BitLocker Drive Encryption: The data drive specified is not set to automatically unlock

Greg Gilles 16 Reputation points
2021-05-14T12:32:32.28+00:00

Good morning,

We are trying to configure BitLocker across our domain, and we are running into some issues. The issues only occur on about a quarter of our machines, the rest work as intended.

The error message we receive states this: "The data drive specified is not set to automatically unlock on the current computer and cannot be unlocked automatically. C: was not encrypted."

This error message occurs only when we configure BitLocker with the "System Check." (Checking the box when it asks). We receive the error after a reboot. If we deploy it without System Check, it works, but it prompts the user every single reboot to input the recovery key.

Things we have tried:

Updating the BIOS

Looking for a "USB Host Controller" Settting in the BIOS - doesn't exist

BIOS settings for booting from USB - Already enabled

Double, triple, and quadruple checking Group Policy settings to make sure they are proper. They are - otherwise it wouldn't be working as intended on the other three quarters of our machines

So to summarize the issue:

The error message only occurs when we configure BitLocker on the local machine with System Check checkbox selected

If we configure it without the System Check, BitLocker works, and immediately encrypts the drive. However, it prompts the user every reboot to input the recovery key, which is just simply unacceptable and unrealistic

I feel like there is something we are missing here. Any suggestions would be greatly appreciated!

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,940 questions
{count} votes

6 answers

Sort by: Most helpful
  1. tt7w1qvpg2 0 Reputation points
    2024-10-03T12:35:25.5266667+00:00

    In my case, I fixed it by enabling "Legacy USB" in the BIOS settings. Without it enabled, the PC cannot detect connected USB flash drives during boot, and consequently Windows cannot access the flash drive to check whether the key protector (.BEK file on your flash drive, and to see it, you must disable "Hide protected operating system files..." setting in Windows) is present, and throws this unhelpful error.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.