What does HRESULT 0x80310066 (FVE_E_POLICY_STARTUP_TPM_NOT_ALLOWED) mean?

 
Previous Next
FVE_E_POLICY_STARTUP_PIN_KEY_REQUIRED FVE_E_POLICY_STARTUP_TPM_REQUIRED

FVE_E_POLICY_STARTUP_TPM_NOT_ALLOWED

FVE_E_POLICY_STARTUP_TPM_NOT_ALLOWED The effective policy does not allow TPM-only startup protection. The TPM may be healthy, but the device is configured to require an additional pre-boot factor or another approved startup method.

What to check

  • Inspect the effective operating-system-drive startup policy.
  • Determine whether the required method is TPM plus PIN, TPM plus startup key, or another approved option.
  • Do not remove existing recovery protectors while changing startup authentication.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: BitLocker boot and TPM countermeasures


Looking for a different code? Search another status or error code.