What does HRESULT 0x8031005B (FVE_E_INVALID_STARTUP_OPTIONS) mean?

 
Previous Next
FVE_E_NO_FEATURE_LICENSE FVE_E_POLICY_RECOVERY_PASSWORD_NOT_ALLOWED

FVE_E_INVALID_STARTUP_OPTIONS

Startup policies are a constraint matrix

BitLocker operating-system protectors can use TPM-only, TPM plus PIN, TPM plus startup key, or TPM plus PIN and startup key, subject to platform and policy support. FVE_E_INVALID_STARTUP_OPTIONS means the effective Group Policy or CSP settings simultaneously require and prohibit combinations that cannot be satisfied.

Looking at one setting in isolation is insufficient. Domain policy, local policy, management profiles, and existing protectors can produce an effective configuration different from the administrator's intended template.

How to resolve the conflict

  • Export the effective policy and compare every startup-authentication option: allow, require, or disallow.
  • Check whether a TPM is present and ready and whether the device supports the required preboot input.
  • Remove stale duplicate policy delivery rather than repeatedly recreating protectors.
  • After policy correction, verify the recovery password is escrowed before changing the operating-system protector.

References


Looking for a different code? Search another status or error code.