Bitlocker encryption on USB only works after volume removal

Detal John 1 Reputation point
2020-12-04T11:39:29.713+00:00

Hello,

When connecting new USB sticks to a laptop, our users cannot encrypt using Bitlocker. They get the error: the drive cannot be encrypted because it contains system boot information. Create a separate partition...

This issue persists after changing from FAT32 to NTFS, quick format, full format... It's happening for all USB sticks, not one specific type.

When deleting the volume and creating a new volume in diskmgmt.msc, encryption is possible without issue. However it's not possible as administrator to do this for every USB for all users in the company. What could be causing this and how could this be resolved?

Thanks in advance.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
0 comments No comments
{count} votes

18 answers

Sort by: Most helpful
  1. Roland MacKenzie 1 Reputation point
    2021-03-10T01:18:16.33+00:00

    We have found this to be an issue with ADATA UV150 USB3.2 flash drives.
    They ship with the "bootable" flag marked on the partition. (And I'm sure many other brands are doing the same)
    Our workaround is to using a Linux machine's fdisk to toggle the flag off ("a", "w"); as our users have no privileges to do this.
    It takes about 3 seconds.

    Why can windows not have a GPO policy/override specific for this use case (removable device with bootable flag on partition)?
    Or possibly a warning that the only partition is marked as bootable (and leave it to the user to decide rather than force disabled?)

    0 comments No comments

  2. Cuong Ha 1 Reputation point
    2021-05-26T08:11:24.71+00:00

    Gents,
    Up to today 26th May 2021, is there any available workable solution for this bugs?

    Regards,


  3. Alex 0 Reputation points
    2023-08-21T09:30:50.9766667+00:00

    Got this Error 0x80310012 but the drive is already encrypted !!! with Encryption Method: AES 128 with Diffuser, BitLocker Version: 2.0 and don't have access to it now. Lost alot of important information. The most in fact!
    No Recovery key. Intentionally deleted before.
    BitLocker Drive Encryption: Configuration Tool version 10.0.19041
    User's image

    Good job MS....

    0 comments No comments