[SOLVED] How to use BitLocker with Intel PTT?

ithemask

Honorable
Dec 26, 2017
14
0
10,520
I am trying to enable BitLocker disk encryption on the main storage where the OS is installed. According to some websites, that Intel PTT "enables devices to support the trust concepts enabled by hardware-based TPM. Furthermore, it supports all of Microsoft’s requirements for firmware Trusted Platform Module" and "PTT implements the equivalent of a TPM 2.0-compliant Trusted Platform Module within the firmware running on the Intel Management Engine (ME). It provides the benefits of a TPM without actually having one."

I have Z270 chip on my motherboard, and in the UEFI setup I enabled Intel Platform Trust Technology (PTT). Unfortunately, the "Trusted Computing" section in the UEFI setup show "NO Security Device Found". Note that I already have secure boot enabled and CSM disabled along with administrator password to access the UEFI setup and disk converted to GPT.

I am using Intel i5-7600k with motherbaord that have Z270 chip and latest BIOS update. I have already contacted the motherboard support, but with no result. In addition, I cannot find any topic online that talk about enabling BitLocker using Intel PTT on personal computers.

msinfo32 =>
OS Name Microsoft Windows 10 Pro
Version 10.0.17134 Build 17134
BIOS Mode UEFI
Secure Boot State On
PCR7 Configuration Binding Not Possible
Device Encryption Support Reasons for failed automatic device encryption: TPM is not usable, PCR7 binding is not supported, Hardware Security Test Interface failed and device is not InstantGo, Un-allowed DMA capable bus/device(s) detected, TPM is not usable

Screenshots: https://imgur.com/a/zCuX9PD
 
Solution
The motherboard support agent recommended me to flash the same version of BIOS again, I have flashed it but with "Intact Mode" (Since last time I updated BIOS I used the "Fast Mode"), which seems to fix the problem with the "Trusted Computing" section in the UEFI setup and now it shows normal settings of TPM.

BitLocker now detect the Intel PTT, and successfully encrypted the OS drive :D

SC: https://imgur.com/a/E0Qu8ZS

ithemask

Honorable
Dec 26, 2017
14
0
10,520


I know that this option is available, but I wanted to utilize the Intel PTT if available ...
 

Satan-IR

Splendid
Ambassador
Just a thought off the top of my head, might help.

You said you converted the disk into GPT, assuming it was MBR before? How did you install Windows 10 Pro?

If I'm not mistaken for the TPM 2.0 to work properly the Windows must have been installed using a UEFI installation media. Maybe it should be the same for Intel PTT too?
 

ithemask

Honorable
Dec 26, 2017
14
0
10,520


Yes, Windows was installed on disk with MBR. I converted the disk to GPT using mbr2gpt utility in WindowsPE. Should I try to re-install the Windows using GPT?
 

Satan-IR

Splendid
Ambassador


It won't hurt to wait a little bit for other possible replies. If nothing else works and nobody else has any input or hands-on experience to share I'd say it wouldn't be a bad idea.

That is to directly install on GPT using UEFI-ready Windows installation media which I think can be made using utilities such as the Microsoft Media Creation Tool or Rufus etc.
 

ithemask

Honorable
Dec 26, 2017
14
0
10,520
The motherboard support agent recommended me to flash the same version of BIOS again, I have flashed it but with "Intact Mode" (Since last time I updated BIOS I used the "Fast Mode"), which seems to fix the problem with the "Trusted Computing" section in the UEFI setup and now it shows normal settings of TPM.

BitLocker now detect the Intel PTT, and successfully encrypted the OS drive :D

SC: https://imgur.com/a/E0Qu8ZS
 
Solution