What does HRESULT 0x80310062 (FVE_E_POLICY_STARTUP_KEY_NOT_ALLOWED) mean?

 
Previous Next
FVE_E_POLICY_STARTUP_PIN_REQUIRED FVE_E_POLICY_STARTUP_KEY_REQUIRED

FVE_E_POLICY_STARTUP_KEY_NOT_ALLOWED

FVE_E_POLICY_STARTUP_KEY_NOT_ALLOWED The requested BitLocker startup key is not permitted by the effective policy for the operating-system drive. A startup key uses removable media during pre-boot authentication and is controlled separately from recovery keys.

What to check

  • Confirm that the requested file-based startup protector is not being confused with an external recovery-key protector.
  • Review the startup-authentication policy for operating-system drives.
  • Use an allowed TPM, TPM plus PIN, or other approved protector combination.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: BitLocker boot and TPM countermeasures


Looking for a different code? Search another status or error code.