Skip to main content

Use BitLocker Drive Encryption without TPM chip

Posted March 2007 by Steve Sinchak

Windows Vista includes a new hard drive encryption feature called BitLocker Drive Encryption. BitLocker can be a very useful security feature for businesses and home users that have sensitive and confidential information stored on their computer.  Unfortunately, BitLocker Drive Encryption by default requires a Trusted Platform Module (TPM Chip) version 1.2 or later installed in your computer.  A lot of the computers and laptops on the market do not come with TPM chips installed since they are typically only found in premium model business computers.  If you have Windows Vista Business, Ultimate or Enterprise but do not have a TPM chip, you can still use BitLocker Drive Encryption.

Hidden away in local group policy is a setting that will allow you to turn on the ability to use a USB storage device instead of a TPM key to store the encryption key.  This is a great feature for users that don't have the latest high-end hardware because you can still use hard drive encryption.  However, every time you turn on your computer, the USB storage device that has the encryption key located on it must be plugged in. Without it, your computer will not boot up.  One BitLocker Drive Encryption is setup with a USB storage device, that USB storage device basically becomes the key to your computer.

Follow these steps to turn on the ability to use a USB storage device with BitLocker Drive Encryption on hardware that does not have a TPM device:

  1. Click on the Start Button and key in gpedit.msc and hit Enter.
  2. Navigate through: Computer Policy, Administrative Templates, Windows Components and BitLocker Drive Encryption.
  3. Right click on Control Panel Setup: Enable advanced startup options and select Properties.
    Check Enabled and hit OK.

Related Posts


If you own a Google Chromecast streaming device, you can easily share a browser tab in Chrome browser or even your entire desktop.  This can be very useful when presenting from your laptop or if you just want to watch something on a big screen that is only on your PC.  The only requirement is you must be on the same network as your Chromecast...

Read More

If you are a fan of minimalist desktop experiences, hiding the desktop icons are an easy way to clean up the Windows interface.  Instead of saving everything to your desktop, use the default profile folders such as downloads and documents.  Actually hiding all the icons on your desktop is a very simple customization hidden in the right-click context menu.  Just right-click on the desktop, select View...

Read More

Google security researchers have published details about a major security flaw found in the SSL protocol that is used to encrypt data transferred between your browser and a web server. SSL is typically used in situations where logon credentials are validated...

Read More

Enabling two-factor authentication is a great way to add an additional level of protection to your Microsoft account.  Even if your password is stolen, your account is still protected because two-factor authetication requires an additional level of verification to log in. Microsoft calls their version of two-factor authentication "two-step verification" and it works by providing you with a random code...

Read More