logo
Bitlocker Group Policy Error When Enabling BitLocker Encryption

How to Fix Group Policy Error When Enabling BitLocker Encryption?

I am attempting to use BitLocker to encrypt my system drive, but I receive the following Group Policy error, "The Group Policy settings for BitLocker startup options are in conflict and cannot be applied. Contact system administrator for more information." Why this error occurs? And how can I solve it?

author

Lydia

Rest assured; this error can be easy solved by simply modifying the Group Policy Editor or Registry Editor. Go ahead reading, you'll understand why this happen and work it out.

Why this BitLocker Group Policy Error Happens?

If you’ve updated the Group Policy settings of BitLocker before enabling BitLocker encryption, then you may run into this BitLocker error: "The Group Policy settings for BitLocker startup options are in conflict and cannot be applied". Due to wrong configuration, it result in the conflict between BitLocker Group Policy settings and BitLocker Registry Editor settings.

BitLocker Group Policy Error

Take a user's experience as an example. To fix BitLocker TPM Error, he firstly set "Required additional authentication at startup" to "Enabled", and then ticked "Allow BitLocker without TPM" in Group Policy Editor as the tutorial described.

But he wrongly selected "Require TPM" in "Configure TPM startup" option. Then when he was about to enable BitLocker Encryption for System drive, this error suddenly appeared.

Wrong BitLocker Group Policy Settings

Solution 1: Update BitLocker Group Policy Settings

When modifying the Group Policy settings of BitLocker, you can’t require one form and allow the others. You can use the following settings to avoid conflicts.

Before start, reach to the BitLocker Drive Encryption in Group Policy Editor first:

Step 1 Type gpedit.msc in the search box, and press Enter.

Step 2 Navigate to following path:

Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drive

BitLocker Local Group Policy Editor Settings

Step 3 Double click on "Required additional authentication at startup".

Option 1: Disable All BitLocker Settings

Steps Select the "Not Configured" radio option. Click "Apply" and "OK" to save the updates.

BitLocker Group Policy not Configured

Option 2: Set One Option Required

Step1 Select radio button of "Enabled" to enable BitLocker startup Authentication.

Step2 Set "Configure TPM startup PIN" option to "Require startup PIN with TPM", and set another three options to "Do not allow", and then apply it. Swapping the TPM startup PIN for another option is also feasible. You can pick the one you need and disable the others.

Require Startup PIN with TPM

Option 3: All options are set to allow

Step1 Check the "Enable" option to enable BitLocker startup Authentication.

Step2 Set all four options to "allow", and apply this setting.

Allow All BitLocker Authentication at Startup

Notes: You just need to choose one option from these three methods that meets your needs. To make the modification takes effect, remember to restart your system.

Solution 2: Update Registry Editor

Step 1 Press Win + R to open the Run dialog. Type "regedit" in it and press Enter key.

Step 2 Go to the following path:

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE

BitLocker Registry Editor Settings

Step 3 Check the REG_DWORD value and change it to be consistent with Group Policy BitLocker settings.

Be careful to update or delete the REG_DWORD value in Registry Editor, which may cause system stability problems.

People Also Ask

How to Resolve Windows 11 BitLocker Missing after System Startup?

There are many possible reasons for this error.Before start, type "Manage BitLocker" in the search box to check if you can access to the BitLocker Drive Encryption panel.

author Lydia

How to Turn On BitLocker for Operating System Drive Without Tpm?

Sure, Windows allows us to encrypt the operating system drive on devices without TPM supported. To configure this, we need to edit the related group policy.

author Benjamin

Why Can't I Open Software on the BitLocker-Encrypted Drive?

BitLocker encryption requires the drive to be unlocked before accessing any data stored on it. The primary reason you can't open software on a BitLocker-encrypted drive is that the drive hasn't been unlocked yet.

author Benjamin

How to Fix Microsoft BitLocker Drive Encryption 65000 Error?

Microsoft says this 65000 BitLocker error is being incorrectly reported by Intune, and it won’t affect the normal operation of BitLocker encryption.

author Lydia