Updating the BIOS on Dell Computers With BitLocker Enabled
Summary: This article provides information about steps to carry out before updating your BIOS on computers with BitLocker encryption enabled. Also, learn what to do if the latest BIOS update has caused a BitLocker error. ...
Symptoms
Be aware of the following when updating the BIOS on a computer with BitLocker enabled.
Cause
An error may occur with BitLocker where BitLocker cannot enable or resume when the Trusted Platform Module (TPM) is in TPM 2.0 mode. This happens when the BIOS installed is one of the affected BIOS versions that is listed below. Update the BIOS to the latest available version for your computer from Dell Drivers & Downloads to resolve the issue.
| Platform | Affected BIOS Version |
|---|---|
| Latitude 7275 | 1.1.29 |
| Latitude 5175 / 5179 | 1.0.22 |
| Latitude 7370 | 1.11.4 |
| Latitude E7270/E7470 | 1.14.3 |
| Latitude E5270/E5470/E5570 | 1.13.3 |
| Precision 3510 | 1.13.3 |
| Precision 7510/7710 | 1.11.4 |
Resolution
There are several possible methods to prevent or resolve this issue:
- Suspend BitLocker before updating the BIOS
- Edit Group Policy for BitLocker
- Edit Services for BitLocker
Click the appropriate method for more information.
Suspend BitLocker before updating the BIOS
- Click the Start menu.
- Go to Control Panel, System and Security, then BitLocker Drive Encryption.
- Select Suspend Protection. Select Yes if prompted to confirm the change.

- Download and install the latest BIOS for your computer from Dell Drivers & Downloads.
Note: For more information about how to update the BIOS, refer to the Dell BIOS and UEFI Update Download and Installation Guide.
- After the BIOS is updated, repeat steps 1-2 and then click Resume Protection.

Edit Group Policy for BitLocker
- Click the Start menu. In the search box, type
gpedit.mscand then press Enter.Note: Administrator rights are required to make edits to Group Policy. - Local Computer Policy is displayed with options for Computer Configuration and User Configuration. Under Computer Configuration, click Administrative Templates.
- Open Windows Components and then click the BitLocker Drive Encryption folder.
- In the right pane, click Configure TPM Platform Validation Profile.

- Double-click the Require additional authentication at startup policy.
- Set the policy to Disabled.
- Click Apply, then OK. Restart the computer.
- Once the BIOS is updated, repeat steps 1-5 and then Reenable BitLocker. Click Apply and then click OK.
Edit Services for BitLocker
- Click the Start menu. In the search box, type
servicesand then press Enter. - Scroll down and then double-click the BitLocker Disk Drive Encryption Service.
- Under the General tab in the open window, next to Startup type, click the drop-down box and then select Disable.
Note: The drop-down box, by default, says Manual.
- Under Service status, click Stop.

Additional Information
How to Update the BIOS
Duration: 00:01:03 (hh:mm:ss)
When available, closed caption (subtitles) language settings can be chosen using the CC icon on this video player.
Refer to these Dell Knowledge Base articles for related information: