TPM v1.2 - No recovery key needed to reboot into safe mode ?

defender2021 1 Reputation point
2021-02-19T06:26:13.793+00:00

Hi Guys,

I have a Win 10 build 17763 lenovo machine that has a tpmv1.2 chip and os drive is bitlocked.

I am able to reboot the machine into safe mode without being prompted for a recovery key, whereas a colleague of mine has a TPM v2.0 machine and he is asked for a recovery key when booting into safe mode.

So it seems this could be a TPM version issue but could someone please confirm or point me to the documentation about this?

Thanks

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,759 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Jenny Feng 14,081 Reputation points
    2021-02-19T08:32:37.72+00:00

    @defender2021
    Hi,
    I think it has something to do with whether you enable BitLocker.
    BitLocker locks the drive if you go into safe-mode. That is a normal function to protect your data.
    If you are not asked to enter a recovery key, you may not have BitLocker enabled.

    The boot order typically affects the system measurement that is verified by BitLocker and a change in boot order will cause you to be prompted for your BitLocker recovery key. For the same reason, if you have a laptop with a docking station, ensure that the hard disk drive is first in the boot order both when docked and undocked.
    For your reference:
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview-and-requirements-faq

    Hope above information can help you.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Jenny Feng 14,081 Reputation points
    2021-02-25T05:52:41.797+00:00

    Hi,
    How did you enable BitLocker? Have you stored the recovery key?
    You can refer to the following link to confirm the difference between version TPM v1.2 and TPM v2.0
    TPM and Windows Features
    https://learn.microsoft.com/en-us/windows/security/information-protection/tpm/tpm-recommendations
    TPM v1.2 does not support Device Encryption.
    Device Encryption is the consumer version of BitLocker, and it uses the same underlying technology. How it works is if a customer logs on with a Microsoft account and the system meets Modern Standby hardware requirements, BitLocker Drive Encryption is enabled automatically in Windows 10.

    Hope above information can help you.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.