{"id":10773,"date":"2019-08-17T00:03:00","date_gmt":"2019-08-16T22:03:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=10773"},"modified":"2019-08-17T07:51:14","modified_gmt":"2019-08-17T05:51:14","slug":"windows-10-v1903-bitlocker-issue-tpm-2-0-drops-error-10","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2019\/08\/17\/windows-10-v1903-bitlocker-issue-tpm-2-0-drops-error-10\/","title":{"rendered":"Windows 10 V1903 Bitlocker issue: TPM 2.0 drops error 10"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" height=\"58\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2019\/08\/17\/windows-10-v1903-bitlocker-problem-tpm-lst-fehler-10-aus\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Is there an issue with the Trusted Platform Module 2.0 on Windows 10 version 1903? I got reports that TPM is causing error code 10 in Device Manager. Then of course Bitlocker does not work anymore.<\/p>\n<p><!--more--><\/p>\n<h2>Background: Bitlocker and TPM<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg01.met.vgwort.de\/na\/979f1ee7e0ee47a2a0210d73437dfbeb\" alt=\"\" width=\"1\" height=\"1\" \/>Microsoft's <a href=\"https:\/\/en.wikipedia.org\/wiki\/BitLocker\" target=\"_blank\" rel=\"noopener noreferrer\">Bitlocker<\/a> can be used for hard disk encryption under Windows. This feature is available from the Pro version of the operating system. Bitlocker has the possibility to perform the encryption with or without Trusted Platform Module 2.0.<\/p>\n<p>If a TPM module is missing, a PIN must be entered to decrypt the Bitlocker-encrypted files. If there is a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Trusted_Platform_Module\" target=\"_blank\" rel=\"noopener noreferrer\">Trusted Platform Module 2.0<\/a> in the form of a chip on the motherboard, Bitlocker can use it for authentication. The encrypted media are then bound to this hardware via TPM.<\/p>\n<h2>Issues with the TPM chip in Windows 10 V1903<\/h2>\n<p>Bitlocker and the Trusted Platform Module 2.0 are always good for problems under Windows (see links to other articles at the end of this article). Now German blog reader Andreas E. (thank you for that) has informed me about a problem with Bitlocker in connection with TPM 2.0 and Windows 10 May 2019 Update (Version 1903) via a private message on Facebook. He himself as well as his colleagues have noticed problems with TPM on several computers running Windows 10 Version 1903.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"TPM error\" src=\"https:\/\/social.technet.microsoft.com\/Forums\/getfile\/1375973\" alt=\"TPM error\" width=\"655\" height=\"527\" \/><br \/>\n(Source: Technet)<\/p>\n<p>The Trusted Platform Module 2.0 cannot be started. In the Device Manager you will find the error message shown in the screenshot above.<\/p>\n<blockquote><p>The device cannot start. (Code 10)<\/p>\n<p>(Operation Failed)<br \/>\nThe requested operation was unsuccessful.<\/p><\/blockquote>\n<p>If the device (TPM 2.0) cannot be started, the device manager reports error 10, of course the TPM protector for bitlockers is omitted. Then Bitlocker is stopped &#8211; and you can no longer access the encrypted information or use Bitlocker with TPM. Andreas writes about it:<\/p>\n<blockquote><p>And the [Bitlocker] protection is stopped<br \/>\nBut you will find very little information about it<br \/>\nMaybe worth doing some research.<\/p><\/blockquote>\n<p>That's the information I have so far. But a short search on the internet shows that Bitlocker and TPM are not fool proof at all, but can cause trouble. Dell has published a Support article <a href=\"https:\/\/www.dell.com\/support\/article\/us\/en\/04\/how12395\/how-to-troubleshoot-and-resolve-common-issues-with-tpm-and-bitlocker?lang=en\" target=\"_blank\" rel=\"noopener noreferrer\">How to troubleshoot and resolve common issues with TPM and BitLocker<\/a> on various bugs.<\/p>\n<blockquote><p>Whether there are issues with a TMP 2.0 firmware update, as described <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4096377\/windows-10-update-security-processor-tpm-firmware\" target=\"_blank\" rel=\"noopener noreferrer\">here by Microsoft<\/a>, isn't known so far.<\/p><\/blockquote>\n<h2>What can I find about TPM Code 10?<\/h2>\n<p>If you search for TPM 2.0 and the error code 10 in the internet, you will get some hits.<\/p>\n<h3>Virus scanners and filter drivers<\/h3>\n<p>In the Technet forum there is this <a href=\"https:\/\/social.technet.microsoft.com\/Forums\/windows\/en-US\/7e96c822-11bc-4b5e-b4d8-8f80783eca53\/tpm-20-quotthis-device-cannot-start-code-10quot-in-device-manager?forum=win10itprogeneral\" target=\"_blank\" rel=\"noopener noreferrer\">post<\/a>, which deals with the code 10 with TPM 2.0. There a user describes he deleted UpperFilters and LowerFilters (injected by a virus scanner), because they seem to have caused TPM problems.<\/p>\n<p>But you can't just delete the filter drivers from the registry &#8211; the system didn't boot anymore. The affected person had to reinstall Windows 10 V1809 &#8211; and then the TPM 2.0 chip was detected cleanly in the device manager.<\/p>\n<blockquote><p>Somewhere in forums I found the hint that you should always use the Windows TPM driver &#8211; but not the OEM TMP driver (it is also mentioned <a href=\"https:\/\/superuser.com\/questions\/1172984\/tpm-2-0-not-working-the-resource-requested-is-already-in-use-in-device-mana\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>). I also found the information (e.g. <a href=\"https:\/\/www.drwindows.de\/programme-tools\/152734-probleme-trusted-platform-module-tpm.html\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>) that the UEFI boot mode can have an influence.<\/p><\/blockquote>\n<h2>Conflict with other hardware?<\/h2>\n<p>In <a href=\"https:\/\/h30434.www3.hp.com\/t5\/Desktop-Operating-Systems-and-Recovery\/TPM-2-0-showing-Code-10-in-Device-Manager-possibly-linked-to\/td-p\/6645759\" target=\"_blank\" rel=\"noopener noreferrer\">this HP forum post<\/a>, a user also describes the error image that the TPM 2.0 device displays Code 10 in the Device Manager. Microsoft Windows 10 is used, but no version is specified (based on the post it can have been at most Windows 10 V1803).<\/p>\n<p>However, the poster also reports issues with Windows 10 Hello logon and a fingerprint sensor. What I took with me from this (unsolved) thread is to pay attention to the following:<\/p>\n<ul>\n<li>BIOS and\/or UEFI must be up to date to cleanly support the TPM 2.0 chip.<\/li>\n<li>A suitable chipset driver must be installed over Windows so that all devices are properly detected.<\/li>\n<\/ul>\n<p>The chipset driver should be provided by Windows 10. But if there are problems there, you can see if the OEM offers something updated.<\/p>\n<blockquote><p>In this context I found <a href=\"https:\/\/hitco.at\/blog\/windows-10-v1709-high-definition-audio-controller-code-10\/\" target=\"_blank\" rel=\"noopener noreferrer\">this blog post<\/a>, where an audio device under Windows 10 V1709 throwing the error code 10. But there was the problem that the Bitlocker DMA protection didn't work anymore. The error was solved by a cumulative update for Windows 10 and afterwards the Direct Memory Access (DMA) protection for Bitlocker worked again.<\/p>\n<p>I found <a href=\"https:\/\/www.pcgameshardware.de\/Windows-10-Software-259581\/News\/Update-aktiviert-Retpoline-Schutz-gegen-Spectre-V2-standardmaessig-1282370\/\" target=\"_blank\" rel=\"noopener noreferrer\">a comment on this article<\/a> in which somebody claims that Windows 10 V1903 is 'bypassing' the TPM &#8211; but without giving further details.<\/p><\/blockquote>\n<p>At this point the question: Are there any other people affected who notice this effect? Has anyone perhaps even determined a cause and knows a fix?<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2019\/07\/17\/windows-10-important-secure-boot-bitlocker-bug-fix\/\">Windows 10: Important Secure Boot\/Bitlocker Bug-Fix<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/05\/09\/bitlocker-management-in-enterprise-environments\/\">BitLocker management in enterprise environments<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/10\/30\/dell-new-bios-is-causing-bitlocker-issues\/\">Dell: New BIOS is causing Bitlocker issues<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/11\/07\/bitlocker-on-ssds-microsoft-security-advisory-notification-nov-6-2018\/\">Bitlocker on SSDs: Microsoft Security Advisory Notification (Nov. 6, 2018)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/11\/06\/ssd-vulnerability-breaks-bitlocker-encryption\/\">SSD vulnerability breaks (Bitlocker) encryption<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2018\/09\/20\/windows-10-v1803-fix-for-bitlocker-bug-in-nov-2018\/\">Windows 10 V1803: Fix for Bitlocker bug in Nov. 2018?<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2019\/07\/20\/hp-probook-430-g5-bitlocker-verschlsselt-automatisch\/\">Windows 10: Bitlocker encrypts automatically<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Is there an issue with the Trusted Platform Module 2.0 on Windows 10 version 1903? I got reports that TPM is causing error code 10 in Device Manager. Then of course Bitlocker does not work anymore.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,2],"tags":[47,194],"class_list":["post-10773","post","type-post","status-publish","format-standard","hentry","category-issue","category-windows","tag-issue","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10773","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=10773"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/10773\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=10773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=10773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=10773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}