This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How do you make SGN take over the TPM if the TPM was disabled when Bitlocker first encrypted?

Windows 10, SGN 8, TPMs, and not previously encrypted before SGN activated Bitlocker.

Two of our sites all had the TPMs disabled when we rolled out to them so they had to set up PINs. For the moment I don't want them to have to enter PINs. I turned on a TPM and enabled it, and now Windows reports it is active.

The machine still wants a PIN at boot.

All policies for TPM Only are enabled. All of the workstations whose TPMs were enabled at initial install and encryption are working as expected.

Do I need to do something like clear it from within Windows?



This thread was automatically locked due to age.
Parents
  • Hi James,

    If the TPM is disabled, SGN can't automatically take over it. You have to ensure that the TPM is enabled. SGN merely manages BitLocker.  I would suggest you reset TPM and enable it again, but please ensure that no drive is encrypted with respect to that TPM. 

    Haridoss Sreenivasan
    Technical Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi James,

    If the TPM is disabled, SGN can't automatically take over it. You have to ensure that the TPM is enabled. SGN merely manages BitLocker.  I would suggest you reset TPM and enable it again, but please ensure that no drive is encrypted with respect to that TPM. 

    Haridoss Sreenivasan
    Technical Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data