The existing automatic booting feature creates a copy of the system's encryption key that is stored on the disk. If the feature "Prevent automatic booting when the disk is moved between (UEFI) systems" is not used, the key is stored on disk in plain-text form. With the TPM autoboot feature, Drive Encryption uses TPM to encrypt this file.
The file can only be decrypted on the system that encrypted it and only if the boot path is unmodified from when it was encrypted. This makes sure that only the specific TPM can decrypt the file, and moreover (like SecureBoot) ensures that malware has not changed the boot path. A combination of TPM encryption and boot path measurements allow the user to securely bypass Pre-Boot Authentication (PBA) through to Windows logon, where user authentication occurs.
Note
Any software update that changes the boot path, like a Microsoft update to the UEFI bootloader will result in pre-boot being displayed since the boot path has changed, and therefore the disk encryption key cannot be unsealed. For example, PBA will be shown when an Operating System is upgraded from Windows 10 to Windows 11.
Drive Encryption uses TPM Platform Configuration Registers (PCRs) 0, 2 and 4 to measure the boot path and shows the PBA when the measurements of the PCRs are modified.
Here are descriptions of the individual registers:
Platform Configuration Registers (PCRs) | Description |
|---|---|
PCR 0 | Core root-of-trust for measurement, EFI boot and run-time services, EFI drivers embedded in system ROM, ACPI static tables, embedded SMM code, and BIOS code. |
PCR 2 | Option ROM code. |
PCR 4 | Master Boot Record (MBR) code or code from other boot devices. |
When autoboot is enabled, we also recommend enabling password synchronization capabilities.