Enable and Activate TPM for BitLocker Pre-Provisioning in WinPE

I have to say this one caught me out. I’m just setting up a task sequence to deploy Windows 8 and pre-provision BitLocker (which is wicked fast by the way!) and got caught with enabling and activating the TPM from WinPE.  The solution I came up with works for me, on a Samsung Series 7 Slate but might not work for all hardware vendors (TPM is a little tricky like that).

The process turned out to be pretty simple.

  1. Download the EnableBitLocker.vbs script from MSDN.
  2. Copy the file to my Configuration Manager 2012 SP1 Site Server.
  3. Edit the file and change the reference to “setup.exe /s” and “setup.exe /r” (shutdown and reboot in full Windows) to “wpeutil shutdown” and “wpeutil reboot” respectively. I did this because WinPE doesn’t include shutdown.exe but instead uses wpeutil to do the same(ish) thing.
  4. Created an Application Management package containing only the EnableBitLocker.vbs script and distributed it to my DPs.
  5. Added a Run Command Line task to my Windows 8 deployment task sequence, after Restart in Windows PE and before Pre-provision BitLocker.
  6. PXE booted and deployed my task sequence to my target machine.

The final effect takes advantage of Windows 8’s used space only encryption and starts encryption before the OS is even deployed, encrypting as the OS deploys – the net result is a fully encrypted machine within minutes!

Don’t forget to download Windows Server 2012, System Center and Windows 8 Enterprise to try this out and take a look at my other posts on System Center.

Comments (5)

  1. Anonymous says:

    Hi, can this be implemented for MDT or is this strictly for SCCM2012SP1

  2. Carlito Castillo says:

    Hi, I looked for both to “setup.exe /s” and “setup.exe /r” but could not find it so I can edit. Can you assist?

  3. K says:

    I believe he is referencing the shutdown.exe commands and not setup.exe

  4. edi karsidi says:

    If your goal is to enable bitlocker in windows, it's easier if you use EASEUS partition master professional to hide and unhide your drive. You can also add a password to enter the Application EASEUS, so that can not be accessed by unauthorized users.

  5. show box says:


    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?
    For more info on showbox please refer below sites:
    Latest version of Showbox App download for all android smart phones and tablets.
    It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.
    For showbox on iOS (iPhone/iPad), please read below articles:
    Showbox for PC articles:
    There are countless for PC clients as it is essentially easy to understand, simple to introduce, gives continuous administration, effectively reasonable. it is accessible at completely free of expense i.e., there will be no establishment charges and after establishment
    it doesn’t charge cash for watching films and recordings.
    Not simply watching, it likewise offers alternative to download recordings and motion pictures. The accompanying are the strides that are to be taken after to introduce Showbox application on Android. The above
    all else thing to be done is, go to the Security Settings on your Android telephone, Scroll down and tap on ‘Obscure sources’.
    Movie Box, an esteemed movies application in which you can find stacks of programs and films. The guide is given here to download Movie Box app to Android and to Apple iOS 9.0.2, iOS 8.4/8.3 and also for the lower versions without Jailbreak.
    Please do login to Showbox application with the help of Ymail. You can login in Ymail from here –
    Sign Up & Do registration for latest movies on Showbox applic

Skip to main content