I have a Fujitsu P728 laptop that I created a image for a few month ago (Win10-1709).
This unit/Image does not have encryption enabled on it at all.
Recently I got a the same model Fujitsu P728, and noticed out-of-the box, the drive has encryption enabled and is on Win10-1803.
I checked and Bitlocker is waiting for activation on the unit.
manager-bde -status shows 100% encrypted.
For testing..
I tried to move this HDD into another shell (Same "newer" P728 model), but it would not boot to Windows. I got a Bitlocker error
I have a few question hopefully I can get answers on...
1) is this normal to get a Bitlocker error when moving a encrypted drive that does not have Bitlocker truly enabled with a PIN to another
shell?
1b) Can I bypass this by Clearing the TPM in the BIOS?
Now the tricky ones..
I was able to take my master image that I created with the "Older" P728 that never had any encryption going on, and deploy this to the newer P728's. They immediately start encrypting on first boot (Nothing in my unattend.xml has encryption settings).
2) What is enabling this encryption when the "Image" and "Master Machine" never had encryption enabled?
3) I was able to swap the drives between machines once they had my "Master Image" on them.
So this appears as though encryption really is not working at this point?
Is this a TPM setting within windows which is allowing the drives to be swapped? Possibly a conflict with TPM and Bitlocker provisioning?
Any help would be appreciated! Thanks