Bitlocker encryption on USB only works after volume removal

Detal John 1 Reputation point
2020-12-04T11:39:29.713+00:00

Hello,

When connecting new USB sticks to a laptop, our users cannot encrypt using Bitlocker. They get the error: the drive cannot be encrypted because it contains system boot information. Create a separate partition...

This issue persists after changing from FAT32 to NTFS, quick format, full format... It's happening for all USB sticks, not one specific type.

When deleting the volume and creating a new volume in diskmgmt.msc, encryption is possible without issue. However it's not possible as administrator to do this for every USB for all users in the company. What could be causing this and how could this be resolved?

Thanks in advance.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
0 comments No comments
{count} votes

18 answers

Sort by: Most helpful
  1. StephanieQ 6 Reputation points
    2021-01-25T20:25:27.713+00:00

    We are suddenly experiencing this same issue and have not year found a resolution. I'm very interested if anyone has gotten any answers.
    I've checked our environment and cannot see that the MS Update listed above is installed. We are on 1909, and fortunately don't have a significant amount of USB/External Media usage, but enough that this is a serious issue. Using DISKPART on all USB drives is definitely not a solution.

    0 comments No comments

  2. Steen-C 1 Reputation point
    2021-02-03T17:02:27.587+00:00

    After raising this with Microsoft Premier Support I was provided with the below statement:

    “Windows Engineering has advised that this is a new behaviour which is added to overcome a known issue where SYSTEM partitions on mirrored disks in Storage Spaces were inadvertently encrypted leading to unbootable systems upon activation during disaster recovery. We are working on updating the documentation for 10B CUs to reflect this change. If customers find the new out of the box USB Sticks affected with this issue they must manually set the partitions as INACTIVE as manufacturers shouldn't be shipping drives with partition marked ACTIVE.”

    I was advised that they have a number of tickets, but at the moment it has not been decided whether they are going to reverse the change or keep it in place.

    0 comments No comments

  3. M m 1 Reputation point
    2021-02-28T21:10:12.967+00:00

    Any update?
    We cant use new pendrive in our company. Users dont have priviledges or knowledge to apply diskpart workarround.

    Regards.

    0 comments No comments

  4. JJones 6 Reputation points
    2021-03-02T11:40:53.873+00:00

    We are also experiencing this problem after upgrading from 1803 to 1909. The diskpart workaround is not a solution for us as like many of the responses the users do not have admin rights and therefore cannot run this.
    Our business requires the use of a large amount of encrypted USB sticks, so this is a major problem for us currently.
    Has there been any update from Microsoft?

    0 comments No comments

  5. Carlos Zuo 1 Reputation point
    2021-03-09T10:04:20.63+00:00

    I have the same issue to Kingston Datatraveler 100 and have to re-partition it. but it is working well for Sandisk USB

    0 comments No comments