Bitlocker hardware encryption cannot be activated on Win10 10586/1511

coretana

Junior Member
Nov 15, 2015
2
0
0
Hey,

I'm having trouble enabling hardware encryption with Bitlocker using Windows 10 build 10586 on a clean install with a Samsung 850 SSD. The encryption worked flawlessly before on build 10240.

I've spent hours and attempted multiple solutions and made several tests.

As mentioned, on the same machine, if clean installing build 10240 (RTM, before November update) right now, the encryption works.

I have UEFI on with Legacy/CSM off, Fast Boot on, Secure Boot on, and a clean GPT installation after using the 'diskpart clean' command.

As always, it's required to change a group policy to allow additional authentication at startup. I did that.

On a clean installation of build 10586, the wizard will say 'parameter is incorrect' when attempting to start encryption.

Microsoft did announce some Bitlocker-related changes for build 10586: https://technet.microsoft.com/en-us/library/mt403325

There are also new group policies added. I've tried all combinations. They now allow you to try and force a specific encryption cipher. Samsung uses XES-AES256. I tried forcing that (as well as all other combinations) but the same error returns.

Now, here's where it gets interesting, and possibly why no reports about this have surfaced yet:
If you enable the encryption on build 10240, and then upgrade to 10586, the encryption will remain and will work properly on build 10586.

If you then attempt to 'Reset this PC', and choose the 'keep nothing' option, it will warn you that bitlocker will be disabled. Once it's done cleaning, if you attempt to enable encryption, it will again show the error.

Even if you don't reset the PC, but simply disable Bitlocker on 10586 and then attempt to re-enable it, it will no longer work.

tl;dr: Hardware encryption via Bitlocker on build 10586 cannot be enabled on a clean install. Currently-known workaround is installing 10240, encrypting it, then upgrading to 10586.

Any solutions would be appreciated, thanks!
 

smakme7757

Golden Member
Nov 20, 2010
1,487
1
81
Don't have time to read the whole post, but i saw the thread before having to log off, so throwing a tip out there.

Try a Secure Erase of your drive.

On my EVO 840 i could only enable the hardware accelerated Bitlocker encryption on a completely fresh (secure erased) drive with a completely fresh install of Windows 8. I'd imagine it couldbe the same for Windows 10.

Use Samsungs Bootable Secure Erase program to perform the secure erase.

Anyhow hope you figure it out :)
 

coretana

Junior Member
Nov 15, 2015
2
0
0
Do you have Windows 10 Pro?

Windows 10 Enterprise.

Try a Secure Erase of your drive.

I tried that as well, luckily the drive in question is only 120GB so it only took about 15 mins. No luck though.

I'm 99.9% sure it has something to do specifically with the changes on build 10586. It still works flawlessly on 10240 by doing a 'diskpart clean' and installing 10240. Doing the same and installing 10586 - fails. Re-install 10240 - works again.

I even tried looking through the registry to see the differences between BitLocker-related keys on 10240 vs. clean 10586 vs. upgraded-and-still-encrypted-10586.