Dell BitLocker Manager Reporting Unprotected After Changing Protector Policy

Resumen: This article discusses the root cause and resolution to Dell BitLocker Manager (formerly Dell Data Protection | Dell BitLocker Manager) reporting unprotected after changing protected Dell Data Security server (formerly Dell Data Protection server) policy from Configure TPM Startup PIN to Configure TPM Startup. ...

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Síntomas

Affected Products:

  • Dell BitLocker Manager
  • Dell Data Protection | BitLocker Manager

Affected Versions:

  • v10.10 and Earlier

In the Dell Data Security server console, an administrator may change the protectors that are required to unlock an endpoint protected with Dell BitLocker Manager.

Dell Data Security TPM Configuration
Figure 1: (English Only) Dell Data Security TPM Configuration

Changing Configure TPM Startup PIN to Configure TPM Startup cause:

  • After the first reboot post policies change:
    • The PIN is required to unlock the operating system disk.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and Disk C: reports Fully encrypted.

Encryption Status
Figure 2: (English Only) Encryption Status 

  • After the second reboot:
    • A PIN is no longer be required to unlock the volume.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and the Disk C: Fully encrypted.

On the Dell Data Security administration console, the endpoint reports as Unprotected:

Endpoint Details
Figure 3: (English Only) Endpoint Details

On the endpoints, the DellAgent.log in C:\ProgramData\Dell\Dell Data Protection shows the error below:

2019.12.10 14:16:34.015 [04596] (00022) E Bde: volume C: unable to enable key protectors - PolicyStartupTpmRequired

Trying to manually resume BitLocker fails:

BitLocker Drive Encryption error
Figure 4: (English Only) BitLocker Drive Encryption error

 

Causa

Not Applicable

Resolución

To address this issue, it is necessary to manually change the policy settings for BitLocker on the endpoints experiencing the issue.

To resolve:

  1. Right-click the Windows Start Menu and then select Run.

Click Run
Figure 5: (English Only) Click Run

  1. In the Run menu, type control panel and then click OK.

Run Control Panel
Figure 6: (English Only) Run Control Panel

  1. In the Control Panel, click BitLocker Drive Encryption.

BitLocker Drive Encryption
Figure 7: (English Only) BitLocker Drive Encryption

  1. Click Change how Drive is Unlocked at startup.

BitLocker Suspended
Figure 8: (English Only) BitLocker Suspended

  1. In the Wizard, select Let BitLocker automatically unlock my drive.

BitLocker Drive Encryption
Figure 9: (English Only) BitLocker Drive Encryption

  1. Click Resume protection.

BitLocker Drive Encryption
Figure 10: (English Only) BitLocker Drive Encryption

The disk will show as Protected again, after performing these steps:

Encryption Status
Figure 11: (English Only) Encryption Status

It is possible to perform the same steps using the administration command line below:

manage-bde -protectors -add c: -TPM
manage-bde -protectors -enable c:

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Productos afectados

Dell Encryption
Propiedades del artículo
Número del artículo: 000129595
Tipo de artículo: Solution
Última modificación: 16 ene 2024
Versión:  10
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.