Over 1 million tech questions and answers.

ThinkPad L590 cannot provision Bitlocker during SCCM task sequence

Q: ThinkPad L590 cannot provision Bitlocker during SCCM task sequence

Hello, As mentioned in this post, we're having deployment issues with one of two identical ThinkPad L590s which were ordere in one batch. While the frist device was deployed successfully including a fully working Bitlocker agent, the second machine cannot enable Bitlocker within the SCCM task sequence.In smsts.log the following error information is given:"Failed to run the action: Enable BitLocker. BitLocker Drive Encryption cannot be enabled on the operating system drive. Contact the computer manufacturer for BIOS upgrade instructions. (Error: 80310048; Source: Windows)"After this the only ways to enable Bitlocker at all are either a startup password or using a USB-Stick which is not acceptable and employees will rather leave Bitlocker disabled, which violates our policy. BIOS was upgraded to the latest version (v1.11) but that also didn't help. Any other ideas as to what could be done to preprovision Bitlocker during deployment?

Read other answers
RELEVANCY SCORE 200
Preferred Solution: ThinkPad L590 cannot provision Bitlocker during SCCM task sequence

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

RELEVANCY SCORE 111.6

When trying to test the new T495 we are failing when the task sequence attempts to  setup bitlocker onto the drive it cannot find the Active/enabled TPM 2.0 chip on the system.  When we look at the error it reports no Win32_TPM instance found. Machine is on latest BIOS update that was released on the 26th.  I tried before and after the udpate.  I have ran through different BIOS settings to see if its bad selection choice.  Nothing seems to work.

Read other answers
RELEVANCY SCORE 111.6

We are running SCCM Current Branch version 1706 and ADK 1703.  We just started having issues with the T470 TPM not initializing correctly during the OSD Deployment.  The TPM goes through the Pre-Provision steps without any problem but when we attempt to Enable Bitlocker and send the Key into AD we get "The TPM is defending against dictionary attacks and is in a time-out period." Error Code: 0x80280803 This is not a problem on any other model at this time.  We are also deploying M710s and X270 devices with the same task sequence using the same steps without issue.  Is there a step we need to take on the T470? This task sequence is deploying Windows 7 Machine is in UEFI mode with CSM support.  Secure Boot is disabled and TPM is set to Active version 2.0 Let me know what else you need to help get this resolved. Thanks!

Read other answers
RELEVANCY SCORE 89.6

Does anyone have solution for installing Thunderbolt Driver in the SCCM Task Sequence for ThinkPad P53s and X1 Yoga 4th? I download Intel Thunderbolt Software (Windows 10 Version 1709 or Later) - 10 [64]n2itd03w.exe Using the following commands but doesn't seem to work for me: Extract command:n2itd03w.exe /VERYSILENT /DIR=%PACKAGEPATH% /EXTRACT="YES" Silent Install:%PACKAGEPATH%\n2itd03w.exe /verysilent /DIR=%PACKAGEPATH%\TMP Thank you, Bob 

Read other answers
RELEVANCY SCORE 89.6

when I image a Lenovo Thinkpad T460 with SCCM 2012 task sequence, got a error 0X80004005. other laptop is working normal with same task sequence. only this laptop failed.I upload SMSTSlog at
https://1drv.ms/u/s!Ano3_c6eO3higQhxS_Z6KPaWsm-D

appreciate for any suggestion.

Read other answers
RELEVANCY SCORE 88.8

I see a lot of documentation about running BIOS updates in SCCM with the WINUPTP bios exectuable.  Unlucky for me the M710q seems to use flash2.exe.  I can't find any documentation on exit codes, or successful run sequences.  I've got 200 machines I need to flash by task sequence for quick deploy.  Can anyone help me?

Read other answers
RELEVANCY SCORE 88.8

We have many different models of dell computers and we image with sccm 2012 successfully on all lines BUT we're just getting the 7040 line and they fail upon disk partitioning component of the task sequence. I finally found the proper drivers for the network and now it fails consisitantly on setting disk partition variables.
I have resorted to bypassing all partition info and set it to install the OS to the next available formatted partition (which does exist) and still come up with the same error. 80070002 which is a very generic error. It is not the driver but something to do with the hard drive or maybe the compatibility or even UEFI (which we have set to legacy mode). We are not using UEFI.
The OS is win 7 Enterprise but it never makes it to copying the OS. It fails on the disk partition. they are seagate 500GB drives with 16GB RAM or 8 GB RAM (same with both).

Read other answers
RELEVANCY SCORE 88.8

I work in an organization that over 80% of the PC's we support are Dell Optiplex's. With SCCM, we deploy Windows 7 to these computers through a Task Sequence and that set standard Dell BIOS settings in WinPE using the Dell Command Configure tool. This has worked great for having all our machines in legacy mode, but with trying to move to Windows 10, I want to be able to change the Dell BIOS from legacy to UEFI automatically through the task sequence. I can set the BIOS to UEFI mode, and I can enable secure boot and all the other settings, but for some reason as soon as I restart the computer after making those settings changes, the computer cannot find the hard drive anymore. After the computer reboots, it enables the NIC card for PXE boot, but not the hard drive as shown below.

So here are my basic steps for accomplishing this so far.
1. Reboot computer into Windows PE
2. Format the drive with MBR so I can download the CCTK files
3. copy CCTK files to X:\CCTK
4. Clear and set the Dell BIOS password
5. Activate UEFI Mode
6. Set boot order and all other settings by importing custom ini file.
7. Restart Computer
Attached is my Task Sequence log to be looked at well. Below are my task sequence settings to make the change from legacy to UEFI on Dell Optiplexs. I have tried this on multiple Optiplex 7010's and 7020's with the same results. If anyone has any suggestion on how to change BIOS from legacy to UEFI in a task sequence o... Read more

A:Enable UEFI on Dell Optiplexs using SCCM Task Sequence

So while I understand what you want to do, i'm not sure what you want to do if that makes sense.  I will add my 2 cents in however.  From everything i've read, UEFI uses GPT as the file table for the HDD while BIOS uses MBR.  My first thought would be if you are using UEFI on a hard drive that is formatted to MBR, maybe it cannot read it as a boot drive?  I have heard that UEFI can see it as a file drive, but nothing has been said about booting from MBR if you are using UEFI.  

Read other 1 answers
RELEVANCY SCORE 88.8

I'm trying to automate the process of flashing the BIOS version for all models during a SCCM Task Sequence.with all of them - all is looking great! we run "wflash2x64.exe [filename].rom /ign /sccm /quiet", then initiate a restart task, the BIOS gets updated and the Task Sequence continues. the only issue we have is with M93 and M900 that behaves differently. we downloaded the latest BIOS versions and when we run the restart command it just continues the task sequence without performing the upgrade.if we remove the /sccm from the command, the machine restarts automatically and the BIOS gets updated but then we kill the TS progress and have to start over.I've seen some blogs here and there that talks about using wpeutil shutdown during the task sequence, but corrent me if I'm mistaken, this will also break the whole TS progress... my questions are:1. why these models specifically behaves differently than any other Lenovo model?what's the purpose if the /sccm argument if the admin needs to do other manual steps that aren't listed anywhere officially?P.S - it will also behave that way if we will try to run the flash command from a running operating system and not just from PE 2. maybe I just missed something and there's a more fluent solution for BIOS flashing via a Task Sequence?

Read other answers
RELEVANCY SCORE 88.8

When imaging HP EliteOne 800 G1 All-in-One  (Intel I217-LM NIC) by Windows 10 task Sequence, Domain Join stage fails every time. It was imaged with Windows 8.1 without any issue.  Same task Sequence works on HP 800 Mini (Intel I217-LM NIC) and other system from different vendor. Could I get some help please? Regards

A:windows 10 Task Sequence Not Join Domain (SCCM 2012 R2 SP1)

Hi,  I'm having the same problem for both the g1 800 and G2 800 EliteDesk Mini 35w.  Did you have any luck resolving this?  Thanks.

Read other 1 answers
RELEVANCY SCORE 88.8

Hello everybody,
I'm trying to run tjhis  batch file using a yask sequence on SCCM 2007.The batch file contained the folowing script:
FORFILES /P %WINDIR%\servicing\Packages /M Microsoft-Windows-InternetExplorer-*11.*.mum /c "cmd /c echo Uninstalling package @fname && start /w pkgmgr /up:@fname /quiet /norestart"

The script works find while running it locally but when  i use a task  sequence i have no error message but it doesn't work.This script was supposed to uninstall IE11.But Nothing Happened...
While advertising it,i tried both to download it locally or to run it to the distribution point then run it .But it still failed...
Can you please help me to run this script using a task sequence  in SCCM 2007?

Read other answers
RELEVANCY SCORE 88.8

I am trying to run an OSD task sequence in SCCM 2012 to set the BIOS configuration, enabling TPM and changing to UEFI native mode in preperation for BitLocker, then setting the BIOS password all from within WinPE. The command below runs just fine when logged into the laptop in full Windows 10 from cmd prompt, but for some reason I recieve and error when the task sequence tries to run the command. Using BCU version: 4.0.13.1WinPE 10 x64 version: 10.0.10240.16384  RunBCU.cmd /setconfig:"Config\8570pconfig.repset" /cspwdfile:"Config\oldpassword.bin" /nspwdfile:"Config\newpassword.bin" Where are the log files for the utility?What does error  0x0000000A and 0x0000000B mean?What am I missing? Any assistance would be very much appreciated. Thank you.










Solved!
View Solution.

A:BCU and SCCM 2012 WinPE10 task sequence error 0x0000000A an...

please, look at the following white paper developed to help understand how to manage the TPM and also no the best practices for SCCM  http://ftp.hp.com/pub/caps-softpaq/cmit/whitepapers/Building,%20Deploying,%20and%20Updating%20an%20Image%20on%20HP%20Commercial%20PCs.pdf this and other white papers are available starting with www.hp.com/go/clientmanagement btw, it seems like you should set the BIOS pwd BEFORE you can manage the TPM

Read other 3 answers
RELEVANCY SCORE 88

Hi, I am trying to do a BIOS update when doing an OSD with a Task Sequence. After successfully executing the phase 1 and 2 BIOS update steps, the computer reboots and doesn't complete the remaining task sequence steps. phase 1 step: Flash64.cmd /quiet /sccm /ign /pass:xxxxxxxxxxphase 2 step: wpeutil shutdown The BIOS update and task sequence is done for a "new machine" OSD scenario. Does anyone know how to continue the task sequence? Thanks, Brian

Read other answers
RELEVANCY SCORE 88

Hi All, We are using windows 10 1803 and recently started facing a strange behavior during OSD.While trying installing X1 carbon 6 gen and X280 using SCCM task sequence, Task sequence will hang randomly at some application. Other models are working fine (X260, X270, T460, T470) and issue is only seen on X1 carbon 6 gen and X280. This issue started appearing only from last few days. We are using USB-C dock Gen 1 / Gen 2 while installing these devices and drivers for dock drivers are added in WinPE and Full image. Kindly Assist.

Read other answers
RELEVANCY SCORE 81.6

url for SCCM TSWorking on getting the task sequence together for a consistent imaging process, I've hit a snag with getting the OS to take ownership of the TPM.  I have a url below that I've pulled the task sequence configuration (and can send a picture of my config). How do I get the "take ownership of TPM" done in an automated format. Is there a way? Can any one point me in the right direction. SCCM 1803Imaging Windows 10 1709  https://bondy.tech/?tag=invoke-mbamclientdeployment-ps1

Read other answers
RELEVANCY SCORE 72.4

Have anyone found a way or created a Windows 10 (64-bit) SCCM for Thinkpad X131e ? And if they are not available, can I possibly use the Win 7 SCCM drivers (or Win 8) to use on Windows 10 ? Thank you 

Read other answers
RELEVANCY SCORE 70.4

Hi everyone. I have just got my new Thinkpad L590. But Can't set fingerprint. The same problem with all L590s that Company aquired.  

Read other answers
RELEVANCY SCORE 69.6

Hello, We received two ThinkPad L590s. Both were sent into deployment via an SCCM task sequence. For the first notebook this worked just fine, but the second notebook refuses to boot from PXE (over IPv4) in UEFI. Legacy works fine.Already updated BIOS to R0ZET33W v1.11 (was v1.06). Our network has several subnets, while the PXE server is on a different subnet than the ports we use at our deployment bench. However, this has not been a problem so far. I am still trying to somehow get a glimpse at the error message, if any, whlie attempting to boot from PXE but the screen is cleared so fast I can't see it.  Any ideas on what could be causing this are appreciated.

Read other answers
RELEVANCY SCORE 64

I deploy Windows 7 using SCCM 2012 and enable BitLocker with a PIN 1234.
Will it be possible to enable a PIN change on first usage ? And how ?

Read other answers
RELEVANCY SCORE 62.4

Am super frustrated and would appreciate any help.   ThinkPad X1 6th Gen has been dead more than a week;  OS crashed, but several reboot and repair efforts failed.  Tried system restore.  That required a bitlocker key (which I found online) but then the machine would not accept my account password.  So unable to restore.    Multiple calls with Thinkpad warranty support (hardware and software) could provide no help or guidance.  (Except to send restoration media.)  Mind-boggling lack of support... and no way to escalate issue to someone who actually understood it.  Deeply disappointing experience w/ Lenovo. . So now the question is how -- after I reset my system -- do I avoid this nonsense in the future?   I shouldn't have to rebuild my laptop from scratch anytime there is an OS problem.  BTW, I did not order bitlocker, set up bitlocker or create any password for it.  Do not need it or want it.    Can anyone help with advice on how to set up my machine without it? Thanks.  

Read other answers
RELEVANCY SCORE 56.8

Hello I am unable to deploy the new ThinkPad P50s model via our SCCM 2012R2.- It fails loading our x64 boot image = I assume its a driver related issues. So I downloaded the WinPE 5 64-bit driver from the link below.- But when I try to import the drivers into SCCM it fails with "Unhandled exception..." See the full detail log at the bottom of this post. Anyone who can point me to a working 64bit PXE driver for these P50s, becouse the one below doesnt seem to... https://support.lenovo.com/dk/da/documents/sccm-index?lenovoid.action=uilogin&lenovoid.realm=support... # ERROR Details # See the end of this message for details on invokingjust-in-time (JIT) debugging instead of this dialog box.************** Exception Text **************System.ArgumentOutOfRangeException: startIndex cannot be larger than length of string.Parameter name: startIndexat System.String.InternalSubStringWithChecks(Int32 startIndex, Int32 length, Boolean fAlwaysCopy)at Microsoft.ConfigurationManagement.AdminConsole.Driver.DriverDetailsPageControl.PopulateData()at Microsoft.ConfigurationManagement.AdminConsole.Driver.DriverDetailsPageControl.OnActivated()at Microsoft.ConfigurationManagement.AdminConsole.SmsWizardPage.OnActivated()at Microsoft.ConfigurationManagement.AdminConsole.WizardFramework.WizardPage.Activate()at Microsoft.ConfigurationManagement.AdminConsole.WizardFramework.WizardForm.OnNext()at Microsoft.ConfigurationManagement.AdminConsole.Driver.ImportDriverWiza... Read more

Read other answers
RELEVANCY SCORE 56.8

Hi all,I am having issues with a WMI query for SCCM driver package for Win10. I have no issues with other models just the thinkpad L380. Anyone else got this working? This is the one i am using SELECT * FROM Win32_ComputerSystem WHERE Model like "%20M6S00J00%" Any ideas? Thanks heapsjamie

Read other answers
RELEVANCY SCORE 56.8

Hello there,
I've read the admin guide for DCU and I'm trying to configure OSD task sequence to update the computer when we install the OS.
However, it keeps failing with this error message:
CLI: Error: Check for updates ended. (System Scan Failed)
So when shall I install and update the drivers with DCU during OSD task sequence?
Any help is appreciated!
Thanks.

Read other answers
RELEVANCY SCORE 56.4

Hi All,
I need to deploy a windows 7 image with WDS and MDT 2013. The deployment part is working well  but I would like to set up an Autologin account at the end of the deployment process. In my task sequence in MDT I have set up a task (a command line) like
that :
reg.exe import "My_reg_key.reg"

and it's not working properly. If I run this command line manually it's working well.
The weird thing is if I put a restart task straight after the "autologin" task it will work but the task sequence will never end up as the system can't catch up where the task sequence has been left before the reboot if the user logged in is not
the admin user.

Thanks for your help,

William

Read other answers
RELEVANCY SCORE 55.6

We currently have a task sequence set up for deploying Windows 7 Pro. We have updated the image and captured it. We had previously made quite a few configurations to the task sequence and would like to know if we can simply delete the current image in
the control folder for that sequence and replace it with an updated one? This would save time in configuring a new task sequence all over again. Any assistance would be appreciated. 

Read other answers
RELEVANCY SCORE 55.6

I have a Lenovo p50 which I am unable to get the laptop to image using MDT. I am able to image the laptop from the network using the p50 profile which I created. Does anyone have a p50 thats succesfull in doing an image via flash drive? I am getting a internal fixed errror where the usb drive is being recognized as  hdd and since its removable, the laptop won't image. Thanks

Read other answers
RELEVANCY SCORE 55.6

Hello Everyone.                           I have a TP 600 and my harddisk crashed so I had to get a new one. Now I am trying to install OS onto it, but when I try to change the boot sequence from the BIOS, (pressing F1 on booting and then clicking on the Start Up option) , I am unable to change the start up sequence.I can see that HDD is alloted to the first sequence and I can see other options like CDROM etc, and when I try to select the CDROM option , it doesnt replace the HDD with CDROM as the first sequence.How do I go about this ? I have been researching for almost 2 days with no luck !!Thanks in anticipation,Alex 












Solved!

Go to Solution.

A:Changing the Boot Sequence in Thinkpad 600

alexmat01, welcome to the forum, You need to point the "birdie" at and click on the reset option first (right of top row), this will clear the current boot order. You can then click on the drives in the order you want them to be in the new boot order. i.e. the first drive you click on will be moved into pos. 1, the second into pos. 2 and so on.

Read other 8 answers
RELEVANCY SCORE 55.6

 Hi custormer support, I'm using Thinkpad X260, my laptop will discharge the external battery first then it discharges the internal one. Today I learnt that for T470 laptops and later models, the discharge algorithm becomes smarter, the least worn battery will discharge first to ensure the wear levels are more even. My X260 still discharges the external battery first despite the wear level of external battery is higher than the internal battery's. I'd like to know if the X260 can do the same thing and how to do this? Thanks and regards,afriendP.S.: my bios version is 1.36

Read other answers
RELEVANCY SCORE 55.2

Hi Folks,

I'm having trouble deploying WIndows Embbended 7 POSready by MDT.

The task sequence goes well until apply the WIM image, but after restart nothing happens.

If I manually run the LTItouch script in the C:\minint the task sequence proceeds.

- BDD.log

No value found for AreaCode ZTIConfigure
25/11/2017 23:19:39 0 (0x0000)
No value found for CountryCode ZTIConfigure
25/11/2017 23:19:39 0 (0x0000)
No value found for LongDistanceAccess ZTIConfigure
25/11/2017 23:19:39 0 (0x0000)
No value found for LongDistanceAccess ZTIConfigure
25/11/2017 23:19:39 0 (0x0000)
Updated C:\MININT\Unattend.xml with TimeZoneName=E. South America Standard Time (value was E. South America Standard Time)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with TimeZoneName=E. South America Standard Time (value was E. South America Standard Time)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with KeyboardLocale=Pt-Br (value was Pt-Br)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with KeyboardLocale=Pt-Br (value was Pt-Br)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with UserLocale=Pt-Br (value was Pt-Br)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with UserLocale=Pt-Br (value was Pt-Br)
ZTIConfigure 25/11/2017 23:19:39
0 (0x0000)
Updated C:\MININT\Unattend.xml with UserLocale=Pt-Br (value was Pt-Br)
ZTIConfigure 25... Read more

Read other answers
RELEVANCY SCORE 55.2

 This is a SSD card we install in this Z240 , what i think is happening is when the image is trying to start its not seeing it?  Has anyone had this issue before ?  How do i get the bios to see this card i did do a Hard drive check and it did pass.  I am not sure it is correct . But just thought i could see if anyone here can help?  Thanks  

Read other answers
RELEVANCY SCORE 55.2

I'm using MDT 2013 and WDS.  I want to be able to have custom settings based on the Task Sequence chosen.  For example, if Task Sequence ID 01 is chosen, the PC will join domain A.  If Task Sequence ID 02 is chosen, it will join domain B.
 Currently my CustomSettings.ini file starts with:
[Settings]
Priority=TaskSequenceID, Default
[01]
<Stuff I want to happen during Task Sequence ID 01>
[Default]
<Default actions I want to occur for other tasks>
This is being ignored unless once I choose the task during deployment I open a command prompt, rerun ZTIGather.wsf, then click Back and choose the task again.  I've tried adding ZTIGather.wsf as the first action in the task sequence, but it's not working.
 What's the easiest/best way to customize actions based on the task?

Read other answers
RELEVANCY SCORE 54.4

Hi, I created an SCCM task sequence for a Windows 10 deployment. For one of my scenarios I also need to stage from an USB disk. Both the network and USB staging processes work as expected, except for one specific model in our park (Dell Optiplex 3010).
The phenomenon we observe is that after starting the staging from the USB disk and when the OS deployment and driver installation is completed, the process is supposed to reboot the machine and continue with the next steps of the task sequence. What happens though, is that upon reboot, the process restarts from the beginning. The only way I found to get around this is to remove the usb disk when the machine reboots and plug it back in when prompted.
Which changes do I have to make so that it works on the 3010 as it does on all other models (Optiplex 3020, Optiplex 5040 Optiplex 5050, Optiplex 7020) where it simply works as expected ?
Thanks for your pointers,
Stephane

Read other answers
RELEVANCY SCORE 54.4

I have a Windows 7 custom deployed ISO that I want to update. Unfortunately the original Deployment Workbench and task sequences are no longer available. Is there a way to extract the original task sequences from the existing deployment image?

Read other answers
RELEVANCY SCORE 54.4

Hello,
We have an MDT 2013 SP1 deployment sequence set up for Windows 7 and a range of various laptop models. The issue I am about to describe seems to happen randomly on various models.
The task sequence gets all the way to the first autologin step and just stays on the desktop not doing anything. At this point the final tasks are executed and the summary screen appears, but nothing happens.
I am not able to open anything as i am prompted by a "Windows Security" dialog saying:
These files can't be opened: Your internet security settings prevented one or more files from being opened.
This message appears if i try to run any executable. None of the usual MDT logs are there and I cannot figure out what is stopping the sequence from completing. I have found some references to Windows Defender online but not much info on this problem out
there.

Read other answers
RELEVANCY SCORE 54.4

I have a box I need to capture the install to an image via MDT 2013 - essentially, use MDT 2013 to backup target Windows 7 PC. How do I create a task sequence in MDT 2013 to capture but not sysprep? 
Thanks!

A:How do I create a task sequence to capture but not sysprep with MDT 2013

DISM\MDT is not designed to be used as a backup solution.

Read other 2 answers
RELEVANCY SCORE 54

Does anyone have an answer for this? Our OptiPlex 7040s work fine but 9020s & 9020Ms will not work. The output from SCCM is below: This is for a Windows 10 Task Sequence. The same steps were used for Windows 7 and seem to work fine for Windows 7. Any assistance would bew greatly appreciated.
.. Tpm ownership is alloweduStatus == 0, HRESULT=80280012 (e:\nts_sccm_release\sms\framework\tscore\tpm.cpp,503)Tpm does not have compatible SRKuStatus == 0, HRESULT=80280007 (e:\nts_sccm_release\sms\framework\tscore\tpm.cpp,548)Tpm does not haveEK pairInitial TPM state: 4(dwTpmState & Tpm::State_Enabled) != 0, HRESULT=80004005 (e:\nts_sccm_release\sms\client\osdeployment\bitlocker\bitlocker.cpp,457)InitializeTpm(), HRESULT=80004005 (e:\nts_sccm_release\sms\client\osdeployment\bitlocker\bitlocker.cpp,1313)ConfigureKeyProtection( keyMode, pwdMode, pszStartupKeyVolume ), HRESULT=80004005 (e:\nts_sccm_release\sms\client\osdeployment\bitlocker\bitlocker.cpp,1517)pBitLocker->Enable( argInfo.keyMode, argInfo.passwordMode, argInfo.sStartupKeyVolume, argInfo.bWait ), HRESULT=80004005 (e:\nts_sccm_release\sms\client\osdeployment\bitlocker\main.cpp,382)'IsSrkAuthCompatible' failed (2150105106)'IsEndorsementKeyPairPresent' failed (2150105095)TPM cannot be enabled without physical presence

Read other answers
RELEVANCY SCORE 53.2

Hello,
If I have a reference image that I capture through a regular sysprep & capture task sequence, how do I update my deployment task sequence to reflect this updated reference image once it has been captured? I would prefer not to have to recreate the deployment
task sequence as the current one has several customizations that I would have to redo. When I try to change the OS in the "Install Operating System" step in the sequence to point to the updated image, the deployment will fail with a message such
as: Windows could not parse or process the unattend answer file for pass [specialize]
I don't know how to tell if this is a problem with the unattend file itself or having something to do with changing the deploying operating system in the task sequence.

Read other answers
RELEVANCY SCORE 52.8

Hi all:

I know I can do a script like this to create an admin user account:

net user LocalAdminUsername LocalAdminPassword /passwordchg:no /expires:never /add
net localgroup Administrators LocalAdminUsername /addHowever, is there a way I can customize the password. For example, what if I wanted the password to include information about the computer name or serial number, for example? How can I set a password variable first and then incorporate it into the process (which I could mimic for the username if I desired)?

Read other answers
RELEVANCY SCORE 51.6

My new HP ProDesk 400 G4 Tower i7 8Gb 256SSD arrived with no Wifi provision fitted.

They say I need a dongle.

Can anyone help please?

Sleepyviolet
 

Read other answers
RELEVANCY SCORE 51.2

Hello,  (This has happened on a couple of these new machines) Windows 10 Enterprise.Secure boot disabled, EUFI (both) Legacy firstHarddrive set to first boot devicePXE boot imaged (SCCM)I enabled bitlocker and setup the computer, AD environment, connected it to a dynadock finished machine config. Deployed it to user and a noticed shortly afterwards that upon startup it is asking for recovery key. I suspend/reboot and enabled bitlocker. Reboot asks again for the key. I messed with BIOS settings galore. Finally decrypted cleared keys, took ownership and prepared the TPM. It said it was ready to work but in reduced funtionality?Attempted to encrypt, did the Bitlocker system check, reboot and got the Bitlocker could not be enabled, the encryption key could not be obtained from the trusted platform module. Any advice would be much appreciated.JB 

Read other answers
RELEVANCY SCORE 51.2

Hi everybody, I got a very strange problem which I was unable to solve yet: My ThinkPad Yoga won't work with BitLocker.After initiation of the "BitLocker system test", it boots to the blue "BitLocker screen" - still, the PIN which was set before is not accepted. After cancellation of the test, Windows 8 (Windows 8.1 Update 1) states that the test failed, because the TPM could not be written. While doing some troubleshooting, I recognized that BIOS states the TPM being in "MFG Mode" (= manufacturing mode?); this might be caused by a motherboard change done by the Lenovo service approx. 1 month ago. My question is:Does anybody know how to make the TPM leave "MFG mode" or any other solution to this problem? Thanks in advance!  Best regards, David  picture: sytem infos picture: TPM infos

A:ThinkPad Yoga - BitLocker- / TPM-problem

I noticed this when I had a Yoga returned from repair, the motherboard has been replaced twice, once to cure the original fault, the second time to try to get the chip out of Mfg Mode.The person I spoke to at the IBM hardware call centre hadn't come across this before.The yoga has been decrypted and encrypted again, and totally rebuilt.  In both cases the TPM chip seemed to work.I am trying to work out a way of testing the bitlocker is actually working, i.e. it will ask for a bitlocker key if it detects any interference.I am slightly worried that we are not able to clear the chip.Any input from Lenovo/IBM would be appreciated.

Read other 2 answers