Windows 11 Home Device Encryption not available PCR7 binding is not supported Swift 3 SF313-53

Options
CCG
CCG Member Posts: 4 New User
edited November 2021 in Windows 11
Hi,
I have a new Acer Swift 3 SF313-53 which I upgraded to Windows 11. I cannot enable device encryption (I know BitLocker is not compatible with Windows Home but I should be able to use the more basic device encryption in windows 11 home).

When Looking in "system", the "Device Encryption Support" states "Reasons for failed automatic device encryption: PCR7 binding is not supported, Un-allowed DMA-capable bus/device(s) detected, Disabled by policy"

The BIOS has TPM and UEFI both enabled and I assume the laptop support TPM2.0

Can anyone offer advice as to why device encryption is not available on this laptop please?

​//Edited the content to add model name.   ​

Best Answer

  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Answer ✓
    Options
    It does look like Device Encryption should be available in Windows 11 Home. Here are some reasons why it might not be offered to you:
    • PCR7 link not supported: Secure Boot is probably disabled.
    • Unauthorized DMA-compatible device/bus detection: Secure Boot is probably disabled, enable it in the UEFI settings. Otherwise, one of your peripherals exposes your PC to unauthorized access to memory.
    • Hardware Security Test Interface Failed: Your PC has not passed the Hardware Security Test Interface (HSTI) tests which verify if a device is properly configured to use the security features of Windows 11.
    Those are in addition to the potential that TPM isn't installed or enabled... Do you have Secure Boot enabled in the BIOS?
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.

Answers

  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Options
    My guess is Microsoft is closing loopholes in W10 that allowed you to do that with the Home version.
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.
  • CCG
    CCG Member Posts: 4 New User
    Options
    Microsoft does offer encryption on their home product, its essentially a cut down version of bit locker so it's part of their official product offering.
    I am trying to find what is preventing it from working. 
    Thank you for the feedback thoigh
  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Answer ✓
    Options
    It does look like Device Encryption should be available in Windows 11 Home. Here are some reasons why it might not be offered to you:
    • PCR7 link not supported: Secure Boot is probably disabled.
    • Unauthorized DMA-compatible device/bus detection: Secure Boot is probably disabled, enable it in the UEFI settings. Otherwise, one of your peripherals exposes your PC to unauthorized access to memory.
    • Hardware Security Test Interface Failed: Your PC has not passed the Hardware Security Test Interface (HSTI) tests which verify if a device is properly configured to use the security features of Windows 11.
    Those are in addition to the potential that TPM isn't installed or enabled... Do you have Secure Boot enabled in the BIOS?
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.
  • CCG
    CCG Member Posts: 4 New User
    Options
    Thanks billsey, 
    I will have a look at secure boot in the bios. If that's enabled because I don't have any connected peripherals I will have to assume acer just hasn't supported it. Fingers crossed
  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Options
    It shouldn't be an Acer thing, it's all in software and Acer doesn't muck with Windows internal stuff... :)
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.
  • CCG
    CCG Member Posts: 4 New User
    Options
    Hi, 
    I've checked the bios, secure book is enabled so I cannot think of anything else except to upgrade to Windows Pro. 
    Thanks for your help
  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Options
    I run Pro in all mine, but then I have a server in my house for my local domain. :)
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.
  • CraigH
    CraigH Member Posts: 1 New User
    Options
    I'm having the same problem with a Swift SF114-34. Any advice on getting encryption enabled? I haven't had any problem with HP Envy or Asus laptops
  • billsey
    billsey ACE Posts: 31,779 Trailblazer
    Options
    Are you also running Windows 11 Pro, @CraigH?
    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.