Unsolved
1 Rookie
•
11 Posts
4
3209
Disable Dell Security Manager Password Prompt With Bitlocker Hardware Encryption eDrive
My Dell Precision 5560 is setup with a Samsung 980 Pro with eDrive IEEE1667 SED hardware Bitlocker encryption, a subset of the TCG Opal standard. Everything works great and there is no performance loss as it does hardware encryption.
I am aware of the potential security risks associated with using hardware encryption. Security researchers did not find fault with an earlier Samsung 840/850 Evo when used in TCG Opal mode.
Source: https://www.ru.nl/publish/pages/909282/draft-paper.pdf
The one snag is that the laptop detects that the drive is SED enabled and shows a Dell Security Manager password prompt at every reboot. It does not actually understand the encryption standard being used and entering a password will not work. It also does not care if Bitlocker is temporarily suspended or not. One must hit Cancel, Esc, or let it timeout after about 10 minutes. After which the laptop will proceed to load the Bitlocker PBA and allow the user to successfully enter the password.
This makes running the laptop in headless mode a headache as anytime it restarts for updates even with Bitlocker suspended it will take at least 10 minutes to timeout at reboot.
How does one disable this "feature" (bug)? If it cannot be disabled, then can the timeout be reduced to 30s?
DSM Password Prompt On BootHitting Esc Makes DSM Go AwayBitlocker PBA Prompt Appears Afterwards
DELL-Cares
Moderator
Moderator
•
25.9K Posts
0
December 21st, 2022 18:00
Thank you! We have received the required details. We will work towards a resolution. In the meantime, you may also receive assistance or suggestions from the community members.
ltctech
1 Rookie
1 Rookie
•
11 Posts
0
December 21st, 2022 18:00
Related Threads:
https://www.reddit.com/r/Dell/comments/zs9s2n/disable_dell_security_manager_password_prompt/
https://www.reddit.com/r/Dell/comments/w24cqt/anyone_with_a_modern_xpsprecision_using_bitlocker/
Bitlocker Hardware Encryption Status
M120
1 Rookie
1 Rookie
•
24 Posts
0
January 10th, 2023 06:00
Definitely a bug. Shouldn't happen. Can we expect a fix for this?
ltctech
1 Rookie
1 Rookie
•
11 Posts
0
January 10th, 2023 16:00
@DELL-Cares will you assign a Dell engineer to reproduce the issue and fix your faulty firmware?
ltctech
1 Rookie
1 Rookie
•
11 Posts
1
January 11th, 2023 12:00
@DELL-Cares Thank you for the following useful DM:
Yes, I am still able to boot. I am using a standards compliant NVMe drive that supports the IEEE1667 encryption standard. A standard which Dell laptops support but unfortunately hamper with Dell Security Manager. This is not a sales issue.
Here is another thread that talks about the same exact issue:
https://www.dell.com/community/XPS/XPS-9520-Edrive-SED-support/td-p/8269387
ltctech
1 Rookie
1 Rookie
•
11 Posts
1
January 13th, 2023 02:00
@DELL-Cares Reply to your DM below:
1. The BIOS was defaulted and reconfigured before Bitlocker was enabled.
2. There are no BIOS passwords of any type configured. The Dell BIOS erroneously recognizes eDrive IEEE1667 SED hardware Bitlocker encryption, a subset of the TCG Opal standard as a "password".
More info about the standard here:
https://learn.microsoft.com/en-us/windows/security/information-protection/encrypted-hard-drive
We have three machines that are setup the same way and have the same annoying prompt at each boot. There are multiple people here and Reddit reporting this exact issue.
Has anyone been assigned to investigate this firmware bug?
ltctech
1 Rookie
1 Rookie
•
11 Posts
0
January 13th, 2023 13:00
@DELL-Cares
Thank you for being concerned about the privacy of my information. However, I am not posting any sensitive information.
ltctech
1 Rookie
1 Rookie
•
11 Posts
0
January 15th, 2023 21:00
@DELL-Cares
The SSD is third-party hardware. And it works without issue.
However, there still remains a firmware bug in Dell's UEFI firmware that fails to properly recognize IEEE1667. In fact, Lenovo ThinkPad laptops do not have this issue with this exact same drive.
Maybe I'm approaching this from the wrong angle...
How does one disable the Dell Security Manager UEFI prompt? Can the timeout for the Dell Security Manager UEFI prompt be reduced from 10 minutes to 30 seconds? If this is currently not supported, can a feature request for this functionality be opened?
ltctech
1 Rookie
1 Rookie
•
11 Posts
1
January 16th, 2023 16:00
@DELL-Cares
I'll be waiting for a BIOS update that fixes this issue.
M120
1 Rookie
1 Rookie
•
24 Posts
1
January 20th, 2023 06:00
Can confirm. This only happens on my XPS. It's a bit problematic because there's no reliable way to use self encrypting drives on my Dell machine. Dell's own SED password feature is not an option because If the machine breaks, there is no way to unlock the SSD without a notebook of the same model.
DmitryP
1 Rookie
1 Rookie
•
30 Posts
0
April 12th, 2023 06:00
Updated XPS 9710 BIOS to 1.19.0 released on 07 Apr 2023. This issue still remains unfixed.
firefox15
1 Message
2
September 1st, 2023 16:41
Same issue on my Precision 3581 with the latest BIOS. Super frustrating and it's really the final piece here keeping me from using hardware encryption.
For kicks, I took the drive out of my Dell and put it into my new HP. The HP also prompted me for a password on boot-up that I had to press ESC to bypass. The difference is that there is a setting in the HP BIOS called "Allow OPAL Hard Drive SID Authentication." When this checkbox is checked, no password is required, and the drive can still be seen (and decrypted) by Windows To Go without an issue.
It would seem that HP has figured this out while Dell has not. I don't understand why they cannot do this. Something is clearly wrong if a password prompt is being shown when there is no password needed.
(edited)
M120
1 Rookie
1 Rookie
•
24 Posts
0
September 17th, 2023 11:54
How is it that Dell hasn't been able to fix this issue for more than a year, especially since both XPS and Prescision users are affected.
cheerful_man
1 Rookie
1 Rookie
•
30 Posts
0
September 27th, 2023 21:32
XPS 9730 same problem. @DELL-Cares please let us know if the problem is going to be resolved.
(edited)
M120
1 Rookie
1 Rookie
•
24 Posts
0
November 7th, 2023 19:52
An Intel NUC user had the same issue 5 years ago but unlike Dell, Intel released a fix two months later. Here we are, years later..
(edited)