Enable BitLocker
Enable BitLocker Drive Encryption in Control Panel or PowerShell
- Start gpedit.msc
- Navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operatin System Drives
- Enable following Settings
- Require additional authentication at startup
- Allow enhanced PINs for startup (OPTIONAL)
- Configure minimum PIN legnt for startup (OPTIONAL)
Configure pre-boot PIN in PowerShell
manage-bde -protectors -add c: -TPMAndPIN
manage-bde -status
Leave a Reply