BIOS upgrade with SMS triggering bitlocker?
I am trying to upgrade BIOS using SMS (ConfigMgr/SCCM 2007). It appears the bitlocker is triggered after the BIOS has been upgraded. The process runs with the system account. Is this by design? Thanks.Mayur
December 14th, 2010 1:03pm

Yes, this is by design. http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx#BKMK_examplesosrec >Upgrading critical early startup components, such as a BIOS upgrade, causing the BIOS measurements to change. If you want to do a firmware or BIOS upgrade using SCCM 2007, do this: 1. Create a task to suspend bitlocker protection >%systemroot%\system32\manage-bde -protectors -disable c: 2. Complete the BIOS/firmware upgrade. 3. Now to enable Bitlocker protection >%systemroot%\system32\manage-bde -protectors -enable c: I hope this helps you.Manoj Sehgal
Free Windows Admin Tool Kit Click here and download it now
December 15th, 2010 8:59am

Thanks. This works. But I think this is a very serious flaw in the OS. It should know the change is being done by an authorized account should not treat it as a threat.Mayur
December 15th, 2010 3:09pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics