Pureinfotech Forums

How to unlock BitLocker drive on Surface Book 2 using PIN on Windows 10

Hi! I am using a Microsoft Surface Book 2 and I have enabled the Require additional authentication at startup on the local policy for Bitlocker drive Encryption on OS drive. When i tried to turn on Bitlocker for the OS drive, it gave me only two options to unlock the drive at startup: either to insert a USB flash drive or Let Bitlocker automatically unlock my drive. It didn’t give me the option to Enter a PIN . Can anyone help me with this issue?


You may have forgotten to select the PIN authentication option.

Use these steps to set up a PIN to unlock the drive during startup with BitLocker on Windows 10:

  1. Open Group Policy.
  2. Browse the following path:
    Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives
  3. Double-click the “Require additional authentication at startup policy.
  4. Under the “Options” section, use the Configure TPM startup PIN drop-down menu, and select the Require startup PIN with TPM.
  5. Open Command Prompt (as admin).
  6. Type the following command to add a boot PIN for the drive using BitLocker and press Enter:
    manage-bde -protectors -add C: -TPMAndPIN
  7. Set up the PIN.
  8. Type the following command to confirm the status of PIN and press Enter:
    manage-bde -status

Once you complete the steps, during boot, you should get a PIN prompt to unlock the drive.