Bitlocker encryption on USB only works after volume removal

Detal John 1 Reputation point
2020-12-04T11:39:29.713+00:00

Hello,

When connecting new USB sticks to a laptop, our users cannot encrypt using Bitlocker. They get the error: the drive cannot be encrypted because it contains system boot information. Create a separate partition...

This issue persists after changing from FAT32 to NTFS, quick format, full format... It's happening for all USB sticks, not one specific type.

When deleting the volume and creating a new volume in diskmgmt.msc, encryption is possible without issue. However it's not possible as administrator to do this for every USB for all users in the company. What could be causing this and how could this be resolved?

Thanks in advance.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,755 questions
0 comments No comments
{count} votes

18 answers

Sort by: Most helpful
  1. Dale Kudusi 3,211 Reputation points
    2020-12-07T07:47:12.367+00:00

    Hi,
    You could try using use DISKPART to set the partition you wish to encrypt as INACTIVE. This will allow you to Encrypt with Bitlocker. See below screenshot that shows marking a Partition on a USB Flash Drive as INACTIVE.

    45528-picture1.png

    Also, have you tried uninstalling the October Update in 20H2, September Update and later in 1903 as suggested above by MTG-3890?

    Best regards.

    **
    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    3 people found this answer helpful.

  2. StephanieQ 6 Reputation points
    2021-03-02T12:34:10.457+00:00

    After working with Microsoft Support I was told they are reverting the change that was made in a previous update, but we should not expect it to be released until May 2021. The issue is related to KB4577062.

    1 person found this answer helpful.

  3. MTG 1,196 Reputation points
    2020-12-04T13:33:41.82+00:00

    I distribute the Bitlocker-encrypted USB sticks in our company. Recently, for the first time, I had the same problem, with 2 different sticks even. I could reproduce the problem at all times on any current windows machine (Win10 20H2).
    The solution was to use diskpart clean on these devices.

    The possible reason for this behavior: these sticks had been used as boot sticks for portable Linux before and had just been quick formatted which somehow left things behind that Bitlocker did not like at all.

    0 comments No comments

  4. Detal John 1 Reputation point
    2020-12-04T13:37:31+00:00

    In my case the USB sticks are new out of the box and have never been used as bootable USB's. Also on some older USB devices the same issue persists...
    Unfortunately, it's not possible to ask users to perform a diskpart, as they are not admin's and this is too complicated and not userfriendly.
    I manage 5000 users, so it's not possible to remediate each USB stick separately by myself...


  5. MTG 1,196 Reputation points
    2020-12-04T13:49:00.14+00:00

    As said, uninstall the november CU, then the october CU and reboot and test.

    0 comments No comments