BitLocker recovery is expected when the TPM protector’s PCR validation profile no longer matches the measured boot state. A new dock can contribute to that if the boot environment changes and those changes affect PCRs used by BitLocker.
The supported way to reset BitLocker’s TPM validation profile is to:
- Unlock the device with the BitLocker recovery key.
- Start Windows normally.
- Identify the current protector configuration and PCR profile from an elevated command prompt:
This shows which PCRs are currently in use.manage-bde.exe -protectors -get C: - Check why recovery was triggered by reviewing BitLocker-related events:
- Application and Services Logs > Microsoft > Windows > BitLocker-API > Management
- Windows Logs > System filtered for BitLocker sources
- Reset BitLocker protection so the TPM protector is resealed to the current trusted state by suspending and then resuming BitLocker.
Important points:
- BitLocker recovery can be triggered by changes to the boot manager, firmware, Secure Boot state, docking or undocking a portable computer, or modifying the PCRs used by the TPM validation profile.
- If PCR 7 is in use, BitLocker expects Secure Boot measurements to remain consistent. If Secure Boot is disabled or its measurements change, recovery can occur.
- If the root cause is an intended hardware or firmware-related change, resetting protection after the device is in the desired configuration prevents recovery on every startup.
- If the root cause cannot be determined, or if tampering or malware is suspected, the device should be investigated before resealing BitLocker.
If the environment is using a nondefault PCR profile, verify that configuration first. On Surface and other modern devices that support it, BitLocker commonly uses PCR 7 and PCR 11 by default when Secure Boot is correctly configured.
References: