How to Use BitLocker with PIN
摘要: Steps to set up a PIN with BitLocker.
本文适用于
本文不适用于
本文并非针对某种特定的产品。
本文并非包含所有产品版本。
说明
- Boot into BIOS (Setup menu) and confirm that the system is in UEFI mode - TPM is activated.
- Under Post Behavior, confirm that Fastboot mode is set to Thorough.
- Boot into the operating system. Set up BitLocker on the wanted drive and reboot to begin the encryption.
- This will not allow for a PIN - You must set BitLocker on this system prior to changing the group policy to create the PIN.
- Upon Reboot, open up gpedit.msc. This brings up your group policy options.
- Go to Computer Configuration; Administrative Templates; Windows Components; BitLocker Drive Encryption; Operating System Drives.
- In the right pane - double-click
Require additional authentication at startup
and a box opens.- Ensure that the
Enabled
option is chosen so that all the other options are active. - Clear the box for
Allow BitLocker without a compatible TPM
. - For the choice of
Configure TPM startup
, chooseAllow TPM
. - For the choice of
Configure TPM startup PIN:
, chooseRequire startup PIN with TPM
. - For the choice of
Configure TPM startup key:
, chooseAllow startup key with TPM
. - For the choice of
Configure TPM startup key and PIN:
, chooseAllow startup key and PIN with TPM
. - Click the
Apply
button and then theOK
button to save the changes in the Local Group Policy Editor.
- Ensure that the
- In the right pane - double-click
- Go to Computer Configuration; Administrative Templates; Windows Components; BitLocker Drive Encryption; Operating System Drives.
- Stay under the BitLocker Drive Encryption > Operating System Drives.
- In the right pane - double-click
Enable use of BitLocker Authentication requiring preboot keyboard input on slates
.- Ensure that the
Enabled
option is chosen to activate. - Click the
Apply
button and then theOK
button to save the changes in the Local Group Policy Editor.
- Ensure that the
- In the right pane - double-click
- Reboot the system once more.
- Launch an Admin Command Prompt (Elevated Command Prompt).
- Excluding the quotation marks, enter the command:
manage-bde -protectors -add c: -TPMAndPIN - You are prompted to enter the PIN. Enter a number between four and seven digits. The cursor will not register the keystrokes as you enter the number.
- Press the Enter key to save the PIN, and you are prompted to enter the PIN again to confirm. Press the Enter key again to save the PIN confirmation - It runs through the commands showing it as saved.
- Excluding the quotation marks, enter the command:
- Reboot the system once more, and it prompts for a PIN with the Slate Keyboard.
BitLocker will prompt for PIN on each reboot after this is completed.
For related information, see article: Using the Group Policy Editor to Enable BitLocker Authentication in the Pre-Boot Environment for Windows 7 / 8 / 8.1 / 10
文章属性
文章编号: 000142382
文章类型: How To
上次修改时间: 14 8月 2025
版本: 6
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。