When installing or replacing a TPM, observe the following guidelines: Do not remove an

installed TPM. Once installed, the TPM becomes a permanent part of the system board. When installing or replacing hardware, hp smart array p420i controller cache module status failed HP service providers cannot enable the TPM or the encryption technology. For security reasons, only the customer can enable these features. When returning a system board for service replacement, do not remove the TPM from the system board. bitlocker without tpm When requested, HP Service provides a TPM with the spare system board. Any attempt to remove an installed TPM from the system board breaks or disfigures the TPM security rivet. Upon locating a broken or disfigured rivet on an installed TPM, administrators should consider the system compromised and take appropriate measures to ensure the integrity of the system data. When using BitLocker™, always retain the recovery key/password. The recovery key/password is required to enter Recovery Mode after BitLocker™ detects a possible compromise of system integrity. HP is not liable for blocked data access caused by improper TPM use. For operating instructions, see the encryption technology feature documentation provided by the operating system.

"This device can't use a Trusted Platform Module" When Enabling BitLocker I recently tried to enable BitLocker on an old Windows 8.1 PC at home and got an error message that I found would be extremely cryptic to anyone who isn't a computer geek. Here was the message: This device can't

use a Trusted Platform Module. Your administrator must select the "Allow BitLocker without a compatible TPM" option in the "Require additional authentication at startup" policy for OS volumes. Say what!? Most people will probably just cancel the operation and forget about the whole thing with a message like that. Unfortunately, Microsoft never makes error messages clear and simple to understand. Let's break it down. 1. Trusted Platform Module (TPM) - This is basically a chip that in on newer processors that has extra security features. When BitLocker uses TPM, it stores the encryption key on the chip itself. If you don't have a chip that supports TPM, then you can still use BitLocker, but you'll have to store the encryption key on a USB stick. 2. Administrator Policy -  So what's all the stuff about selecting X and Y policy for OS volumes? Basically, it's a group policy setting that has to be changed that will allow BitLocker to work without the TPM requirement. The fix is pretty straight-forward, just follow the instructions and don't make any other changes. Step 1- Open the group policy editor by pressing the Windows Key + R or by opening the charms bar in Windows 8 and typing in Run. In the Run dialog box, go ahead and type in gpedit.msc and press Enter. Now expand to the following section under group policy: Computer Configuration - Administrative Templates - Windows Components - BitLocker Drive Encryption - Operating System Drives On the right-hand side, you will see an option called Require additional authentication at startup. Go ahead and double-click on that option. By default, it is set to Not Configured, so you'll have to click on the Enabled radio button.  Automatically, it should check the Allow BitLocker without a compatible TPM box, but if not, make sure to check it. Click OK and then close out group policy. Now go back to the BitLocker screen and click the Turn on BitLocker link. Now instead of getting an error message, you should see the BitLocker setup screen. When you click Next, it'll start setting up your hard drive for BitLocker. Again, there is no real security disadvantage to using BitLocker without a TPM, it's just that the encryption key has to be stored on a USB drive instead of being stored on the chip itself. If you're still having issues enabling BitLocker on Windows 8 or Windows 8.1, post a comment and let us know.

