Bitlocker enabled itself on Windows 10 Home edition without a notice and without permission

Anonymous
2022-06-29T22:51:13+00:00

After three years of owning a Dell Inspiron 13 (Windows Home) the computer somehow enabled Bitlocker on its own and encrypted my C: drive. Since I did not activate Bitlocker, I don't have the keys to decrypt the drive. My Microsoft account does not list any keys in it so there is no way to recover the keys as far as I know. Therefore none of the published solutions I have seen can work because they all assume that I have access to the keys. I see many similar complaints online (at least since 2018) and hundreds of "likes" so this appears to be a relatively common problem.

When booting, I see a message titled "BitLocker recovery" and it asks for the recovery key. It then says to "try your work or school account at: aka.ms/aadrecoverykey."

This suggests that the key may be associated with some active directory domain away from my computer. However, the admin account on this computer has, to my knowledge, never logged into an active directory domain, although non-admin users have. And, if the Amin account has connected to a Active Directory somewhere, I sure as heck did not give them a permission to encrypt my drive and lock me out of my computer, and give the key to some third party "work or school" account. If this is what happened, Microsoft, you have a serious security issue where third parties can effectively encrypt hard drives without permission using Microsoft's own tools. That is ransomware - without the ransom. But, this is still just a theory vaguely supported by this link https://hardsoft-support.kayako.com/article/99-windows-10-bitlocker-turns-on-without-a-notice

Here is a quote from the post: "Dell and Lenovo systems that ship with the Windows 10 operating system and are equipped with Trusted Platform Module (TPM) capability will have Microsoft BitLocker encryption enabled from the factory. It has been found that once the device is registered to a Active Directory domain - Office 365 Azure AD, Windows 10 automatically encrypts the system drive. You find this once you reboot your computer and are then prompted for the BitLocker key."

Since I don't know what possible organization could have encrypted the drive, and since I don't have admin access to them, the instructions in the article don't apply.

The laptop is Dell Inspiron 13 7370 - which I don't even think has a TPM chip built in it. BIOS is version 1.20.0. ePSA build is 4306.13 UEFI ROM.

So, Microsoft, how does this get fixed?

P.S. My other computers have Win10 Pro and and they have Bitlocker turned on, but this computer intentionally did not have Bitlocker turned on - and it was not supposed to be possible to turn on bitlocker on a Win10 Home edition. I am mentioning this to highlight that I did not "accidentally" trigger the Bitlocker being turned on - especially because it requires many steps and confirmations. The drive was simply encrypted one day with permission from me.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

104 answers

Sort by: Newest
  1. Neil D 34,285 Reputation points Volunteer Moderator
    2023-12-18T20:04:56+00:00

    I do see Device Encryption and I know I have it by the Padlock on the C: drive and the fact it shows how to save the recovery key in Control Panel. I have had to use it once or twice so I know it works.

    There is no "turn off" encryption.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-12-18T20:02:54+00:00

    here is 1 link by googleing it , how to turn it off in windows 10 and 11 home, its the same just looks a bit different ,

    so if you dont see device encryption in your windows home then you dont have it ,your bios does not support it.

    [Windows 11] How to disable Device encryption & Standard BitLocker encryption | Official Support | ASUS Global

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-12-18T19:57:22+00:00

    no device encryption is in home and bitlocker is on pro, and device encryption is only on some OEM models, enabled by the manufacturer,

    if you dont have device encryption when you searc for it in Home they you dont have it,

    its only on some oem models with home, some Dell models with home, . yes all pro has bitlocker in

    this device encryption in home versions is a new thing, if you have pro you will only see bitlocker,

    my hp with home does not have it , but my dell insperon does, both 2020 models,

    i have read that microsoft is now recomending to OEM's going for word to have device encryption on all home devices going forward , and yes it is at the bios level to support it in home, pro its only the OS.

    but again , if windows home device encryption is on at the bios level you would have option to turn it off in windows , also my dell home, if i turn off tpm in the bios, and reinstall windows then encryption is off i have noticed, some bios will have option to turn off encryption in the bios also , depends on your system model

    Was this answer helpful?

    0 comments No comments
  4. Neil D 34,285 Reputation points Volunteer Moderator
    2023-12-18T19:41:01+00:00

    Type and search [Device encryption settings] in the Windows search bar①, then click [Open]②. On the Device encryption field, set the option to [Off]③

    and for Pro versions of windows Type and search Bitlocker to manager Bitlocker settings to turn it off and wait for it to decrypt the drive. ,

    the only difference with pro versions of Bitlocker it can do more than one drive , Home versions on device encryption can only encrypt 1 drive the c drive, but they both use Bitlocker key's

    So far as I can see there is not option to turn off Device Encryption in Home edition. That function s only available in Pro. Certainly the case with my Lenovo.

    Device Encryption in Home edition is set due to the bios during the OOBE.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-12-18T17:22:51+00:00

    find your bitlocker key and then turn off device encryption , now applies to some OEM's running Home or Pro,

    last resort you have to format the drive , and turn it off is windows settings after clean installing windows going forward,

    FYI, i have also seen this in a drive that was failing , windows got corrupted and caused device encrytion to stop booting further,

    The following is by googeling how to find your bitlocker key,

    In your Microsoft account: Open a web browser on another device. Go to **https://account.microsoft.com/devices/recoverykey** to find your recovery key. Tip: You can sign into your Microsoft account on any device with internet access, such as a smartphone.

    Type and search [Device encryption settings] in the Windows search bar①, then click [Open]②. On the Device encryption field, set the option to [Off]③

    and for Pro versions of windows Type and search Bitlocker to manager bitlocker settings to turn it off and wait for it to decrypt the drive. ,

    the only difference with pro versions of bitlocker it can do more than one drive , Home versions on device encryption can only encrypt 1 drive the c drive, but they both use bitlocker key's

    Was this answer helpful?

    0 comments No comments