This commit is contained in:
Teresa-Motiv
2019-11-05 13:59:40 -08:00
parent 7210bdd880
commit 251a679fff

View File

@ -106,16 +106,18 @@ This issue occurs if the Surface device TPM is configured to use Platform Config
- Secure Boot is turned off. - Secure Boot is turned off.
- PCR values have been explicitly defined, such as by Group Policy. - PCR values have been explicitly defined, such as by Group Policy.
Devices that support Connected Standby (also known as *InstantGO* or *Always On, Always Connected PCs*), including Surface devices, must use PCR 7 of the TPM. In its default configuration on such systems, BitLocker binds to PCR 7 and PCR 11 if PCR 7 and Secure Boot are correctly configured. For more information, see "About the Platform Configuration Register (PCR)" at [BitLocker Group Policy Settings]https://docs.microsoft.com/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj679890(v=ws.11)#about-the-platform-configuration-register-pcr)). Devices that support Connected Standby (also known as *InstantGO* or *Always On, Always Connected PCs*), including Surface devices, must use PCR 7 of the TPM. In its default configuration on such systems, BitLocker binds to PCR 7 and PCR 11 if PCR 7 and Secure Boot are correctly configured. For more information, see "About the Platform Configuration Register (PCR)" at [BitLocker Group Policy Settings](https://docs.microsoft.com/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj679890(v=ws.11)#about-the-platform-configuration-register-pcr)).
### Resolution ### Resolution
To verify the PCR values that are in use on a device, open and elevated Command Prompt window and run the following command: To verify the PCR values that are in use on a device, open and elevated Command Prompt window and run the following command:
```cmd ```cmd
manage-bde.exe -protectors -get \<OSDriveLetter\>: manage-bde.exe -protectors -get <OSDriveLetter>:
``` ```
In this command, &lt;*OSDriveLetter*&gt; represents the drive letter of the operating system drive.
To resolve this issue and repair the device, follow these steps. To resolve this issue and repair the device, follow these steps.
#### <a id="step-1"></a>Step 1: Disable the TPM protectors on the boot drive #### <a id="step-1"></a>Step 1: Disable the TPM protectors on the boot drive