Bitlocker enabled itself on Windows 10 Home edition without a notice and without permission

Anonymous
2022-06-29T22:51:13+00:00

After three years of owning a Dell Inspiron 13 (Windows Home) the computer somehow enabled Bitlocker on its own and encrypted my C: drive. Since I did not activate Bitlocker, I don't have the keys to decrypt the drive. My Microsoft account does not list any keys in it so there is no way to recover the keys as far as I know. Therefore none of the published solutions I have seen can work because they all assume that I have access to the keys. I see many similar complaints online (at least since 2018) and hundreds of "likes" so this appears to be a relatively common problem.

When booting, I see a message titled "BitLocker recovery" and it asks for the recovery key. It then says to "try your work or school account at: aka.ms/aadrecoverykey."

This suggests that the key may be associated with some active directory domain away from my computer. However, the admin account on this computer has, to my knowledge, never logged into an active directory domain, although non-admin users have. And, if the Amin account has connected to a Active Directory somewhere, I sure as heck did not give them a permission to encrypt my drive and lock me out of my computer, and give the key to some third party "work or school" account. If this is what happened, Microsoft, you have a serious security issue where third parties can effectively encrypt hard drives without permission using Microsoft's own tools. That is ransomware - without the ransom. But, this is still just a theory vaguely supported by this link https://hardsoft-support.kayako.com/article/99-windows-10-bitlocker-turns-on-without-a-notice

Here is a quote from the post: "Dell and Lenovo systems that ship with the Windows 10 operating system and are equipped with Trusted Platform Module (TPM) capability will have Microsoft BitLocker encryption enabled from the factory. It has been found that once the device is registered to a Active Directory domain - Office 365 Azure AD, Windows 10 automatically encrypts the system drive. You find this once you reboot your computer and are then prompted for the BitLocker key."

Since I don't know what possible organization could have encrypted the drive, and since I don't have admin access to them, the instructions in the article don't apply.

The laptop is Dell Inspiron 13 7370 - which I don't even think has a TPM chip built in it. BIOS is version 1.20.0. ePSA build is 4306.13 UEFI ROM.

So, Microsoft, how does this get fixed?

P.S. My other computers have Win10 Pro and and they have Bitlocker turned on, but this computer intentionally did not have Bitlocker turned on - and it was not supposed to be possible to turn on bitlocker on a Win10 Home edition. I am mentioning this to highlight that I did not "accidentally" trigger the Bitlocker being turned on - especially because it requires many steps and confirmations. The drive was simply encrypted one day with permission from me.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

104 answers

Sort by: Oldest
  1. Anonymous
    2022-10-21T19:19:34+00:00

    This happened to me. A recently purchased laptop had a black screen, and BestBuy tried to transfer data from the hard drive to a brand new laptop. That's when I found out BitLocker was turned on. I did not switch it to On, and the Recovery Key was not in my MS account.

    When I checked the brand new laptop, the Privacy & Security / Device Encryption screen has Device Encryption defaulted to On.

    When I loaded MS365 on the brand new laptop, I was NOT notified that the default is ON, nor was I notified to save the Recovery Key.

    MS really needs to get it together. If a user is unable to log on for whatever reason (BIOS issue for example), the user's data is inaccessible. MS doesn't even mention BitLocker during the MS365 installation process. Users are left to discover too late that they don't have a Recovery Key.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-10-21T19:41:49+00:00

    That is a terrible thing to put parents through. Shame on MS.

    But I feel your pain: By the time I went through all of those steps to get into my MS Account (which I don't access on a regular basis), the Recovery Key was not there.

    My only guess as to why: when Geek Squad installed MS365, they were not logged into my MS Account. And...I now know that BitLocker is not mentioned in the MS365 installation process even though it defaults to On, so Geek Squad didn't know to save it.

    Lost about two months of data. Gone. Forever.

    Also lost hours of time trying to learn all I could about Bit Locker before I gave up, including 1.5 hours chatting with MS Support only to have my problem repeated back to me with the proverbial "it shouldn't do that." No kidding it shouldn't do that, but it did.

    I just installed MS365 on a brand new laptop. I was logged into my MS Account. No mention of Bit Locker. I went straight to the Device Encryption screen - default is set to On.

    btw: I saved the recovery key, turned it off, then turned it on again. The key had changed! So, if it gets turned on again by someone other than me while logged into my MS Account....

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-10-21T19:43:20+00:00

    I agree with you and think a class action case is bound to happen.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-10-24T14:08:23+00:00

    I was lucky. It took some wrangling around, but at least I was able to find the correct bit locker keys for each computer. I cannot imaging the grief I would be dealing with if my In-Laws had lost 80 some odd years worth of pictures and videos that they paid good money to have digitized. Chances are3, I have them backed up somewhere, but finding all that would have been a major task.

    I find it odd that Microsoft has offered no explanation or apology for this blatant and egregious error. It's almost like they are saying "we are Microsoft, you don't like it? tough."

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2022-10-24T19:46:56+00:00

    I've tried 3 times posting to this thread and for some reason it is not allowing me to complete my thoughts. It's as if someone does not want me to post. But let's move past conspiracy theories.

    In a nutshell, I registered my laptop with Microsoft. I have bitlocker key, but bit locker was turned off. 2 weeks agon my laptop loses access to my C drive, and I'm left with an X drive. X is a very limited drive, with bare minimal drivers. Most of the cmd prompt commands do not work, you need the C drive for that. When I try to unlock my bit locker, it does not accept my key, which is why I think I may be a victim of ransom ware - the BitLocker Virus. Anyone else heard of this virus? But after reading these posts, I'm wondering if it's a recent update to MIcrosoft. In either case I have found no resolution, with the following exception:

    The X drive is bare minimum on drivers. Divers for my C drive were missing. So, I found what drivers I needed from Intel and installed them - unfortunately they must be reinstalled each time I reboot as the X drive is a small boot drive. However, once I installed the correct drivers, I could see my C Drive. I tried accessing this drive, but the bit locker key window pops up, but my key, the one I saved upon registration of my laptop no longer works. I've tried everything I think trying to turn off, remove, and stop bit locker from initiating to no avail.

    I don't remember seeing a ransom note so no idea if it is a virus, all I know is I can't access my files. So, anyone and/or Microsoft, you got any solutions or even heard of the Bit Locker Virus? I've run Malware and other kinds of virus removers. Microsoft Defense is not available as it not on the X drive, but the C drive.

    At this point, I'm ready to hold an "Office Space" party. But rather than taking it out on a fax machine, I chuck the laptop into the canal in back.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments