Bitlocker enabled itself on Windows 10 Home edition without a notice and without permission

Anonymous
2022-06-29T22:51:13+00:00

After three years of owning a Dell Inspiron 13 (Windows Home) the computer somehow enabled Bitlocker on its own and encrypted my C: drive. Since I did not activate Bitlocker, I don't have the keys to decrypt the drive. My Microsoft account does not list any keys in it so there is no way to recover the keys as far as I know. Therefore none of the published solutions I have seen can work because they all assume that I have access to the keys. I see many similar complaints online (at least since 2018) and hundreds of "likes" so this appears to be a relatively common problem.

When booting, I see a message titled "BitLocker recovery" and it asks for the recovery key. It then says to "try your work or school account at: aka.ms/aadrecoverykey."

This suggests that the key may be associated with some active directory domain away from my computer. However, the admin account on this computer has, to my knowledge, never logged into an active directory domain, although non-admin users have. And, if the Amin account has connected to a Active Directory somewhere, I sure as heck did not give them a permission to encrypt my drive and lock me out of my computer, and give the key to some third party "work or school" account. If this is what happened, Microsoft, you have a serious security issue where third parties can effectively encrypt hard drives without permission using Microsoft's own tools. That is ransomware - without the ransom. But, this is still just a theory vaguely supported by this link https://hardsoft-support.kayako.com/article/99-windows-10-bitlocker-turns-on-without-a-notice

Here is a quote from the post: "Dell and Lenovo systems that ship with the Windows 10 operating system and are equipped with Trusted Platform Module (TPM) capability will have Microsoft BitLocker encryption enabled from the factory. It has been found that once the device is registered to a Active Directory domain - Office 365 Azure AD, Windows 10 automatically encrypts the system drive. You find this once you reboot your computer and are then prompted for the BitLocker key."

Since I don't know what possible organization could have encrypted the drive, and since I don't have admin access to them, the instructions in the article don't apply.

The laptop is Dell Inspiron 13 7370 - which I don't even think has a TPM chip built in it. BIOS is version 1.20.0. ePSA build is 4306.13 UEFI ROM.

So, Microsoft, how does this get fixed?

P.S. My other computers have Win10 Pro and and they have Bitlocker turned on, but this computer intentionally did not have Bitlocker turned on - and it was not supposed to be possible to turn on bitlocker on a Win10 Home edition. I am mentioning this to highlight that I did not "accidentally" trigger the Bitlocker being turned on - especially because it requires many steps and confirmations. The drive was simply encrypted one day with permission from me.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

104 answers

Sort by: Most helpful
  1. Anonymous
    2023-10-04T18:02:50+00:00

    i mean , lenovo, , does not matter , all oem install stuff,

    when you say clean install , did you use the lenovo recover softwere or get it from microsoft site, ? there is no way you have encryption on home if you got it from microsoft , using the media creation too, be more specific, thanks, i mentioned this 3 times,

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-10-04T17:59:21+00:00

    no , i am gathering information, now i have it all, , your computer has 3rd party software to encrypt windows home, so you would need to format the drive and reinstall windows clean, its free to download into usb from microsoft site, , fyi, when I.T people like my self and banks and business, buy from Dell and HP, the 1st thing they do is wipe it and put fresh windows, because of all the bloadware dell and hp installs, \

    so all the information you need is in my messangs, create your windows 11 usb media here Download Windows 11 (microsoft.com)

    , If you install windows 11 home fresh , there will be no encryption, it does not come in home version at all,

    dell did it , you can contact Dell to see options regarding it , but myself i would wipe it. you dont need encryption for home, also it slows down your computer, and if your computer dies you cant get the data off the drive if you need to ,unless you have the key

    Was this answer helpful?

    0 comments No comments
  3. Neil D 34,285 Reputation points Volunteer Moderator
    2023-10-04T17:13:31+00:00

    I think we are going round in circles.

    I don't want to remove the encryption, but I'll have a look at right clicking on the drive in Disk Management anyway and let you know.

    It is a lenovo laptop preinstalled with Windows 11 but I did a clean install last week and device encryption started automatically.

    I am only making the point that Home edition of Windows 11 does initiate the process and appears to use BitLocker, or at least that is how it's labelled.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-10-04T16:41:29+00:00

    is this the factory image from dell or hp, if so then they used 3rd party software to get the drive, in this link im sending , is ways to try to turn it off by right clicking the drive in disk manage ment and menu should have option to unlock, but you need the key , wich would be in your microsoft account also, if you format install windwos 11 home and download windows 11 from microsoft site, there will be no encryption, as home does not support it without 3rd party software, how to enable and disable bitlocker on windows 10 home= [Solved] How to enable BitLocker on Windows 11/10 Home? (iboysoft.com)

    Was this answer helpful?

    0 comments No comments
  5. Neil D 34,285 Reputation points Volunteer Moderator
    2023-10-04T16:21:57+00:00

    A few screenshots:

    As you can see there is no option to disable BitLocker in Home. I used the Media Creation tool to create the USB boot media. I noticed that encryption started as soon as the installation was completed and I had the chance to go and check. I didn't feel inclined to try an stop it.

    TPM 2.0 is a requirement for Windows 11 as is Secure boot.

    Was this answer helpful?

    0 comments No comments