Dell BitLocker Manager Reporting Unprotected After Changing Protector Policy

Oversigt: This article discusses the root cause and resolution to Dell BitLocker Manager (formerly Dell Data Protection | Dell BitLocker Manager) reporting unprotected after changing protected Dell Data Security server (formerly Dell Data Protection server) policy from Configure TPM Startup PIN to Configure TPM Startup. ...

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Symptomer

Affected Products:

  • Dell BitLocker Manager
  • Dell Data Protection | BitLocker Manager

Affected Versions:

  • v10.10 and Earlier

In the Dell Data Security server console, an administrator may change the protectors that are required to unlock an endpoint protected with Dell BitLocker Manager.

Dell Data Security TPM Configuration
Figure 1: (English Only) Dell Data Security TPM Configuration

Changing Configure TPM Startup PIN to Configure TPM Startup cause:

  • After the first reboot post policies change:
    • The PIN is required to unlock the operating system disk.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and Disk C: reports Fully encrypted.

Encryption Status
Figure 2: (English Only) Encryption Status 

  • After the second reboot:
    • A PIN is no longer be required to unlock the volume.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and the Disk C: Fully encrypted.

On the Dell Data Security administration console, the endpoint reports as Unprotected:

Endpoint Details
Figure 3: (English Only) Endpoint Details

On the endpoints, the DellAgent.log in C:\ProgramData\Dell\Dell Data Protection shows the error below:

2019.12.10 14:16:34.015 [04596] (00022) E Bde: volume C: unable to enable key protectors - PolicyStartupTpmRequired

Trying to manually resume BitLocker fails:

BitLocker Drive Encryption error
Figure 4: (English Only) BitLocker Drive Encryption error

 

Årsag

Not Applicable

Løsning

To address this issue, it is necessary to manually change the policy settings for BitLocker on the endpoints experiencing the issue.

To resolve:

  1. Right-click the Windows Start Menu and then select Run.

Click Run
Figure 5: (English Only) Click Run

  1. In the Run menu, type control panel and then click OK.

Run Control Panel
Figure 6: (English Only) Run Control Panel

  1. In the Control Panel, click BitLocker Drive Encryption.

BitLocker Drive Encryption
Figure 7: (English Only) BitLocker Drive Encryption

  1. Click Change how Drive is Unlocked at startup.

BitLocker Suspended
Figure 8: (English Only) BitLocker Suspended

  1. In the Wizard, select Let BitLocker automatically unlock my drive.

BitLocker Drive Encryption
Figure 9: (English Only) BitLocker Drive Encryption

  1. Click Resume protection.

BitLocker Drive Encryption
Figure 10: (English Only) BitLocker Drive Encryption

The disk will show as Protected again, after performing these steps:

Encryption Status
Figure 11: (English Only) Encryption Status

It is possible to perform the same steps using the administration command line below:

manage-bde -protectors -add c: -TPM
manage-bde -protectors -enable c:

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Berørte produkter

Dell Encryption
Artikelegenskaber
Artikelnummer: 000129595
Artikeltype: Solution
Senest ændret: 16 jan. 2024
Version:  10
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.