Bitlocker enabled itself on Windows 10 Home edition without a notice and without permission

Anonymous
2022-06-29T22:51:13+00:00

After three years of owning a Dell Inspiron 13 (Windows Home) the computer somehow enabled Bitlocker on its own and encrypted my C: drive. Since I did not activate Bitlocker, I don't have the keys to decrypt the drive. My Microsoft account does not list any keys in it so there is no way to recover the keys as far as I know. Therefore none of the published solutions I have seen can work because they all assume that I have access to the keys. I see many similar complaints online (at least since 2018) and hundreds of "likes" so this appears to be a relatively common problem.

When booting, I see a message titled "BitLocker recovery" and it asks for the recovery key. It then says to "try your work or school account at: aka.ms/aadrecoverykey."

This suggests that the key may be associated with some active directory domain away from my computer. However, the admin account on this computer has, to my knowledge, never logged into an active directory domain, although non-admin users have. And, if the Amin account has connected to a Active Directory somewhere, I sure as heck did not give them a permission to encrypt my drive and lock me out of my computer, and give the key to some third party "work or school" account. If this is what happened, Microsoft, you have a serious security issue where third parties can effectively encrypt hard drives without permission using Microsoft's own tools. That is ransomware - without the ransom. But, this is still just a theory vaguely supported by this link https://hardsoft-support.kayako.com/article/99-windows-10-bitlocker-turns-on-without-a-notice

Here is a quote from the post: "Dell and Lenovo systems that ship with the Windows 10 operating system and are equipped with Trusted Platform Module (TPM) capability will have Microsoft BitLocker encryption enabled from the factory. It has been found that once the device is registered to a Active Directory domain - Office 365 Azure AD, Windows 10 automatically encrypts the system drive. You find this once you reboot your computer and are then prompted for the BitLocker key."

Since I don't know what possible organization could have encrypted the drive, and since I don't have admin access to them, the instructions in the article don't apply.

The laptop is Dell Inspiron 13 7370 - which I don't even think has a TPM chip built in it. BIOS is version 1.20.0. ePSA build is 4306.13 UEFI ROM.

So, Microsoft, how does this get fixed?

P.S. My other computers have Win10 Pro and and they have Bitlocker turned on, but this computer intentionally did not have Bitlocker turned on - and it was not supposed to be possible to turn on bitlocker on a Win10 Home edition. I am mentioning this to highlight that I did not "accidentally" trigger the Bitlocker being turned on - especially because it requires many steps and confirmations. The drive was simply encrypted one day with permission from me.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

104 answers

Sort by: Oldest
  1. Anonymous
    2023-10-04T19:22:32+00:00

    yes , lenovo is going to cause havic for newbs, Microsoft only puts it on Pro for a reason, becuase home users do not have valuable data so there is no need for it, but lenovo is more of a business brand so i can see their point. to force it on Home users. they need to have a screen pop up with more information to educate you when you 1st turn on the computer i agree, i was interested in the forum becuse i work for microsoft and i know Home does not have it, you have to add it with 3rd party tools

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-10-04T20:21:52+00:00

    based on your pic, you dont have bitlocker you have device encryption, here is a pic of what it would look like if you had full bitlocker, here is where it gets confusing, they should rename it really, so device encription still used bitlocker keys, so its just a partal verion of the full bitlocker, , ie still needs same key, so only only small difference is full bit locker you can apply it to all dives connected, device incryption only can do one drive, ie the main drive, so they sould call it bitlocker light, lol, anyways , interesting to me people saying turn on by default, that is surprising as my new HP and other Dell , that i have with home , new in 2022 , not the case, it says in settings not supported , so your lenovo they did something at the bios level or even a windows update to lenovo only they push, that is also possable, to tell windows device encryption to turn on , crazy.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-10-04T20:23:08+00:00

    you would see this with full bitlocker, only available in Pro versions,

    Was this answer helpful?

    0 comments No comments
  4. Neil D 34,285 Reputation points Volunteer Moderator
    2023-10-04T21:18:42+00:00

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-10-04T21:52:42+00:00

    yes it seems microsoft of partnering with oems to tighten security measures, but i see why it has to have modern standby, as if you have multiple drives and one is sleeping , some security issue, so modern standby must remedie the issues with basic drive encryption , sorry for my spelling, "  Modern Standby session encompasses the entire screen-off to screen-on user scenario, its because...From Google on modern standby"

    Was this answer helpful?

    0 comments No comments