BitLocker not suspended when automatically rebooting after installing windows feature update

Oleg Melnychuk 26 Reputation points
2020-08-19T09:27:53.003+00:00

I have Windows 10 Enterprise machines which joined to Azure AD and managed by Intune, which has configured Bitlocker encryption TPM+preboot PIN. When feature updates are installed on the machine and an automatic reboot is initiated, the reboot get's stuck on the Bitlocker password prompt. And installing Feature Update is failing all the time. I can install feature update when I suspend BitLocker manually. But for is not ok for me(( I have a lot of PC's with BitLocker and preboot PIN.

Also, I have an onprem machines which joined to AD and managed by SCCM and I found the solution in client settings in Configuration Manager

Suspend BitLocker PIN entry on restart

If computers require BitLocker PIN entry, then this option bypasses the requirement to enter a PIN when the computer restarts after a software installation.

Always: Configuration Manager temporarily suspends BitLocker after it has installed software that requires a restart, and it restarts the computer. This setting only applies when Configuration Manager restarts the computer. This setting doesn't suspend the requirement to enter the BitLocker PIN when the user restarts the computer. The BitLocker PIN entry requirement resumes after Windows startup.)

According to BitLocker Upgrading FAQ

No user action is required for BitLocker in order to apply updates from Microsoft, including Windows quality updates and feature updates. Users need to suspend BitLocker for Non-Microsoft software updates, such as:

Computer manufacturer firmware updates
TPM firmware updates
Non-Microsoft application updates that modify boot components

Is there a setting I can apply that makes sure the reboot doesn't get stuck at the Bitlocker screen when it's rebooting after an installing Feature Updates?

Thanks!

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,788 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,779 questions
0 comments No comments
{count} votes

Accepted answer
  1. MTG Marinetechnik 356 Reputation points
    2020-08-19T12:09:42.37+00:00

    With defaults, it would work. You are not at defaults. Possibly you are not aware that some (other) admin set this: Setup.exe /BitLocker ForceKeepActive
    If win10 feature upgrade setup is started like this, then if suspend does not work, it fails the upgrade - and with Preboot PIN set, it cannot work,


2 additional answers

Sort by: Most helpful
  1. Bagitman 581 Reputation points
    2020-08-19T17:28:45.407+00:00

    You receive feature updates via online update as any normal home computer would? So you do direct updating from the internet?
    I cannot give a suggestion yet, since I need to know that in detail, first.

    We updated hundreds of win10 installations and bitlocker with PIN is used anywhere - no problems, it suspends automatically.


  2. 2020-08-20T07:13:08.303+00:00

    Just to check if the above reply could be of help, if yes, you may mark useful reply as answer, if not, welcome to feedback.

    Best regards,
    Sylvia

    0 comments No comments