Dell BitLocker Manager Reporting Unprotected After Changing Protector Policy

摘要: This article discusses the root cause and resolution to Dell BitLocker Manager (formerly Dell Data Protection | Dell BitLocker Manager) reporting unprotected after changing protected Dell Data Security server (formerly Dell Data Protection server) policy from Configure TPM Startup PIN to Configure TPM Startup. ...

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

症狀

Affected Products:

  • Dell BitLocker Manager
  • Dell Data Protection | BitLocker Manager

Affected Versions:

  • v10.10 and Earlier

In the Dell Data Security server console, an administrator may change the protectors that are required to unlock an endpoint protected with Dell BitLocker Manager.

Dell Data Security TPM Configuration
Figure 1: (English Only) Dell Data Security TPM Configuration

Changing Configure TPM Startup PIN to Configure TPM Startup cause:

  • After the first reboot post policies change:
    • The PIN is required to unlock the operating system disk.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and Disk C: reports Fully encrypted.

Encryption Status
Figure 2: (English Only) Encryption Status 

  • After the second reboot:
    • A PIN is no longer be required to unlock the volume.
    • In the BitLocker Drive Encryption applet of the Control Panel, BitLocker Drive Encryption shows as suspended.
    • In the Dell Data Security console, Drive 0 reports Unprotected and the Disk C: Fully encrypted.

On the Dell Data Security administration console, the endpoint reports as Unprotected:

Endpoint Details
Figure 3: (English Only) Endpoint Details

On the endpoints, the DellAgent.log in C:\ProgramData\Dell\Dell Data Protection shows the error below:

2019.12.10 14:16:34.015 [04596] (00022) E Bde: volume C: unable to enable key protectors - PolicyStartupTpmRequired

Trying to manually resume BitLocker fails:

BitLocker Drive Encryption error
Figure 4: (English Only) BitLocker Drive Encryption error

 

原因

Not Applicable

解析度

To address this issue, it is necessary to manually change the policy settings for BitLocker on the endpoints experiencing the issue.

To resolve:

  1. Right-click the Windows Start Menu and then select Run.

Click Run
Figure 5: (English Only) Click Run

  1. In the Run menu, type control panel and then click OK.

Run Control Panel
Figure 6: (English Only) Run Control Panel

  1. In the Control Panel, click BitLocker Drive Encryption.

BitLocker Drive Encryption
Figure 7: (English Only) BitLocker Drive Encryption

  1. Click Change how Drive is Unlocked at startup.

BitLocker Suspended
Figure 8: (English Only) BitLocker Suspended

  1. In the Wizard, select Let BitLocker automatically unlock my drive.

BitLocker Drive Encryption
Figure 9: (English Only) BitLocker Drive Encryption

  1. Click Resume protection.

BitLocker Drive Encryption
Figure 10: (English Only) BitLocker Drive Encryption

The disk will show as Protected again, after performing these steps:

Encryption Status
Figure 11: (English Only) Encryption Status

It is possible to perform the same steps using the administration command line below:

manage-bde -protectors -add c: -TPM
manage-bde -protectors -enable c:

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

受影響的產品

Dell Encryption
文章屬性
文章編號: 000129595
文章類型: Solution
上次修改時間: 16 1月 2024
版本:  10
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。