UNSOLVED

ecarpenter

updated

4 years ago

E

ecarpenter

1 Rookie

5 Posts

0

2470

August 11th, 2022 07:00

Inspiron 7391 Bios Update enabled Bitlocker

Anyone else found Bitlocker enabled after they update the BIOS to version 1.9.1?

Bitlocker has never been enabled or set up on this laptop before.

Before it gets to the Windows login I get the message "Bitlocker needs your recovery key to unlock your drive because Secure Boot Policy has unexpectedly changed"

Literally the only thing I was doing was Windows updated and decided to do the Dell BIOS update last.

  • nobox

    8 Posts

    1247

    0

    Posted August 15th, 2022 08:00

    hello

    i am in the same case with a vostro 5515... just accepted a windows update and now i have one inaccessible computer !!! did'nt used a microsoft account so no unlock code is possible, dell or microsoft can do nothing for me ! incredible...

    hope you will find a solution, for me it is buying a M2>usb card and make myself a backup before re installing os.... without this bitlocker . TOS76>of course !

  • X-SPIKE

    2 Posts

    1243

    0

    Posted August 15th, 2022 10:00

    There is an option to backup the key on the encryption option tab to unlock the drive in the case of hardware change (failure). Must always be used, unless you want data to be blocked permanently in such situations.

    It's important to backup BitLocker key on a separate location.

    Unfortunately Windows Home Edition encrypts drive by default and never offers to backup that key, but option exists. (assuming you've been forced to MS account which allegedly suppose to save the key for you). If you have Home Edition, I believe key is saved to the account even by force, due to it does not enable BitLocker Lite until you login to MS Account.

  • lmacri

    6 Operator

    1873 Posts

    7974 Points

    1231

    0

    Posted August 15th, 2022 13:00


    @ecarpenter wrote:

    Anyone else found Bitlocker enabled after they update the BIOS to version 1.9.1?...Before it gets to the Windows login I get the message "Bitlocker needs your recovery key to unlock your drive because Secure Boot Policy has unexpectedly changed"

    Literally the only thing I was doing was Windows updated and decided to do the Dell BIOS update last.



    Hi ecarpenter:

    What is your Windows operating system [if Win 10 or Win 11 please include the edition (Home or Pro), version and build shown at Settings | System | About | Windows Specifications], and are you sure your BIOS is currently v1.9.1?  I'm not sure if you have the Dell Inspiron 7391 (the support page <here> for that model lists the Dell Inspiron 5391/7391 and Vostro 5391 System BIOS v1.19.1) or if you have the Dell Inspiron 7391 2-in-1 (the support page <here> for that model lists the Dell Inspiron 7391/7591/7791 System BIOS v1.17.0) , but if you don't know your current BIOS version open a Run dialog box, enter msinfo32 to open your System Information panel, and look for the “BIOS Version/Date” field.

    Window Update delivered KB5012170 (2022-08 Security Update for Windows 10 Version 21H2 for x64-based Systems) to Win 8.1 and higher machines during this month's August 2022 Patch Tuesday updates. The KB article <here> for KB5012170 is titled KB5012170: Security update for Secure Boot DBX: August 9, 2022 and Microsoft is already tracking problems with this update in the Known Issues section of that KB article. Also see Neowin's 13-Aug-2022 Microsoft Warns About Windows Update Fails, UEFI Update Might be Necessary to Fix and the ghacks.net 15-Aug-2022 article KB5012170: Windows Update Error 0x800f0922, UEFI BIOS Update May Resolve It. I haven't heard of KB5012170 enabling BitLocker (yet) but suspected problems with KB5012170 and Secure Boot are still being reported.

    Just an FYI that KB5012170 does not appear to have caused any issues on my Inspiron 5584 / Win 10 Pro v21H2 laptop. BitLocker is still disabled at Control Panel | System and Security | BitLocker Drive Encryption and when I checked the status of Secure Boot in System Information I confirmed that Secure Boot was disabled both before and after my Aug 2022 Patch Tuesday updates were installed on 12-Aug-2022.  I installed  the latest Inspiron 5583/5584 BIOS v1.20.0 for my system on 14-Aug-2022 and this did not change my BitLocker or Secure Boot settings.

    Win 10 Pro v21H2 System Information BIOS Mode UEFI Secure Boot Disabled 10 Aug 2022.png

    ---------------
    64-bit Win 10 Pro v21H2 build 19044.1889 * Firefox v103.0.2 * Microsoft Defender v4.18.2205.7-1.1.19500.2 * Malwarebytes Premium v4.5.12.204-1.0.1725 * Macrium Reflect Free v8.0.6867 * Dell SupportAssist v3.11.4.29 * Dell Update Windows Universal v4.6.0 * Inspiron 5583/5584 BIOS v1.20.0
    Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, 256 GB Toshiba KBG40ZNS256G NVMe SSD, Intel UHD Graphics 620

  • lmacri

    6 Operator

    1873 Posts

    7974 Points

    1230

    0

    Posted August 15th, 2022 14:00

    ... and further to your immediate problem, the MS support article Finding your BitLocker Recovery Key in Windows might help you find your recovery key.  I used to have BitLocker enabled on my Inspiron 5584 and kept the recovery key backed up on a USB thumb drive, but if you have access to a working computer and can log in to your Microsoft Account that support article will explain where you might find a copy of your recovery key online.

  • lmacri

    6 Operator

    1873 Posts

    7974 Points

    1206

    0

    Posted August 16th, 2022 11:00

    Hi ecarpenter / nobox:

    Just a bit of additional information.

    I posted about your problem in the AskWoody.com forum thread It’s Time for Those August Updates To Be Deferred and user PKCano replied in post # 2470657 that "Win10 and Win11 Pro turn on Bitlocker in the OOBE by default". I have an Inspiron 5584 / Win 10 Pro laptop and when I performed a reset to factory condition in August 2020 I vaguely recall now that I had to decline the use of BitLocker encryption during the initial "out-of-box experience" setup of my system.

    The MS support article Overview of BitLocker Device Encryption in Windows also states that "When a clean installation of Windows 11 or Windows 10 is completed and the out-of-box experience is finished, the computer is prepared for first use. As part of this preparation, BitLocker Device Encryption is initialized on the operating system drive and fixed data drives..." and also notes that "Beginning in Windows 8.1, Windows automatically enables BitLocker Device Encryption on devices that support Modern Standby. With Windows 11 and Windows 10, Microsoft offers BitLocker Device Encryption support on a much broader range of devices, including those that are Modern Standby, and devices that run Windows 10 Home edition or Windows 11." See my AskWoody post # 2444880 in “Modern” Standby in Newer PCs showing that my Inspiron 5584 does not support the Modern Standby sleep state, which might be another reason why BitLocker encryption is not enabled on my system.

    I also found a multi-page thread BitLocker: Need a Key But I Never Installed It in the Windows 10 board of this Dell Community. It doesn't explain why a change to your Secure Boot settings suddenly triggered BitLocker to request your recovery key, but I suspect BitLocker encryption has been enabled on your system for a long time and you just weren't aware of it.
    ----------------------
    64-bit Win 10 Pro v21H2 build 19044.1889 * Firefox v103.0.2 * Microsoft Defender v4.18.2205.7-1.1.19500.2 * Malwarebytes Premium v4.5.12.204-1.0.1725 * Macrium Reflect Free v8.0.6867 * Dell SupportAssist v3.11.4.29 * Dell Update Windows Universal v4.6.0 * Inspiron 5583/5584 BIOS v1.20.0
    Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, 256 GB Toshiba KBG40ZNS256G NVMe SSD, Intel UHD Graphics 620

  • nobox

    8 Posts

    1190

    0

    Posted August 17th, 2022 02:00

    hello thank you for your searches...

    yes dell is putting bitlocker but has no solution if you have to get the key back !!!

    apparently they know they are using one unsecure process for customer but they don"t tell, and they don't offer any solution or compensation when you are in trouble with this...

    this was my last dell ever !!

    g

  • nobox

    8 Posts

    1189

    1

    Posted August 17th, 2022 03:00

    well i unlocked it... just to let you know, if you are using a microsoft account pro or edu with azure active directory inside, you can connect to azure active directory and serach in it for the devices you used to connect to the account... the bitlocker key is there. no need to have been using an email as an acount for windows, just beeing using one on your machine... and directly go to the azure active directory, not on the url told by the bitlocker blue screen ! this one told me that my microsoft account wasn't existing !! pffffffffff

  • lmacri

    6 Operator

    1873 Posts

    7974 Points

    1180

    0

    Posted August 17th, 2022 06:00


    @nobox wrote:

    well i unlocked it... just to let you know, if you are using a microsoft account pro or edu with azure active directory inside, you can connect to azure active directory and serach in it for the devices you used to connect to the account...



    Hi nobox:

    Glad to hear you found your recovery key.

    From the MS support article Finding your BitLocker Recovery Key in Windows I mentioned <here> in my 15-Aug-2022 post:


    " In an Azure Active Directory account: If your device was ever signed into an organization using a work or school email account, your recovery key may be stored in that organization's Azure AD account. You may be able to access it directly or you may need to contact a system administrator to access your recovery key."

    The Dell support article Automatic Windows Device Encryption or BitLocker on Dell Systems has more information on how device encryption can sometimes be automatically enabled on Dell computers after the initial Out-of-Box Experience (OOBE) is completed. That support article has instructions for both Win 10 Home and Win 10 Pro on how to suspend the device encryption before flashing the system BIOS (in a perfect world, newer installers for Dell BIOS updates will automatically suspend BitLocker encryption before starting the BIOS update) or turn off device encryption before performing a reset to factory condition.

    I have a Win 10 Pro OS so BitLocker can be managed from Control Panel | System and Security | BitLocker Device Encryption. Less than a year after purchasing my Inspiron 5584 laptop it refused to boot up and would not enter the Dell recovery environment and I was forced to perform a reset to factory condition. I could not proceed until I entered my recovery key, and I was fortunate that I had printed out a hard copy of my 48-digit recovery key and tucked it away in a safe place. After my reset to factory condition and OOBE setup I made sure that BitLocker was turned OFF and started using Macrium Reflect Free imaging software to create rescue media (a bootable USB) and the occasional full disk image that is stored on an external backup drive in case I ever have to perform another emergency recovery. Here's an old image of what my BitLocker drive encryption used to look like when BitLocker was still turned ON before my reset to factory condition in 2020.

    Win 10 v1909 Suspend Bitlocker Control Panel 06 Jun 2020.png
    ----------------------
    64-bit Win 10 Pro v21H2 build 19044.1889 * Firefox v103.0.2 * Microsoft Defender v4.18.2205.7-1.1.19500.2 * Malwarebytes Premium v4.5.13.208-1.0.1740 * Macrium Reflect Free v8.0.6867 * Dell SupportAssist v3.11.4.29 * Dell Update Windows Universal v4.6.0 * Inspiron 5583/5584 BIOS v1.20.0
    Dell Inspiron 15 5584, Intel i5-8265U CPU, 8 GB RAM, 256 GB Toshiba KBG40ZNS256G NVMe SSD, Intel UHD Graphics 620


  • nobox

    8 Posts

    1171

    0

    Posted August 17th, 2022 07:00

    hello imacri

    yes just crazy that on the blue screen of blocked bitlocker, the url proposed was unfonctionnal ! i used the pro account in "aka.ms/aadrecoverykey" and the other one, it told me that the account wasn't valid !!! after that i stopped searching around this account, which was the good one ! Bravo microsoft !

  • ann_droid

    2 Intern

    508 Posts

    568

    0

    Posted August 17th, 2022 09:00

    Hi

    "BitLocker is capable of encrypting entire hard drives, including both system and data drives."

     

    So my keeping my Bitlocker key on a separate drive, and separate partition will still get encrypted?

     

    If I put it inside a Linux Mint directory that also gets encrypted by Microsoft?