Using a PIN mitigates many BitLocker vulnerabilities. Make sure you’re ready for the next one...
Design Pics/Darren Greenwood via Getty Images
The NCSC provides guidance on how to securely configure Microsoft Windows. This includes setting up BitLocker, which encrypts your device to protect the data and the operating system from tampering. Our guidance recommends that BitLocker be configured to require a PIN before decrypting your device.
However, many organisations use BitLocker without a PIN, leaving their devices vulnerable. In this blog we explain why a PIN is so important, and what to do if – for whatever reason – you can’t use a PIN.
Breaking BitLocker: vulnerabilities and WinRE
BitLocker has been under increased public scrutiny in recent months, as vulnerabilities like YellowKey made headlines. By using the Windows Recovery Environment (WinRE), YellowKey was able to bypass certain BitLocker configurations, potentially decrypting drives that should have been protected. Whilst this issue was quickly patched, the severity of this finding left many concerned about the security of BitLocker.
What is often missed in discussions around YellowKey is that it is not a new type of vulnerability; bugs in WinRE have been used to bypass BitLocker for years. Preventing these sorts of attacks is one of the reasons why NCSC guidance has always encouraged using a BitLocker PIN. And despite the hyperbolic descriptions of YellowKey’s author likening it to a backdoor, Microsoft have been very public about this. In 2025, Microsoft found and patched four very similar bugs, presenting them at the security conference BlackHat along with a blog explaining how these vulnerabilities work and how to protect against them. If I were trying to hide something, that’s certainly not how I’d start.
The NCSC guidance recommends configuring BitLocker to require a PIN, which mitigates the YellowKey vulnerability. The underlying question though, is why do attacks like this keep happening? If WinRE is such a threat to BitLocker, why hasn’t it been fixed?
The answer is that this problem is as much about conflicting design principles as it is about individual bugs. WinRE exists to ensure that you can retrieve your data even if something goes wrong. To do this, BitLocker deliberately does not encrypt the files associated with WinRE (because an issue with BitLocker might be the reason you need to recover data). This absence of encryption leaves a gap that can be used by exploits such as YellowKey, and as long as that design decision remains in place, vulnerabilities like YellowKey will continue to be found.
This is why configuring BitLocker to require a PIN is so crucial. Requiring a user to authenticate before using WinRE helps to protect an element of Windows that is uniquely exploitable. In this respect, using BitLocker without a PIN will always be a half measure; it is only a matter of time before new vulnerabilities are discovered in an operating system as large as Windows. YellowKey was not the first time WinRE was used to bypass BitLocker, and it will not be the last.
What if I can’t use a PIN?
The NCSC appreciate that there will be cases where using a PIN is not practical. For example:
- where multiple users access the same device (such as in a ‘hot desking’ office)
- where a device is used in time-critical emergencies, so the extra seconds in takes to type in a PIN cannot be spared
- where a device needs to boot without human interaction (such as in a dangerous environment)
Whatever the reason, if you can’t manually enter a BitLocker PIN in your deployment, some of the risk can be mitigated using a number of techniques:
-
Use the same PIN
If the only barrier is that users can’t remember a PIN, consider using the same PIN for Windows Hello and BitLocker. This isn’t practical for shared devices with multiple users, but otherwise it provides considerably more protection than not using a PIN, with nothing new for users to remember.
-
Use Network Unlock
If a device is mostly used on a corporate network, consider using Network Unlock. This BitLocker feature allows you to skip the PIN prompt by reading the key from a trusted network. If the device is disconnected from that network (for instance if stolen), then the user will be asked for a PIN. Depending on your environment, this may remove almost all of the PIN prompts you would see whilst still providing a greater degree of protection than not using a PIN. For desktop devices, this is often the best option.
-
Create a Startup Key
A spare USB stick can be turned into a Startup Key, which can provide a different kind of pre-boot authentication. A physical key like this can be lost or stolen, and users with multiple devices may struggle to keep track of several keys. But otherwise, this is a good option. If you do choose to use Startup Keys, ensure that you configure BitLocker to require both the TPM and the Startup Key (as all Windows 11 devices have a TPM).
-
Conditional access
Finally, if there is no way to add pre-boot authentication to your device, consider how you are going to manage that additional risk. For example, you may wish to use conditional access policies to prevent these high-risk devices from accessing sensitive resources.
Don’t do nothing
Ultimately, you will be best positioned to determine the least disruptive way to protect devices that do not currently use a BitLocker PIN. But whatever you do, don’t do nothing. When it comes to BitLocker vulnerabilities, there will be a next time. Make sure you’re ready for it.
Facts Only
* The NCSC provides guidance on securely configuring Microsoft Windows, including setting up BitLocker encryption.
* Guidance recommends configuring BitLocker to require a PIN before decrypting the device.
* Vulnerabilities like YellowKey used the Windows Recovery Environment (WinRE) to bypass certain BitLocker configurations.
* Bugs in WinRE have been used to bypass BitLocker for years.
* BitLocker deliberately does not encrypt files associated with WinRE due to recovery needs.
* Requiring a PIN before using WinRE protects an element of Windows uniquely exploitable by exploits like YellowKey.
* Options when a PIN cannot be used include: using the same PIN for Windows Hello and BitLocker, using Network Unlock, creating a Startup Key via USB, or implementing conditional access policies.
Executive Summary
BitLocker requires a PIN to mitigate vulnerabilities such as those exploited via the Windows Recovery Environment (WinRE), particularly concerning flaws like YellowKey. The National Cyber Security Centre (NCSC) guidance recommends configuring BitLocker to require a PIN for enhanced security. This configuration addresses concerns stemming from inherent design decisions, as the lack of encryption for WinRE files leaves an exploitable gap. Requiring a PIN before accessing WinRE is presented as crucial for protecting this element of Windows.
When PIN usage is impractical, mitigation strategies exist. These include using the same PIN for Windows Hello and BitLocker, leveraging Network Unlock to bypass prompts on trusted networks, utilizing Startup Keys stored on USB drives, or implementing conditional access policies to restrict access to high-risk devices. The core message is that while a PIN is recommended, layered protection techniques should be considered when practical barriers exist, emphasizing that inaction leaves devices vulnerable to evolving threats.
