Quantcast
Channel: Windows 8.1 Installation, Setup, and Deployment forum
Viewing all articles
Browse latest Browse all 5362

Microsoft Surface, TPM and Bitlocker issues

$
0
0
I've currently started to deploy Microsoft Surface Pro's and I am having issues with TPM, Bitlocker, and AD.  
I've followed this guide, and all of my Windows 7 machines backup fine.

Technet Article dd875529 

Process:
Create Windows 8 Enterprise image on Surface Pro #1
Sysprep Image
Capture image using DISM
Deploy Image to Surface Pro #2
Once Surface Pro #2 comes out of Sysprep the TPM Status is "The TPM is ready for use with reduced functionality".

If I clear the TPM, the Surface will reboot and prompt me with an American Megatrends "TPM Page" BIOS/UEFI page.

Text from Page:
"A configuration change was requested to enable, activate, clear, enable, and activate the TPM
This action will clear and turn on the computer's TPM (Trusted Platform Module)
Warning: This request will remove any keys stored in the TPM

Press F12 to enable, activate, clear, enable, and activate the TPM

Press Esc to reject this change request and continue

I can then clear the TPM, and it resets to a "The TPM is ready for use." state.

At this point when I go to enable Bitlocker I get the message "Group Policy settings require that a recovery password be specified before encrypting the drive".  Surface Pro #1 was able to come out of Sysprep and backup it's keys correctly and required nothing further to enable Bitlocker.  I was hoping that after clearing the TPM, Surface Pro #2 would be able to do the same, but it seems at some point, #2 is not backing up keys to AD.

Checking the attributes in AD of Surface Pro #2 shows "msTPM-TpmInformationForComputer" is populated.  "msTPM-OwnerInformation" is not populated though.

Viewing all articles
Browse latest Browse all 5362

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>