| Previous | Next |
| FVE_E_POLICY_RECOVERY_KEY_REQUIRED | FVE_E_POLICY_STARTUP_PIN_REQUIRED |
FVE_E_POLICY_STARTUP_PIN_NOT_ALLOWED
FVE_E_POLICY_STARTUP_PIN_NOT_ALLOWED BitLocker was asked to use a TPM plus startup PIN configuration, but the effective startup-authentication policy forbids a PIN. This is a policy mismatch, not evidence that the TPM or PIN itself is broken.
What to check
- Review the operating-system-drive startup-authentication policy and determine which TPM protector combinations are allowed.
- Use one of the approved startup methods instead of repeatedly retrying the same PIN request.
- If a PIN is required by the security design, have the policy owner enable it before adding the protector.
manage-bde -protectors -get <drive>
Microsoft: Configure BitLocker policy settings
Microsoft: manage-bde -protectors
Microsoft: BitLocker boot and TPM countermeasures
Looking for a different code? Search another status or error code.
