{"id":7073,"date":"2018-09-20T01:02:00","date_gmt":"2018-09-19T23:02:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=7073"},"modified":"2018-09-18T13:53:17","modified_gmt":"2018-09-18T11:53:17","slug":"windows-10-v1803-fix-for-bitlocker-bug-in-nov-2018","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/09\/20\/windows-10-v1803-fix-for-bitlocker-bug-in-nov-2018\/","title":{"rendered":"Windows 10 V1803: Fix for Bitlocker bug in Nov. 2018?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" align=\"left\" height=\"58\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=209448\" target=\"_blank\">German<\/a>]Brief note for administrators and users of Windows 10 Version 1803 in enterprise environment using Bitlocker encryption. Microsoft plans to fix the Bitlocker bug, which deactivates the function during update installation, with a patch scheduled for November 2018.<\/p>\n<p><!--more--><\/p>\n<h2>What's the Bitlocker Bug?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/aeda5515b452412fad77668852efa6fd\" width=\"1\" height=\"1\">If you are not up to date (I for instance also had to check my blog for details): There is the problem that Bitlocker pauses during update installation if there is no TPM chip on the machine. I blogged about that within my article <a href=\"https:\/\/borncity.com\/win\/2018\/08\/18\/windows-10-v1709-1803-issues-also-august-patchday\/\">Windows 10 V1709\/1803: Issues (also August Patchday)<\/a> in August 2017. <\/p>\n<p>The bug is described in the <a href=\"https:\/\/social.technet.microsoft.com\/Forums\/en-US\/0e48536f-40ff-4046-bd08-ed4a39b4840f\/bitlocker-automatically-suspending-during-updates?forum=win10itprosecurity&amp;prof=required\" target=\"_blank\">Technet forum<\/a> and applies to machines with Windows 10 version 1803 that do not have a TPM module. If the hard disk encryption with Bitlocker is activated, Windows deactivates it during the installation of an update. Here is the description:&nbsp; <\/p>\n<blockquote>\n<p>I have a machine with Bitlocker enabled, no TPM, Windows 10 1803.  <\/p>\n<p>For the last month or so, whenever a Windows system update is applied, Bitlocker is automatically suspended upon first login after the machine restarts. Case in point: the latest Windows 10 cumulative update was applied this morning, only for the machine to restart with Bitlocker suspended on the OS drive. Interestingly, there is also some dubious behaviour in terms of the initial Bitlocker password entry screen. Not having a TPM, the user must enter a password to boot. On at least 2 occasions, after applying an update, the system does not present the Bitlocker password entry screen and progresses all the way to the user login screen. However, this morning the Bitlocker password entry screen was presented correctly but after entering the correct password and then logging in to Windows, Bitlocker was suspended.  <\/p>\n<p>This is the state of the OS drive after logging in:  <\/p>\n<p>Volume C: [System]<br \/>[OS Volume]  <\/p>\n<p>Size:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 59.07 GB<br \/>BitLocker Version:&nbsp;&nbsp;&nbsp; 2.0<br \/>Conversion Status:&nbsp;&nbsp;&nbsp; Fully Encrypted<br \/>Percentage Encrypted: 100.0%<br \/>Encryption Method:&nbsp;&nbsp;&nbsp; XTS-AES 128<br \/>Protection Status:&nbsp;&nbsp;&nbsp; Protection Off (1 reboots left)&nbsp;&nbsp; &lt;\u2014\u2014<br \/>Lock Status:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Unlocked<br \/>Identification Field: Unknown<br \/>Key Protectors:<br \/>Password<br \/>Numerical Password  <\/p>\n<p>Now, I realise that Bitlocker is temporarily suspended \u2013 restarting the machine again will enable it without any action from the user. However, this is a security risk for the time between restarting after an update and the next restart and severely undermines our trust in Bitlocker. I would expect that Bitlocker should NEVER be suspended unless initiated by a user\/admin.<\/p>\n<\/blockquote>\n<p>If the machine is restarted again, Bitlocker will be activated again. So if people install updates and put the machine into sleep mode, Bitlocker may remain disabled for a long time. The bug only occurs on Windows 10 V1803 machines without a TMP chip.&nbsp; <\/p>\n<h2>Microsoft plans a bug fix for November 2018<\/h2>\n<p>I haven't followed the progress, but affected users hoped that Microsoft would roll out a fix per update in September 2018. But that didn't happen, as user andadok notes in the Technet thread. There is then a hint to deactivate Bitlocker temporarily before each update and to activate it again after the update installation. Susan Bradley, who follows the thread, now points to Twitter. <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">btw the bug whereby bitlocker with a password needs reactivation after patching in 1803 has been identified and will be fixed in November. Kudos to Chad Z. Hower for the assist with the bug.<\/p>\n<p>\u2014 SBSDiva (@SBSDiva) <a href=\"https:\/\/twitter.com\/SBSDiva\/status\/1041790434069012480?ref_src=twsrc%5Etfw\">17. September 2018<\/a><\/p><\/blockquote>\n<p><span id=\"preserve6e93edaee1744af9be0e25924d472433\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>So if someone should be affected: Just keep it in mind &#8211; although the problem should be eaten in 30 months anyway. The updated Bitlocker documentation can be found <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/information-protection\/bitlocker\/bitlocker-countermeasures\" target=\"_blank\">here<\/a>.<\/p>\n<p><strong>Similar articles<\/strong><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/09\/15\/windows-10-v1803-custom-login-lock-screen-image-wont-show-until-user-login\/\">Windows 10 V1803: Custom login\/lock screen image won't show, until user login<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/26\/windows-10-v1803-issues-with-cisco-anyconnect-vpn\/\">Windows 10 V1803: Issues with Cisco Anyconnect VPN<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/15\/windows-10-v1803-rollout-stopped-due-to-tls-1-2-issues\/\">Windows 10 V1803 rollout stopped due to TLS 1.2 issues<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/18\/windows-10-v1803-update-kb4458166-fixes-tls-1-2-issue\/\">Windows 10 V1803: Update KB4458166 fixes TLS 1.2 issue<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/14\/windows-10-v1803-easy-document-creator-scan-bug-fixed\/\">Windows 10 V1803: Easy Document Creator scan bug fixed<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/13\/windows-10-v1803-backup-fails-with-0x800706ba\/\">Windows 10 V1803: Backup fails with 0x800706BA<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/08\/09\/windows-10-v1803-domain-join-bug-and-a-workaround\/\">Windows 10 V1803: Domain join bug and a workaround<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/07\/28\/windows-10-v1803-fixes-old-black-screen-display-bugs\/\">Windows 10 V1803 fixes old (black screen) display bugs<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/07\/26\/windows-10-v1803-detects-internal-sata-drives-als-removable\/\">Windows 10 V1803 detects internal SATA drives as removable<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/07\/24\/windows-10-v1803-roaming-profile-not-fully-synchronized\/\">Windows 10 V1803: Roaming profile not fully synchronized<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/07\/23\/windows-10-v1803-smbv1-specials\/\">Windows 10 Pro V1803: SMBv1 'special traps'<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2018\/07\/06\/windows-10-v1803-hcvi-causes-driver-error-code-39\/\">Windows 10 V1803: HCVI causes driver error code 39<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Brief note for administrators and users of Windows 10 Version 1803 in enterprise environment using Bitlocker encryption. Microsoft plans to fix the Bitlocker bug, which deactivates the function during update installation, with a patch scheduled for November 2018.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[356,188,76],"class_list":["post-7073","post","type-post","status-publish","format-standard","hentry","category-windows","tag-bitlocker","tag-bug","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=7073"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/7073\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=7073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=7073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=7073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}