Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Wyse Windows 10 IoT Enterprise for Wyse 7040 Thin Client Administrator’s Guide

PDF

Using TPM and BitLocker

A TPM is a microchip designed to provide basic security-related functions, primarily involving encryption keys. BitLocker Drive Encryption (BDE) is a full disk encryption feature which is designed to protect data by providing encryption for entire volumes. By default it uses the AES encryption algorithm in CBC mode with a 128 bit key, combined with the Elephant diffuser for additional disk encryption-specific security not provided by AES.

Windows 10 does not support sysprep on a BitLocker encrypted device. Because of this limitation, you cannot encrypt the device, perform a sysprep and pull the image. To overcome this issue, you must add or modify the TPM related script that handles TPM. The device must not be encrypted before sysprep (pull). The device encryption is handled by the post push script that uses the TPM_enable script located at C:\Windows\setup\tools\tpm\tpm_enable.ps1. This script must be included before enabling the UWF and after sysprep scripts. The PIN used to encrypt the client must be passed to the script as an argument.

To use TPM and BitLocker, do the following:
  1. Enable TPM from the BIOS menu.
  2. Add/modify the TPM related part of the script, based on the type of imaging.
    • Image Push— LicenseActivation.ps1.

    • WSI Push— Admin2.ps1.

    • SCCM Push— AdminConfigMgr.ps1.

    For example: During the SCCM push, the TPM related part in AdminConfigmgr.ps1 must be modified as follows:
    #uncomment the below two lines and update the pin for TPM encryption for SCCM push
                                        cd C:\windows\setup\Tools\TPM\
                                        .\TPM_enable.ps1 -pin 1234 
                                        
                                     
  • NOTE:
    If the client is encrypted previously, then do the following to clear the TPM.
    1. Enter the BIOS mode.

    2. In TPM configuration, set the Change TPM Status to Clear, and then apply the settings.

    3. Reboot the device, and enter the BIOS mode again.

    4. Set the Change TPM Status to Enable and Activate.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\