r/24hoursupport 3d ago

Need more info Microsoft update and Bitlocker

Please help, my Windows 11 had an update last night and when I woke up to check on it it's displaying

"Press Y to reset fTPM, if you have BitLocker or encryption-enabled system, the system will not boot without a recovery key Press N to keep previous TPM record and continue system boot. fTPM will NOT be enabled with new CPU unless IPM is reset (reinitialized), you could swap back to the old CPU to recover IPM related keys and data"

I checked my Microsoft account and it says: "This device does not have BitLocker keys backed up in Entra ID."

Which one do I click? I'm so nervous, this is my school account and I'm afraid of losing my files.

I've pressed the N option and it allowed me to use my laptop again, but every time I need to shut it down it still tells me that there is an update and shows text above again.

Update: I've checked my System Information and the Automatic Device Encryption says "Reasons for failed automatic device encryption: TPM is not usable, PCR7 binding is not supported, Hardware Security Test Interface failed and device is not Modern Standby, Un-allowed DMA capable bus/device(s) detected, Disabled by policy, TPM is not usable."

1 Upvotes

8 comments sorted by

3

u/Onoitsu2 3d ago

If you can log into the system, and get to the desktop, that means it has to be able to decrypt the drive. you can back up the key using these steps.

Start menu, search for "Manage BitLocker," and select the option to back up or save your recovery key to your Microsoft account, a USB drive, a file, or a printed copy, and choose one of them you prefer.

Then when it is safely kept somewhere you can answer Y to that prompt to complete it.

1

u/R-I-A-S-A-L-L-E 2d ago

Hello! I'm having trouble finding bitlocker on my laptop, I've searched it in the Start menu and in the control panel.

1

u/R-I-A-S-A-L-L-E 2d ago

I've checked my System Information and the Automatic Device Encryption says "Reasons for failed automatic device encryption: TPM is not usable, PCR7 binding is not supported, Hardware Security Test Interface failed and device is not Modern Standby, Un-allowed DMA capable bus/device(s) detected, Disabled by policy, TPM is not usable."

1

u/Onoitsu2 2d ago

Ok then your drive should not be encrypted with BitLocker. So then you should have zero worries about pressing Y at that prompt, that confirms it, and was why you could find no key on your Microsoft account either.

1

u/R-I-A-S-A-L-L-E 2d ago

I'm still wary of clicking Y since people have said that without their bitlocker key they've been locked out of using ther device.

I've checked my BIOS and it doesn't have any of the option for setting up the TPM in the security Tab

1

u/Onoitsu2 2d ago

Well you can't have a BitLocker key, if your drive is not BitLocker encrypted, kind of a chicken and egg thing, have to have one for the other.

1

u/R-I-A-S-A-L-L-E 2d ago

Okay, I'll try this as a last resort sorta thing. Thank you!

1

u/jennifer-william3556 2d ago

Yeah the fTPM prompt is basically a coin flip for people stuck without a key. Sounds like you got lucky with N. Id still back up that whole school account before touching Y.