
Critical BitLocker Issues Impact Windows 10 Following May 2025 Updates
Recently, concerns surrounding BitLocker encryption have extended from Windows 11 24H2 to Windows 10, affecting users following the latest Patch Tuesday updates released in May 2025 (KB5058379, KB5058392, KB5058383, and KB5058387).Users across various major hardware manufacturers, including Lenovo, Dell, and HP, have reported encountering the BitLocker recovery screen upon system reboot post-installation.
A Widespread Bug Affecting Enterprise Environments
This issue predominantly targets enterprise PCs managed through Intune, WSUS, and SCCM. It represents the second significant bug affecting enterprise users within the same month, following a prior issue that disrupted the installation of the Windows 11 2024 update on devices running versions 22H2 and 23H2.
User Concerns and Experiences
One user, known as mersongeorge, raised a concern on Microsoft forums with the thread titled “May 13 – KB5058379 Windows 10 leads to corruption and endpoints asking for BitLocker key.”They explained that the update has caused multiple devices to trigger the BitLocker key prompt after a restart, with many users experiencing a cycle of continuous reboots. The issue seems to affect those utilizing Lenovo ThinkPad devices significantly, causing additional frustrations such as keyboard malfunctions that hinder users from entering their BitLocker recovery keys.
Microsoft Acknowledges the Issue and Offers Solutions
Fortunately, Microsoft has acknowledged the issues resulting from update KB5058379, including restart loops, update failures, and prompts for BitLocker recovery. The tech giant is currently offering workarounds. Notably, Intel-based models, such as the Dell Precision 5570 and 5680, have been confirmed to have this problem. A contributor named Callum Hargreaves2 verified these experiences on the forums. Preliminary investigations from Microsoft suggest a connection to Intel’s Trusted Execution Technology (TXT), prompting the recommendation to disable this feature in the BIOS as a potential fix.
Steps Users Should Take
The following recommendations have been provided for users experiencing these issues:
Next Steps & Recommendations:
- Pause updates on impacted devices to prevent further complications.
- If your device requires BitLocker recovery, use the recovery key and revert the update as a temporary solution.
- Consider disabling TXT in the BIOS; however, note that remote access may be necessary, making it less practical for extensive deployments.
- Microsoft is committed to documenting these issues on the Windows Release Health and Microsoft 365 Admin Center portals and will provide updates as new information becomes available.
Understanding Intel’s Trusted Execution Technology (TXT)
For those unfamiliar, Intel’s TXT is a security feature integrated into Intel processors and chipsets. Its primary function is to defend computers against software attacks by assuring that applications operate within a secure, isolated environment. This hardware-based security system employs various mechanisms, including Intel PTT (often referred to as TPM) and Secure Boot, to ensure data integrity and security.
Leave a Reply