Bit Locker Recovery Key Requested at Boot Time

Anonymous
2013-11-05T08:14:46+00:00

Hi,

At the weekend our two Surface 2 devices got a firmware update installed. My Surface 2 updated and rebooted fine with no issues.

But my wife's Surface 2 (64GB model) asked for the Bitlocker Recovery key at boot after the update, and now every time it reboots. Although I have the key this is very poor end user experience.

Especially as I am trying to sell her the Surface 2 over an iPad.

Any assistance in this would be most welcome.

Kind Regards,

Andrew

Surface | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-01-06T19:58:11+00:00

Hi,

Microsoft released an update for this today, for Surface 2 devices, as reflected in KB article 2921482.  Please check for Windows updates and install the latest updates.

Here's how to check for updates manually:

Step 1: Swipe in from the right edge of the screen, and then tap Settings.   (If you're using a mouse, point to the lower-right corner of the screen, move the mouse pointer up, and then click Settings.)

Step 2: Tap or click Change PC settings, tap or click Update and recovery, and then tap or click Windows Update

Step 3: Tap or click Check now

Step 4: If there are updates available, tap or click View details

Step 5: Tap or click to select the ones you want to install, and then tap or click Install.  You may need to restart Surface after the updates have been installed. 

Thanks!

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

115 additional answers

Sort by: Most helpful
  1. Anonymous
    2013-11-19T13:05:43+00:00

    It generates a fresh copy og Windows RT 8.1. I already tried that after my first BitLock error, and after a few days the BitLock problem reoccured. but I will give it another try. I will make a few reboots and see what happens. If the BitLock problem doesn't pop up, I will then force an update, followed by a reboot.

    But if this is supposed to solve it, why does Microsoft not puts it as a suggestion in this thread?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-11-19T12:28:24+00:00

    Those are the same errors I see in my event log as well. I tried the online support chat with MS last night and they suggested the following: http://windows.microsoft.com/en-us/windows/answers?tId=4075b6e6-0cad-4914-a8ce-67555a2cf1bd I was a bit uncertain since my case seems to be only after a firmware update and this article describes entering the recovery key every reboot. But I tried it just to see. It seems to rollback to the original Surface 2 Windows 8.1 as best as I can tell. I didn't get any bitlocker prompt after the recovery operation which was a good sign. Then last night it looks like it reapplied the 11/12 firmware update (I guess because it rolled that back during the recovery) so I had a prompt to reboot to apply updates. After the reboot I did not get a bitlocker recovery which I take as a very good sign. I guess the final test will be seeing what happens the next time they push out a firmware update, but at least i'm more hopeful it may be fixed for me. Hopefully this will help others with problems.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-11-19T11:23:10+00:00

    Yesterday my Surface 2 became very slow and stopped to respond. I could not restart it in the normal way, and forced a stop by holding the power button down for some time. When I started up, it asked once more for the BitLocker key. The code was accepted, but it had to go through a few restart attempts, including once more a forced stop by me, before the process completed. This restart problem can be explained by my forced stop, so I will not complaint about that one, but the reoccurrence of the BitLock problem cannot be explained by it.

    I checked the Event Log (good idea, I hadn’t given it a thought on my RT machine), end the same error with Event ID 842 is recorded at the same time as the BitLock issue. Also around the same time as the previous BitLock problem the log has the event recorded.

    There is also a warning in the log just before 842 (sorry for the Danish text, my Surface 2 is installed as a Danish Windows):

    Lognavn:       Microsoft-Windows-BitLocker/BitLocker Management

    Kilde:         Microsoft-Windows-BitLocker-API

    Dato:          18-11-2013 23:03:15

    Hændelses-id:  843

    Opgavekategori:Ingen

    Niveau:        Advarsel

    Nøgleord:     

    Bruger:        SYSTEM

    Computer:      Karel

    Beskrivelse:

    BitLocker was suspended from within the Windows Recovery Environment.

    Suspend time: ‎2013‎-‎11‎-‎18T23:00:32.974Z

    Hændelses-Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Microsoft-Windows-BitLocker-API" Guid="{5D674230-CA9F-11DA-A94D-0800200C9A66}" />

    <EventID>843</EventID>

    <Version>0</Version>

    <Level>3</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x4000000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-18T22:03:15.793454800Z" />

    <EventRecordID>27</EventRecordID>

    <Correlation />

    <Execution ProcessID="1212" ThreadID="1300" />

    <Channel>Microsoft-Windows-BitLocker/BitLocker Management</Channel>    <Computer>Karel</Computer>

    <Security UserID="S-1-5-18" />

    </System>

    <EventData>

    <Data Name="IdentificationGUID">{862626AA-6AA6-41D5-BED5-447F7E3FAB0C}</Data>

    <Data Name="ResealTime">2013-11-18T23:00:32.974Z</Data>

    </EventData>

    </Event>

    There are also older warnings that are not followed by an error:

    Lognavn:       Microsoft-Windows-BitLocker/BitLocker Management

    Kilde:         Microsoft-Windows-BitLocker-API

    Dato:          16-11-2013 14:34:08

    Hændelses-id:  841

    Opgavekategori:Ingen

    Niveau:        Advarsel

    Nøgleord:     

    Bruger:        SYSTEM

    Computer:      Karel

    Beskrivelse:

    BitLocker was unable to update a key for volume C: due to the following error: Du skal initialisere TPM, inden du kan bruge BitLocker-drevkryptering.

    Hændelses-Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Microsoft-Windows-BitLocker-API" Guid="{5D674230-CA9F-11DA-A94D-0800200C9A66}" />

    <EventID>841</EventID>

    <Version>0</Version>

    <Level>3</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x4000000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-16T13:34:08.502560500Z" />

    <EventRecordID>17</EventRecordID>

    <Correlation />

    <Execution ProcessID="864" ThreadID="1928" />

    <Channel>Microsoft-Windows-BitLocker/BitLocker Management</Channel>

    <Computer>Karel</Computer>

    <Security UserID="S-1-5-18" />

    </System>

    <EventData>

    <Data Name="IdentificationGUID">{862626AA-6AA6-41D5-BED5-447F7E3FAB0C}</Data>

    <Data Name="VolumeName">\?\Volume{349c1601-80d5-47fa-8710-91613f4a354d}</Data>

    <Data Name="VolumeMountPoint">C:</Data>

    <Data Name="ErrorCode">-2144272360</Data>

    </EventData>

    </Event>

    Lognavn:       Microsoft-Windows-BitLocker/BitLocker Management

    Kilde:         Microsoft-Windows-BitLocker-API

    Dato:          12-11-2013 11:34:22

    Hændelses-id:  793

    Opgavekategori:Ingen

    Niveau:        Advarsel

    Nøgleord:     

    Bruger:        SYSTEM

    Computer:      Karel

    Beskrivelse:

    BitLocker resealed boot settings to the TPM for volume C:.

    Hændelses-Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Microsoft-Windows-BitLocker-API" Guid="{5D674230-CA9F-11DA-A94D-0800200C9A66}" />

    <EventID>793</EventID>

    <Version>0</Version>

    <Level>3</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x4000000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-12T10:34:22.189680300Z" />

    <EventRecordID>15</EventRecordID>

    <Correlation />

    <Execution ProcessID="4856" ThreadID="5260" />

    <Channel>Microsoft-Windows-BitLocker/BitLocker Management</Channel>

    <Computer>Karel</Computer>

    <Security UserID="S-1-5-18" />

    </System>

    <EventData>

    <Data Name="IdentificationGUID">{862626AA-6AA6-41D5-BED5-447F7E3FAB0C}</Data>

    <Data Name="VolumeName">\?\Volume{349c1601-80d5-47fa-8710-91613f4a354d}</Data>

    <Data Name="VolumeMountPoint">C:</Data>

    </EventData>

    </Event>

    Around the time of the recent BitLock problem, the Surface 2 was not engaged in an update process. The earliest update that took place earlier was an update of Defender.

    I am getting worried now. When I look in Charm/settings/restart&update/history, update history is disabled, and it says that I can only enable it when I connect a drive. However, when I search for a drive, none is found. History has though worked earlier!

    Yesterday I used Word on the Surface 2 for some serious business; a breakdown would have given me problems. Due to good fortune, the Surface 2 did not crash, but I will use another machine next time.

    The Tech media should be informed.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-11-18T22:31:08+00:00

    I noticed the following error in event viewer that correspond to the times I was forced to enter the recovery key. Do others see this as well?

    Log Name:      Microsoft-Windows-BitLocker/BitLocker Management

    Source:        Microsoft-Windows-BitLocker-API

    Date:          11/12/2013 8:09:13 PM

    Event ID:      842

    Task Category: None

    Level:         Error

    Keywords:     

    User:          SYSTEM

    Computer:      james-surface

    Description:

    BitLocker was unable to reseal boot settings to the TPM in the Windows Recovery Environment.

    Error: You must initialize the Trusted Platform Module (TPM) before you can use BitLocker Drive Encryption.

    Protection has been temporarily suspended.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Microsoft-Windows-BitLocker-API" Guid="{5D674230-CA9F-11DA-A94D-0800200C9A66}" />

        <EventID>842</EventID>

        <Version>0</Version>

        <Level>2</Level>

        <Task>0</Task>

        <Opcode>0</Opcode>

        <Keywords>0x4000000000000000</Keywords>

        <TimeCreated SystemTime="2013-11-13T01:09:13.985939600Z" />

        <EventRecordID>28</EventRecordID>

        <Correlation />

        <Execution ProcessID="908" ThreadID="1448" />

        <Channel>Microsoft-Windows-BitLocker/BitLocker Management</Channel>

        <Computer>james-surface</Computer>

        <Security UserID="S-1-5-18" />

      </System>

      <EventData>

        <Data Name="ErrorCode">-2144272360</Data>

      </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments