Windows
BitLocker was blocked by a conflicting startup authentication policy
BitLocker was not resuming because a Group Policy required a USB drive at startup. The authentication policy was adjusted, BitLocker resumed normally, the recovery key was saved to Entra ID, and a test file save did not trigger another BitLocker prompt.
Killed once by someone from XL.net, on 2026-07-21.
Affects
Apps
- BitLocker
What you see
- Unfamiliar BitLocker/encryption notifications
- BitLocker prompting as if startup authentication needed a USB drive
Why it happens
Likely A conflicting Group Policy required a USB drive at startup, which prevented BitLocker from resuming normally.
When it shows up
A Windows PC shows unexpected BitLocker or encryption notifications and BitLocker is blocked by startup authentication policy.
You are in this case if:
- BitLocker startup authentication requires a USB drive
- Group Policy is enforcing BitLocker USB startup authentication
1 fix below
The steps that killed it
The steps are behind a quick check
There are two ways in and both take a few seconds. Signing in opens the steps on every bug page; so does reading the picture.
Or answer this
Drawing a picture for you.
Can't read it? Sign in instead.
Someone from XL.net killed this on a Windows computer on 2026-07-21. It is written up from that one repair, so it cites no outside page.