What the guidance says

The NCSC has restated its advice that organisations configure BitLocker with a Trusted Platform Module (TPM) and a PIN. BitLocker encrypts a Windows system drive, while the additional PIN asks an authorised user to authenticate before the drive is made accessible. The advice is about strengthening protection against physical access to a device, not responding to a newly announced incident.

Microsoft distinguishes TPM-only unlocking from TPM with a PIN. TPM-only is convenient because a device can start without user interaction when its integrity checks succeed. Microsoft describes it as less secure than options requiring another authentication factor. With TPM and a PIN, the protected volume cannot be accessed without the PIN, and the TPM provides anti-hammering protection intended to resist repeated guessing.

[1][2]

Why it matters

Full-disk encryption is often treated as a simple enabled-or-disabled control. The unlock method changes what that control can withstand. The NCSC explains that the Windows Recovery Environment must remain available when the main operating system has a problem, creating a useful recovery path but also an area where vulnerabilities have previously affected some BitLocker configurations. Requiring authentication before recovery helps reduce that class of risk.

This is primarily a lost-device and targeted physical-access question. Microsoft says TPM-only protection can suit an attacker of opportunity with limited physical access, while TPM with a stronger PIN is its mitigation for a skilled attacker with lengthy access. That distinction matters: the appropriate setting depends on the data, users, locations and realistic threat, rather than a blanket assumption that every encrypted device has identical protection.

[1][2]

What defenders should do

Start with evidence. Use device management records to identify Windows endpoints with BitLocker enabled, their key protectors and whether recovery information is available to the support team. Separate portable devices carrying sensitive data from fixed or shared machines, then record where TPM-only unlocking is an accepted risk and where pre-boot authentication is required.

Pilot TPM-and-PIN configuration with a representative group before wider enforcement. Test ordinary starts, operating-system and firmware updates, remote support and BitLocker recovery. Microsoft notes that pre-boot prompts can inconvenience users and complicate unattended reboots, while forgotten PINs require access to a recovery key. A stronger setting that strands staff or encourages unsafe workarounds has been deployed badly, not securely.

Where a manual PIN is impractical, document the reason and choose a supported alternative. The NCSC points to BitLocker Network Unlock for suitable corporate-network devices and to a TPM plus startup key in other cases. It also suggests managing the remaining risk through measures such as conditional access. Microsoft says Network Unlock has specific infrastructure and wired-network requirements, so it needs design and testing rather than a casual switch-on.

  • Inventory BitLocker key protectors, not just encryption status.
  • Classify devices by portability, data sensitivity and physical-access risk.
  • Confirm that recovery keys are available to authorised support staff.
  • Pilot TPM-and-PIN settings and test update, restart and recovery workflows.
  • Record and manage exceptions where pre-boot authentication is impractical.
[1][2]

The Beekeeper view

Encryption status is a reassuring dashboard number, but it does not describe the whole control. The useful question is what must happen before a stolen laptop releases the key that protects its drive.

Treat pre-boot authentication as a managed business decision. Set it where the physical-access risk justifies it, prove that recovery works, and give every exception an owner. That produces stronger protection without pretending that one configuration fits every desk, laptop and operational environment.

[1][2]
Check how managed Windows devices unlock BitLocker, match the control to the physical-access risk, and test recovery before requiring pre-boot authentication at scale.

Primary sources

  1. How BitLocker PINs help protect your data and devices — National Cyber Security Centre, 13 August 2026
  2. BitLocker countermeasures — Microsoft, 29 July 2025

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.