Event ID 24625 — BitLocker Startup
Applies To: Windows Server 2008
When a computer protected with BitLocker Drive Encryption is restarted, the early startup components perform a series of integrity checks and, if the system passes, attempts to retrieve the needed key information to unlock any BitLocker-protected volumes. Success depends on the availability of configured key protectors, such as the TPM or a user-supplied PIN, and the existence of volume metadata stored within the encrypted drive.
If Windows cannot unlock the Windows operating system volume, BitLocker enters recovery mode. If the user can supply a recovery password or insert a USB flash drive with a recovery key, BitLocker will unlock the volume.
After the Windows operating system volume has been successfully unlocked, BitLocker uses encrypted information stored in the volume metadata and Windows registry to unlock any data volumes configured for automatic unlocking.
Event Details
Product: | Windows Operating System |
ID: | 24625 |
Source: | Microsoft-Windows-BitLocker-Driver |
Version: | 6.0 |
Symbolic Name: | FVE_KEYRING_KEY_OBTAINED |
Message: | A valid key was found during the last restart. |
Resolve
This is a normal condition. No further action is required.