26 points
*
I guess they mean use the password as part of the encryption key, or encrypt the key with the password. Bitlocker doesn’t use the user’s password in that way, which is why it can boot an encrypted system without user interaction. That part always seemed very sketchy to me.
12 points
FYI: You can set it to require a PIN + TPM, or even just a password eg using manage-bde -on c: -password
.
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/manage-bde-on
3 points
Thanks, that sounds really useful. I’m guessing it won’t work unless you’re local admin though.
4 points