Windows 10: PCR7 binding not possible/encryption issues

Discus and support PCR7 binding not possible/encryption issues in Windows 10 Gaming to solve the problem; I tried enabling encryption of the file explorer to be able to lock certain folders the other day and now i can not download anything from the xbox app... Discussion in 'Windows 10 Gaming' started by AcrylicFrigate, Mar 11, 2025.

  1. PCR7 binding not possible/encryption issues


    I tried enabling encryption of the file explorer to be able to lock certain folders the other day and now i can not download anything from the xbox app for pc. It says that my drives are not encrypted.In System Information my BIOS mode IS set to: UEFIPCR7 reads: Binding not possibleAutomatic Device Encryption Support reads: Reasons for failed ADE: PCR7 binding is not supported, Hardware Security Test Interface failed and device is not Modern StandbySecure Boot IS enabledI have verified TPM is available and reads as working,The command Confirm-SecureBootUEFI reads as true on all drives,The com

    :)
     
    AcrylicFrigate, Mar 11, 2025
    #1
  2. LShel42 Win User

    PCR7 Configuration Binding Not Possible

    I've got Windows 10 Home, Version 10.0.18363 Build 18363. I haven't been having any specific problems, but tonight I looked at my System Information and on the Summary page I noticed a couple of entries that I really don't understand.

    • PCR7 Configuration Binding Not Possible
    • Device Encryption Support Reasons for failed automatic device encryption: PCR7 binding is not supported, Hardware Security Test Interface failed and device is not Modern Standby, Un-allowed DMA capable bus/device(s) detected
    Do I have a problem that I'm unaware of? Should I be concerned? What do I do to fix it if necessary? Would appreciate some expert guidance here. Thanks.
     
    LShel42, Mar 11, 2025
    #2
  3. BitLocker error - PCR7 binding is not supported

    Hello,



    I have an issue with BitLocker not working and advising "PCR7 binding is not supported"

    I've undertaken extensive research on the internet to resolve the issue and drawing a blank.

    (This laptop was previously using BitLocker without issue prior to me wiping the system and doing a clean install)



    When attempting to enable BitLocker on a HP Elitebook G3 1030 running Windows 10 Pro the following error message is receive following reboot.



    "BitLocker could not be enabled.

    The data drive specified is not set to automatically unlock on the current computer and cannot be unlocked automatically.

    C: was not encrypted"



    This error message occurs only when I configure BitLocker with the "System Check." (Checking the box when it asks).

    The error message is received after reboot.

    If I do not select the System Check, it works, but it prompts the user every single reboot to input the recovery key.



    Apparently if BitLocker keeps asking for Recovery key at startup even after multiple attempts, one is trapped in a recovery key loop.

    You may enter a BitLocker recovery key loop if your device TPM is configured to use PCR (Platform Configuration Register) values that are not the default values (PCR 7 & PCR 11) to which BitLocker binds.



    Initial efforts to resolve the situation included:



    • Clear the TPM via the BIOS
    • Removing all partitions on the hard disk using Parted Magic
    • Clean re-install of Windows 10 via Microsoft website installer
    • Reset of the BIOS settings
    • Reinstalling the latest BIOS update
    • Verifying in the BIOS that Secure Boot is ENABLED

    Following this I executed the advice from this Microsoft forum to reset TPM protectors

    https://learn.microsoft.com/en-us/a...cker-drive-encryption-the-data-drive-specifie

    Basically this involved using command prompt to issue the following commands

    1. "manage-bde -protectors -delete c: -t TPM"
    2. "manage-bde -protectors -add c: -tpm"

    Unfortunately this did not resolve the problem



    Issuing the command "manage-bde -protectors -get c:" Reveals that my system is relying on PCR 0, 2, 4, 11 instead of PCR 7, 11



    When running "System Information" as administrator the following key information about my system was returned

    BIOS Mode = UEFI

    Secure Boot State = On

    PCR7 Configuration = Binding Not Possible

    Device Encryption Support = Reason for failed automatic device encryption: PCR7 binding is not supported.



    This website had some useful suggestion that were followed. PCR7 Binding Is Not Supported in Windows 11/10? [Fixed] - MiniTool

    Step 1 = I ran "tpm.msc" and it advises "The TPM is ready to use"

    Step 2 = The BIOS is configured with UEFI enabled and the system disk partition style is GPT

    Step 3 = Secure Boot State = On (as per "System Information")

    Step 4 = 4 In command prompt I ran the command "powercfg /a" and receive the message back

    "The following sleep states are available on this system:

    Standby (S0 Low Power Idle) Network Connected

    Hibernate

    Fast Startup"



    When opening Event Viewer and selecting "Applications and Services Logs -> Microsoft -> Windows -> BitLocker-API -> Management" it lists a string of events with mostly alternating Event ID's as follows:

    Event 834 (Information) - BitLocker determined that the TCG log is invalid for use of Secure Boot. The filtered TCG log for PCR[7] is included in this event.

    Event 816 (Warning) - BitLocker cannot use Secure Boot for integrity because the TCG Log for PCR [7] contains invalid entries.



    Out of desperation, I reached out to Microsoft support and one week later I'm still waiting for the next level of suport to contact me.



    Does anyone have any advice of what else I can try to resolve this BitLocker issue?
     
    Sherminator 2, Mar 11, 2025
    #3
  4. Zolock Win User

    PCR7 binding not possible/encryption issues

    PCR7 Configuration Binding Not Possible

    Wanting to encrypt my drives, and seeing the same message, I purchased a TPM module and installed it. It is enabled, was cleared, but I'm seeing the same binding not possible message. I would like fix it. Any idea?
     
    Zolock, Mar 11, 2025
    #4
Thema:

PCR7 binding not possible/encryption issues

Loading...
  1. PCR7 binding not possible/encryption issues - Similar Threads - PCR7 binding possible

  2. PCR7 binding not possible/encryption issues

    in Windows 10 Software and Apps
    PCR7 binding not possible/encryption issues: I tried enabling encryption of the file explorer to be able to lock certain folders the other day and now i can not download anything from the xbox app for pc. It says that my drives are not encrypted.In System Information my BIOS mode IS set to: UEFIPCR7 reads: Binding not...
  3. PCR7 Binding not possible

    in Windows 10 Gaming
    PCR7 Binding not possible: I am running Windows 11 23H2 with an Asus B760 motherboard. Why do I see this message?And why S0 sleep state is not available?powercfg /availablesleepstates The following sleep states are available on this system: Standby S3 Hibernate Fast Startup The following sleep states...
  4. PCR7 Binding not possible

    in Windows 10 Software and Apps
    PCR7 Binding not possible: I am running Windows 11 23H2 with an Asus B760 motherboard. Why do I see this message?And why S0 sleep state is not available?powercfg /availablesleepstates The following sleep states are available on this system: Standby S3 Hibernate Fast Startup The following sleep states...
  5. PCR7 binding was possible and now it suddenly is not - but everything works properly

    in AntiVirus, Firewalls and System Security
    PCR7 binding was possible and now it suddenly is not - but everything works properly: Hello everyone! I have an odd question regarding PCR7 binding not supported and mysterious Device Encryption Support for new desktop PCs using Windows 10 Pro for home use. I am using Secure Boot and all of the security features e.g., Virtualization & Code Integrity, but not...
  6. PCR7 binding was possible and now it suddenly is not - but everything works properly

    in Windows 10 Gaming
    PCR7 binding was possible and now it suddenly is not - but everything works properly: Hello everyone! I have an odd question regarding PCR7 binding not supported and mysterious Device Encryption Support for new desktop PCs using Windows 10 Pro for home use. I am using Secure Boot and all of the security features e.g., Virtualization & Code Integrity, but not...
  7. PCR7 binding was possible and now it suddenly is not - but everything works properly

    in Windows 10 Software and Apps
    PCR7 binding was possible and now it suddenly is not - but everything works properly: Hello everyone! I have an odd question regarding PCR7 binding not supported and mysterious Device Encryption Support for new desktop PCs using Windows 10 Pro for home use. I am using Secure Boot and all of the security features e.g., Virtualization & Code Integrity, but not...
  8. Device standard encryption - PCR7 binding issue

    in AntiVirus, Firewalls and System Security
    Device standard encryption - PCR7 binding issue: I've windows 10 Home edition, build 19042. I want to encrypt my drives, but in system information, under encryption support, this message is shown: Device Encryption Support Reasons for failed automatic device encryption: PCR7 binding is not supported, Hardware Security Test...
  9. PCR7 Configuration Binding Not Possible, Bitlocker event IDs 813, 834

    in AntiVirus, Firewalls and System Security
    PCR7 Configuration Binding Not Possible, Bitlocker event IDs 813, 834: In our office we are trying to swap over from using McAfee's encryption tool to managing Bitlocker via Workspace One formerly Airwatch. I was able to successfully apply Bitlocker to two Lenovo models T470s. After those worked, I pushed the same profile over to a test T480s....
  10. PCR7 Configuration Binding Not Possible

    in Windows 10 BSOD Crashes and Debugging
    PCR7 Configuration Binding Not Possible: I've got Windows 10 Home, Version 10.0.18363 Build 18363. I haven't been having any specific problems, but tonight I looked at my System Information and on the Summary page I noticed a couple of entries that I really don't understand. PCR7 Configuration Binding Not...