






















Hi all,
We are experiencing ongoing BitLocker recovery prompts on a Windows 11 enterprise device even after successfully installing KB5089549, which Microsoft states fixes the recent Secure Boot / PCR7 BitLocker recovery issue.
Environment:
HP EliteBook G10
Windows 11 25H2
OS Build 26200.8457
Hybrid Azure AD Joined
BitLocker TPM protector enabled
Secure Boot enabled
VBS / Secure Launch enabled
What we already confirmed:
KB5089549 installed successfully
TPM healthy (Get-Tpm)
Secure Boot healthy (Confirm-SecureBootUEFI = True)
PCR7 Configuration = Bound
TPM protector recreated successfully
No pending HP BIOS/firmware updates via HP Image Assistant
BitLocker protection status healthy
Current issue:
The device still requests the BitLocker recovery key after every reboot.
We already tested:
Suspend BitLocker
Remove/re-add TPM protector
Multiple reboots
KB5089549 installation
No custom BitLocker PCR GPOs found
Hypervisor disabled using:
bcdedit /set hypervisorlaunchtype off
The issue still persists.
Interesting observations:
System has Secure Launch, SMM Firmware Measurement, and VBS enabled
USB4 / DisplayLink / dock-related drivers present
TPM protector uses PCR profile 7,11
Has anyone else seen:
continued BitLocker recovery after KB5089549,
especially on HP enterprise devices,
even when PCR7 shows “Bound” and Secure Boot/TPM health appear normal?
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。