Bitlocker encryption on USB only works after volume removal

Detal John 1 Reputation point
2020-12-04T11:39:29.713+00:00

Hello,

When connecting new USB sticks to a laptop, our users cannot encrypt using Bitlocker. They get the error: the drive cannot be encrypted because it contains system boot information. Create a separate partition...

This issue persists after changing from FAT32 to NTFS, quick format, full format... It's happening for all USB sticks, not one specific type.

When deleting the volume and creating a new volume in diskmgmt.msc, encryption is possible without issue. However it's not possible as administrator to do this for every USB for all users in the company. What could be causing this and how could this be resolved?

Thanks in advance.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
0 comments No comments
{count} votes

18 answers

Sort by: Most helpful
  1. John Cromer 1 Reputation point
    2020-12-22T10:20:31.747+00:00

    Uninstalling November, October, September update did not resolve the issue unfortunately.
    Diskpart is no solution. As stated before, support cannot perform this action every time one of the 5000 users wants to encrypt a USB stick. I can remediate it with diskmgmt, but this does not resolve the issue for different USB sticks, only for the one in question.

    0 comments No comments

  2. CD-SDCDA 1 Reputation point
    2021-01-07T18:59:38.527+00:00

    Any answer yet from Microsoft on patching this? The Diskpart solution does of course work, but it would be nice to have a more scalable answer to this issue. It also has to be manually done for each individual USB drive inserted into the machine. I haven't found any combination of installing/uninstalling updates to fix this issue. It's happening on both Win10 1909 and 2004 in my environment.

    0 comments No comments

  3. Lennard Kjartan Christensen 1 Reputation point
    2021-01-12T09:00:12.827+00:00

    We are experiencing the same problem. If a computer has been inplace upgraded from Windows 1809 -> Windows 1909 we get the error: "The drive cannot be encrypted because it contains system boot information. Create a separate partition..." when we try use bitlocker on a new usb stick. After diskpart clean, we are able to use bitlocker on the usb stick.

    If we do a clean install with Windows 1909 on the same computer - we do not get the error when we try to use bitlocker on new usb stick.

    Anyone found at way to fix this issue without diskpart clean or do a clean install of Windows 1909?

    Update: When we inplace to Windows 10 20H2 - the issue is gone :-)


  4. Thomas Hansen 1 Reputation point
    2021-01-12T12:28:08.213+00:00

    Any updates on this issue. We are experiencing this as well?

    It would seem that this is the update that does it:
    https://support.microsoft.com/en-in/help/4577069/windows-10-update-kb4577069
    55782-image.png

    So removing the active setting on the partition works. But that's not a solution as non admin users dont have access to that.

    It would seem that all our new Kingston USB Sticks have an active partition from the factory.

    0 comments No comments

  5. Detal John 1 Reputation point
    2021-01-22T11:40:55.76+00:00

    The issue is still not resolved unfortunately.