question

aRookie088 avatar image
0 Votes"
aRookie088 asked Miles-MSFT answered

BitLocker questions

I have got a couple of questions about BitLocker.

  1. If I were to misplace the BitLocker Recovery Key, and I want to delete everything in the C: and reinstall Windows? Is that possible? I have read that we could change the boot order to boot from a USB and then reimage Windows. But isn't changing the boot order will trigger the BitLocker Recovery?

  2. Can it boot to the PXE environment and not trigger BitLocker Recovery?

  3. An SSD has BitLocker encryption on it and, I misplaced the Recovery Key. I take the SSD out of the laptop and DBAN it and, install Windows on it. I put the SSD back to the same machine it's Bitlocker-ed with, will this boot up normally? Or, the TPM will request for Recovery Key? Is there a way to reset the TPM?

  4. Have BitLocker policy pushed via Intune, now for some reason, we need this policy removed. What is the best way to go about, removing the policy from the workstations and ensuring that it is no longer encrypted? Do I remove the workstation from the BitLocker policy group that I created? If so, will this reset the policy that Intune has set on the workstations and, the OS drive will be unencrypted?

Any insights or help on this would be much appreciated. Thank you in advance.

windows-10-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Miles-MSFT avatar image
1 Vote"
Miles-MSFT answered Miles-MSFT commented

Hi
1. A) It is possible that you delete the bitlocker encrypted drive to clean install windows 10 on ,because there is no need to do anything special since the drive gets wiped. We could refer to this web to clean install windows 10 https://www.tenforums.com/tutorials/1950-clean-install-windows-10-a.html .
B) Changing boot order is triggering bitlocker asking the recovery key at reboot which is by design. Changing the boot order will prompt for the recovery key if bitlocker is not suspended. Here is a link we could review. https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-recovery-guide-plan
2. When we boot to PXE environment , we will always trigger bitlocker recovery. Only when we boot with no Ethernet cable , bitlocker recovery does not trigger at all. The abortpxe.com is somehow "untrusted" by the bitlocker boot process. If UEFI changes the boot order to PXE boot, bitlocker Recovery comes along. Here is a similar case we could refer to https://configurationmanager.uservoice.com/forums/300492-ideas/suggestions/38526007-fix-bitlocker-recovery-if-pxe-boot-is-in-the-firhttps://techcommunity.microsoft.com/t5/configuration-manager/bitlocker-recovery-with-pxe/m-p/224704
3. According to your preconditions , this process will boot up normally.
About resetting the TPM ,we could follow this link to reset TPM https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/manage-tpm-lockout#:~:text=1%20Open%20the%20TPM%20MMC%20%28tpm.msc%29.%202%20In,click%20I%20have%20the%20owner%20password%20file%2C%20.
4. On the BitLockered device, type Control Panel , click System and Security , and then click BitLocker Drive Encryption . Click the Turn off BitLocker .
We could follow the steps to sync our devices to get the latest settings from Intune. https://docs.microsoft.com/en-us/mem/intune/user-help/sync-your-device-manually-windows

In order to make post easy to read, one case usually talking about one question, it is our basic policy, please understanding

Best regards

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you, Miles,
I'm still a bit confused about question 1. That link suggests installing Windows via a USB. As you suggested, changing the boot order in a BitLocker encrypted device will trigger a Recovery Key. So I"m not sure how we can reinstall Windows using the USB or PXE boot. Any other suggestions?

Also sorry about all the questions together, was thinking that it was all related to BitLocker. Thank you for answering them anyway.

0 Votes 0 ·

Hi ThomasHus
It's my pleasure to answer your questions.

To reinstall windows using the USB or PXE boot we could refer to these two links

1.Install Windows from a USB Flash Drive
https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/install-windows-from-a-usb-flash-drive#:~:text=What%20you%20need%201%20Format%20the%20drive%20and,FAT32%2C%20which%20has%20a%204GB%20filesize%20limit.%20

2.Deploy Windows 10 using PXE and Configuration Manager
https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-cm/deploy-windows-10-using-pxe-and-configuration-manager

0 Votes 0 ·
Miles-MSFT avatar image
0 Votes"
Miles-MSFT answered

Hi
--please don't forget to Accept as answer if the reply is helpful--

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.