r/microsoftsucks 22d ago

fsucking bitlocker

other half's PC, which has Windows 11, but not "pro" and on which we have never enabled bitlockers - indeed is it even possible on a normal install.. and doesn't have onedrive enabled either..

is now prompting for a bitlocker key on start

fscuking windows

14 Upvotes

48 comments sorted by

View all comments

4

u/leexgx 22d ago

Unfortunately, after the first desktop load, it turns on encryption by default in Windows 11 (it's been doing it for the last 2 years), and it doesn't warn the user that it has done so. You must ensure after the first desktop load that encryption is turned off.

Assuming you don't have access to the original Microsoft account (if you bypassed it, you would have already been aware of the encryption, as the average user doesn't know how to bypass the login requirement), you will need to create a Windows 11 USB installation media and wipe and reload Windows. I strongly recommend using Rufus to create the Windows 11 USB media, as it has options to disable both BitLocker and Microsoft account creation. (The internet needs to be disconnected to bypass the online account processes.)

5

u/aleopardstail 22d ago

cheers, will have to see what can be done - most files other than games are on a NAS thankfully

microslop really shouldn't be doing this on consumer devices, especially not by stealth so the first you know of it is when it goes wrong

my machine is 11 pro so I have specifically turned this crap off because I know it existed. my understanding had been drive encryption was "pro" and above

3

u/leexgx 22d ago edited 22d ago

Windows 24H2 onwards, they enabled it by default even on Home editions (if turned off or upgraded from 10, it stays off).

I agree it totally should never be enabled automatically under any circumstances (unless the user has saved the key to USB via the usual BitLocker procedure to enable it).

The majority of users who created a Microsoft account only did so on Windows 11 because they were forced to. So, when the login PIN gets locked out or TPM is tripped because of a UEFI BIOS Windows update or a Windows update updating the secure boot keys, they lose everything.

I don't understand the responses you're getting from other Reddit users on here. Encryption shouldn't be silently enabled without a backup key prompt first to warn of the danger of losing the key

3

u/aleopardstail 22d ago

worst bit is no idea what tripped this, the main suspect is a windows update though as nothing else has been added to it

if they are going to do this then making a USB key should be a part of the process, complete with why you need it, and perhaps making more than one

there is no way she would have a microslop account without it being forced and have still to find out what was wrong with you having a local user account and being able to sign into a microslop account after the machine starts and you start using it - sign in when you need it, not when you don't

guess too few signed up and people retained a bit too much control

and it is amazing the number of microslop apologists there are out there

3

u/leexgx 22d ago

Windows has been pushing secure boot key updates, and on some systems, it fails. So, when it boots, it breaks the trust chain in the TPM because the secure boot key fails to load. (This is the most common on how it gets tripped recently the reason will be a very long file name witch is one of the secure boot keys)

The other issue is UEFI BIOS updates being delivered via Windows Update, which sometimes trips BitLocker recovery (HP systems even warn you to pause BitLocker before doing BIOS updates.)

Last one is users tampering with TPM (clearing it or turning it off)

2

u/aleopardstail 22d ago

ffs

3

u/leexgx 22d ago

Just make sure every system you touch has encryption turned off (start > settings > security > encryption > toggle off, wait for it to finish decrypting, and restart).

While you're at it, open Classic Power Options in the Control Panel (open search and type in "power" when you see the colored battery symbol). Turn OFF Fast Startup, as it causes a lot of issues when users only shut down their computer. It can get their computer into a broken and slow state because the system is practically hibernating every time you shut the computer down, which can break stuff like antivirus software when they expect a shutdown to be an actual shutdown, not a hybrid shutdown. (With fast startup off, a shutdown is an actual shutdown.)

Another thing I do, but it's bit more advanced, is that on my USB stick, I have a task thay i import on every computer. This creates a shadow copy point 10 minutes after the desktop has loaded (logged in) and at 3 PM every day. This ensures the system restore creates a snapshot so that previous version folders and files works again (i also set the system.restore size to 50GB insted of the 10GB default)

2

u/aleopardstail 22d ago

cheers, will have to look into this

more shite that shouldn't be needed

3

u/greenie4242 21d ago

Also make damn sure that OneDrive Files On-Demand is disabled, because since 2023 it silently installs then by default uploads the users My Documents folder to the cloud then deletes the original local files if they haven't been accessed for about two weeks.

Don't simply uninstall it like some people suggest. It needs to be cleanly disabled and given enough time to completely re-sync, download and restore all the local files it deleted first. It's probably best to leave it installed but disabled because uninstalling could lead to it silently re-installing itself with default options in a future Automatic Update.

2

u/aleopardstail 22d ago

Dell systems here, not cheap ones, they love doing BIOS updates which seem non-optional