Want to use BitLocker security on a machine without a TPM chip?
Just follow the instructions below to get around this:
- Click on start and in the run box type “gpedit.msc” and press enter
- Navigate Local Group Policy to require additional authentication at startup. (See below).
- Under Local Computer Policy navigate to Computer Configuration\Administrative Templates\Windows Components\Bit Locker Drive Encryption\Operating System Drives and double click on Require Additional Authentication at Startup.
- Double click on Require Additional Authentication at startup and click Enable in the window that opens.
- Then tick the box halfway down on the left hand side to Allow BitLocker Without a Compatible TPM.
- Close all the windows and go back to the drive you want to encrypt and you should now be able to encrypt with only a USB pen drive, save to a file or print off the key or a combination of all three.


