What does HRESULT 0x80310060 (FVE_E_POLICY_STARTUP_PIN_NOT_ALLOWED) mean?

 
Previous Next
FVE_E_POLICY_RECOVERY_KEY_REQUIRED FVE_E_POLICY_STARTUP_PIN_REQUIRED

FVE_E_POLICY_STARTUP_PIN_NOT_ALLOWED

FVE_E_POLICY_STARTUP_PIN_NOT_ALLOWED BitLocker was asked to use a TPM plus startup PIN configuration, but the effective startup-authentication policy forbids a PIN. This is a policy mismatch, not evidence that the TPM or PIN itself is broken.

What to check

  • Review the operating-system-drive startup-authentication policy and determine which TPM protector combinations are allowed.
  • Use one of the approved startup methods instead of repeatedly retrying the same PIN request.
  • If a PIN is required by the security design, have the policy owner enable it before adding the protector.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: BitLocker boot and TPM countermeasures


Looking for a different code? Search another status or error code.