logo
Windows 10How to Set up a BitLocker Startup PIN in Windows 10

How to Set up a BitLocker Startup PIN in Windows 10

By Achilles Hill | Last Updated

BitLocker Drive Encryption enables us to encrypt the entire drive with password protection. If your system is equipped with Trusted Platform Module (TPM), you can also choose to set a BitLocker PIN rather than password when encrypting Windows system drive (C:) with BitLocker. However, the steps of setting BitLocker PIN are a little different and complicated. Don't worry! This post will walk you through a full guide on how to set up a BitLocker startup PIN in Windows 10.

how to set up a bitlocker startup pin in windows 10

Part 1: Require startup PIN with TPM

When we are intended to set a BitLocker PIN for hard drive, but the system only offers the option to set a password not a PIN. What's all this about? It is because that the system is not required to set startup PIN. So, we need to reset some settings to enable BitLocker PIN for your system drive. Here is what to do.

Step 1: Press Windows key + R shortcut and then type gpedit.msc and hit Enter.

open policy editor

Step 2:On the popup window, navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives in the left pane.

Step 3: In the right pane, double-click Require additional authentication at startup policy option.

navigate to a particular folder

Step 4: On the popup window, select the radio button of Enable and then check the box of Allow BitLocker without a compatible TPM. Select Require startup PIN with TPM option under Configure TPM startup PIN. Finally, click OK button to save the changes.

require startup pin with tpm

Step 5: In the right pane, double-click Enable use of BitLocker Authentication requiring preboot keyboard input on slates option. Select the radio button of Enabled and then click OK button.

enable use of bitlocker authentication requiring preboot keyboard input on slates

Step 6: Reboot your computer. Then you can refer to the following part to set a BitLocker startup PIN in Windows 10.

Part 2: Set BitLocker PIN by Command Prompt

Step 1: Run Command Prompt as Administrator.

Step 2:Type manage-bde -protectors -add c: -TPMAndPIN and hit Enter.

Step 3: Type and confirm a PIN. Note that when typing PIN, there won't be any change displayed in the interface, which doesn't mean that the input is invalid.

set bitlocker pin in command prompt

Finally, you have set a BitLocker startup PIN in Windows 10 successfully. Next time you boot up your computer, you'll be required to enter this BitLocker PIN.

Notes: Sometimes it is likely that you fail to set a BitLocker PIN for your system drive and a popup window prompts that the BitLocker encryption key cannot be obtained from the trusted platform module (TPM) and PIN. Actually, there are various kinds of factors that may cause this issue on your computer such as UEFI and secure boot is disabled, BIOS is outdated. For more details about this, you can refer to this post.

Related Articles: