1 Rookie
•
4 Posts
0
8187
October 8th, 2023 23:36
Device Encryption missing due to "PCR7 Configuration Binding Not Possible" Error
XPS 15 7590
I would like to use the built-in device encryption that comes with Windows 11 Home, but it is not enabled. In System Information, I see these 2 entries:
PCR7 Configuration: Binding Not Possible
Device Encryption Support Reasons for failed automatic device encryption: PCR7 binding is not supported
In the Event Viewer, I see these error messages:
Microsoft-Windows-BitLocker-API/Management
Event ID: 835
BitLocker cannot use Secure Boot for integrity because the expected TCG Log entry for the OS Loader Authority has invalid structure.
The event is expected to be an EV_EFI_VARIABLE_AUTHORITY event. The event data must be formatted as an EFI_VARIABLE_DATA structure with VariableName set to EFI_IMAGE_SECURITY_DATABASEGUID and UnicodeName set to 'db'.
Microsoft-Windows-BitLocker-API/Management
Event ID: 834
BitLocker determined that the TCG log is invalid for use of Secure Boot. The filtered TCG log for PCR[7] is included in this event.
How do I resolve this binding error on my device?



yohohoho
1 Rookie
•
4 Posts
1
October 10th, 2023 04:36
Follow up: I managed to resolve this!
A while back, I tried to install WSL on my computer, and kept running into error screens on start up. I had to disable a setting in my BIOS: the "VT for Direct IO" option in the Virtualization sub-menu.
After the fresh install of Windows, I reset my BIOS, but I unchecked that box again to match my old settings.
Apparently unchecking that box adds something to the Secure Boot such that it prevents proper binding of PCR7. Once I re-enabled that checkbox in my BIOS, the PCR7 bindings were fixed, and device encryption turned on! WSL even works just fine.
(edited)
DELL-Jesse L
Moderator
•
17.8K Posts
0
October 9th, 2023 10:58
yohohoho,
To receive assistance from Dell chat support, they need to verify the warranty status and ownership. Then you must troubleshoot with them. Click the "Get Help Now" icon on the right to start a live chat session. If already out of warranty, click here for the Dell out of warranty offering.
ejn63
10 Elder
•
30K Posts
0
October 9th, 2023 11:00
Make sure the system is in UEFI mode (not legacy/CSM) and that secure boot is enabled -- both of those are required.
yohohoho
1 Rookie
•
4 Posts
0
October 10th, 2023 03:28
@ejn63 I have all of the prerequisites for Device Encryption setup and enabled on my system:
My system supports Modern Standby:
> powercfg /a
The following sleep states are available on this system:
Standby (S0 Low Power Idle) Network Connected
Hibernate
Fast Startup
It is a UEFI BIOS
> Confirm-SecureBootUEFI
True
The TPM is set up:
Secure Boot is Enabled:
RMG28
1 Message
0
October 13th, 2023 15:09
Hello could you explain a bit in detail this part?
" Apparently checking that box adds something to the Secure Boot such that it prevents proper binding of PCR7. Once I re-enabled that checkbox in my BIOS, the PCR7 bindings were fixed, and device encryption turned on! WSL even works just fine."
We are facing the same issue for aprox 20 devices
We have checked everything,
UEFI- enabled
TPM- 2.0 active
Secure boot- enabled
Disk - GPT
modern standby- enabled
Suspended protectors and re-enabled
Deleted protectors and re-add
Only cleaning the TPM didn t try
The next plan of action is the following: Factory reset > BIOS reset> cleaning the TPM
The question is, after you have re-imaged the PC and run the BIOS reset, the "VT for Direct IO" option you keep it as default? I know the default configuration is "enabled", you said you have disabled it, at the end you choose to enabled it back? or keep it disabled?
yohohoho
1 Rookie
•
4 Posts
2
October 13th, 2023 21:22
@RMG28
(edited)
Gilles.P
1 Rookie
•
47 Posts
0
June 27th, 2025 14:29
On my brand-new Tower Plus EBT2250 I'm also facing the same issue but in my case, "VT for Direct IO" is set in the BIOS.