550 (Nov. 2020), running Windows 10 ( 64 bit,  2004, 19041.746) - provisioned using a corporate build (no problems with other Dell laptops). The BIOS version is 1.6.1.

 

I am fast running out of ideas, so any guidance gratefully received.

 

Thanks in advance,

 

Jon.

 

3 Posts

January 27th, 2021 23:00

I finally got the laptop encrypted.

Turned out that the issue was because due to the Bitlocker process being unable to talk to our company servers (currently being away from the office due to COVID). Connecting the laptop, over VPN, I was able to get Bitlocker to encrypt the hard disk.

The clue to all of this was in the Dell Encryption Enterprise console log file. Specifically;

(00006) I Comm : An error occurred while trying to obtain the IP address of the server from the URL provided. No such host is known

and...

(00007) W Comm : server endpoint https://xxxxxxxxx.xxxxxxxx.lan:8888/agent was not found

However, for reference, the following seems irrelevant to my situation and occurs when working;

(00007) E Comm : Could not locate saasManager plugin


Once connected and the process re-attempt the log file started showing successful key escrow messages, and encryption progress could be seen via the Dell Encryption console, and also Get-BitLockerVolume (PowerShell).

Hope this helps folks,

Jon.

Moderator

 • 

25.1K Posts

January 27th, 2021 21:00

We tried reaching you on a private message asking for the Service Tag number to ascertain the warranty but did not receive a response. Please feel free to reply to the private message whenever you are available.

No Events found!

Top