How to Use BitLocker with PIN
摘要: Steps to set up a PIN with BitLocker.
本文章適用於
本文章不適用於
本文無關於任何特定產品。
本文未識別所有產品版本。
說明
- Boot into BIOS (Setup menu) and confirm that the system is in UEFI mode - TPM is activated.
- Under Post Behavior, confirm that Fastboot mode is set to Thorough.
- Boot into the operating system. Set up BitLocker on the wanted drive and reboot to begin the encryption.
- This will not allow for a PIN - You must set BitLocker on this system prior to changing the group policy to create the PIN.
- Upon Reboot, open up gpedit.msc. This brings up your group policy options.
- Go to Computer Configuration; Administrative Templates; Windows Components; BitLocker Drive Encryption; Operating System Drives.
- In the right pane - double-click
Require additional authentication at startup
and a box opens.- Ensure that the
Enabled
option is chosen so that all the other options are active. - Clear the box for
Allow BitLocker without a compatible TPM
. - For the choice of
Configure TPM startup
, chooseAllow TPM
. - For the choice of
Configure TPM startup PIN:
, chooseRequire startup PIN with TPM
. - For the choice of
Configure TPM startup key:
, chooseAllow startup key with TPM
. - For the choice of
Configure TPM startup key and PIN:
, chooseAllow startup key and PIN with TPM
. - Click the
Apply
button and then theOK
button to save the changes in the Local Group Policy Editor.
- Ensure that the
- In the right pane - double-click
- Go to Computer Configuration; Administrative Templates; Windows Components; BitLocker Drive Encryption; Operating System Drives.
- Stay under the BitLocker Drive Encryption > Operating System Drives.
- In the right pane - double-click
Enable use of BitLocker Authentication requiring preboot keyboard input on slates
.- Ensure that the
Enabled
option is chosen to activate. - Click the
Apply
button and then theOK
button to save the changes in the Local Group Policy Editor.
- Ensure that the
- In the right pane - double-click
- Reboot the system once more.
- Launch an Admin Command Prompt (Elevated Command Prompt).
- Excluding the quotation marks, enter the command:
manage-bde -protectors -add c: -TPMAndPIN - You are prompted to enter the PIN. Enter a number between four and seven digits. The cursor will not register the keystrokes as you enter the number.
- Press the Enter key to save the PIN, and you are prompted to enter the PIN again to confirm. Press the Enter key again to save the PIN confirmation - It runs through the commands showing it as saved.
- Excluding the quotation marks, enter the command:
- Reboot the system once more, and it prompts for a PIN with the Slate Keyboard.
BitLocker will prompt for PIN on each reboot after this is completed.
文章屬性
文章編號: 000142382
文章類型: How To
上次修改時間: 16 1月 2026
版本: 7
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。