secure boot pcr7

About this tag
The secure boot pcr7 tag covers discussions about BitLocker recovery prompts triggered by Windows 11 security updates, specifically KB5083769 from April 2026. The issue occurs on systems with a specific combination of TPM, Secure Boot, and BitLocker policy settings, where the update causes a boot-time lockout requiring recovery key entry. Microsoft's documentation ties the condition to Secure Boot PCR7 measurements, which are part of the TPM validation process. The tag includes troubleshooting guidance such as using Group Policy changes or Known Issue Rollback to prevent or resolve the recovery prompt. This is relevant for IT administrators managing BitLocker-encrypted devices with Secure Boot enabled.
  1. KB5083769 Can Trigger BitLocker Recovery on Reboot (April 2026 Windows 11)

    Windows 11’s April 2026 security update is doing something far more alarming than just taking a long time to install: on a narrow set of systems, it can trigger a BitLocker recovery prompt at the next reboot. Microsoft has now documented the issue in KB5083769 and says the condition is tied to a...
  2. KB5083769 Windows 11 April 2026: BitLocker Recovery Prompts & Multiple Reboots

    Microsoft’s April 2026 Windows 11 cumulative update, KB5083769, is shaping up to be one of those Patch Tuesday releases that looks routine on paper but still manages to unsettle administrators and consumers in practice. Microsoft has now confirmed a BitLocker recovery prompt issue affecting a...