P R E - B O O T
Windows can demand a PIN before it starts loading. That is the difference between the stolen laptop is encrypted and the stolen laptop is encrypted and cannot be switched on.
Intune has no built-in way to collect that PIN from the person at the keyboard. This is that missing piece.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#221B33','primaryTextColor':'#EDEAF5','primaryBorderColor':'#5CE1E6','lineColor':'#D81B74','secondaryColor':'#16121F','tertiaryColor':'#1f1a2e','fontFamily':'Consolas, monospace'}}}%%
flowchart LR
U([User at the keyboard]) -->|knows the PIN| W1{{"WALL 1: adding a key protector needs admin rights"}}
I([Intune, session 0]) -->|has admin rights| W2{{"WALL 2: session 0 has no desktop, nothing can be typed"}}
W1 -.->|blocked| X[No PIN]
W2 -.->|blocked| X
manage-bde -changepin called from a Win32 app does not fail loudly. It
silently does nothing, because there is no interactive desktop to prompt on.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#221B33','primaryTextColor':'#EDEAF5','primaryBorderColor':'#5CE1E6','lineColor':'#5CE1E6','secondaryColor':'#16121F','tertiaryColor':'#1f1a2e','fontFamily':'Consolas, monospace'}}}%%
flowchart TB
subgraph S0["SESSION 0 - SYSTEM - no desktop"]
A["Install-BitLockerStartupPin.ps1: TPM, encryption and escrow checks"]
B["Scheduled task, runs as SYSTEM"]
end
subgraph SU["USER SESSION - has a desktop, no admin"]
D["Set-BitLockerPin.ps1: the dialog"]
end
A --> B
B -->|ServiceUI.exe hooks explorer.exe| D
D -->|still SYSTEM, now on-screen| E([PIN applied])
ServiceUI.exe lends session 0 the user's desktop while the process stays
SYSTEM. Admin rights and a keyboard, at the same time.
Order is everything. Add first, verify, and only then remove.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#221B33','primaryTextColor':'#EDEAF5','primaryBorderColor':'#5CE1E6','lineColor':'#5CE1E6','secondaryColor':'#16121F','tertiaryColor':'#1f1a2e','fontFamily':'Consolas, monospace'}}}%%
sequenceDiagram
autonumber
participant D as Dialog
participant V as Volume
D->>V: validate the PIN (nothing touched yet)
D->>V: ADD the TpmPin protector
V-->>D: confirm it exists
D->>V: REMOVE the old Tpm-only protector
Note over D,V: a leftover Tpm protector silently cancels the pre-boot prompt
A TPM-only protector left behind means the device boots straight into Windows and nobody notices the PIN never applied. That is why detection checks for its absence, not just for the PIN's presence.
Without self-service, a forgotten pre-boot PIN is a service-desk job twice over: a recovery key to get in, then an admin to set a new PIN. Now the key is needed once and the user does the rest.
%%{init: {'theme':'base','themeVariables':{'primaryColor':'#221B33','primaryTextColor':'#EDEAF5','primaryBorderColor':'#5CE1E6','lineColor':'#5CE1E6','secondaryColor':'#16121F','tertiaryColor':'#1f1a2e','fontFamily':'Consolas, monospace'}}}%%
flowchart TB
K([48-digit recovery key, once]) -->|past pre-boot, into Windows| S["Start menu: Reset BitLocker PIN"]
S --> G1{{"GATE 1: the user who enrolled the device"}}
G1 --> G2{{"GATE 2: at most 3 resets in 24 hours"}}
G2 --> G3{{"GATE 3: Windows Hello, password if Hello is unavailable"}}
G3 --> P([New PIN, asked for at the next boot])
The recovery key is unavoidable: the reset lives inside Windows, not in pre-boot. Start > Reset BitLocker PIN then opens the window above. Any signed-in user can start it; nothing changes until all three gates pass. Starting the task is not the privilege, passing the gates is.
- Gate 1, the enrolled user. The signed-in Entra account must be the one that enrolled the device. Local accounts and anyone else are refused.
- Gate 2, the throttle. At most three completed resets in a rolling 24 hours. If the history cannot be read, the answer is no.
- Gate 3, Windows Hello. Declining or cancelling stops the reset. The account password is asked for only when Hello is not set up or cannot run, never as a second guess.
A reset is the one flow that must remove before it adds: only one PIN protector
may exist, and the old PIN is unknown. If the new one then fails to land, the
device drops back to TPM-only so it still starts, and the user is told plainly
that it now starts without a PIN. Every gate decision - allowed, denied,
throttled, completed, failed - is an event (3200-3204) in the Application log
under <Org>-BitLockerPin; simply closing the window is only noted in the
local log. The full flow, the events and the
limits: docs/REFERENCE.md, section 9.1.
| Devices | Windows 10 1809+ / Windows 11, x64, TPM 2.0 |
| Join type | Entra-joined or hybrid, so the recovery key can escrow |
| Management | Microsoft Intune |
| You supply | ServiceUI.exe (MDT) and IntuneWinAppUtil.exe, neither redistributed here |
| Tests | 119 passing, touching no BitLocker state |
| Guide | What it covers |
|---|---|
| QUICKSTART.md | Ten steps from a bare repo to a verified pilot device |
| INTUNE.md | Every portal field, and how to stop it fighting your disk-encryption policy |
| BRANDING.md | Your own logo and wallpaper in the dialog |
| TROUBLESHOOTING.md | It is not prompting. Now what? |
| docs/REFERENCE.md | Architecture, design decisions, every knob |
Try it right now. No admin rights, no BitLocker changes, nothing installed:
.\Set-BitLockerPin.ps1 -PreviewUI # the PIN dialog
.\Set-BitLockerPin.ps1 -PreviewNotEncrypted # the "not encrypted" notice
.\Set-BitLockerPin.ps1 -PreviewManage # the self-service reset windowThe dialog ships as an arcade cabinet: violet-black body, CRT phosphor cyan, magenta marquee. Every bit of it is yours to replace.
| Default | With your artwork |
|---|---|
![]() |
![]() |
Three PNGs, no code. Branding is a drop-in, never a dependency: supply none and the window falls back to a wordmark with the same layout. BRANDING.md has the sizes and the wallpaper gotchas.
Everything is namespaced under -Organization (default WK-Hub).
C:\ProgramData\<Org>\BitLockerPin |
payload and logs; SYSTEM + Administrators only |
HKLM\SOFTWARE\<Org>\BitLockerPin |
version and state markers, plus ResetHistory, LastResetOn and ResetCount for self-service resets |
Scheduled task <Org> BitLocker PIN Enrollment |
runs the dialog in the user's session |
Scheduled task <Org> BitLocker PIN Reset |
the self-service reset; no triggers, signed-in users may start it |
Start-menu shortcut Reset BitLocker PIN |
starts the reset task |
Event source <Org>-BitLockerPin |
reset audit events in the Application log; left on uninstall on purpose so past resets stay readable |
HKLM\SOFTWARE\Policies\Microsoft\FVE |
startup-auth values, backed up first and restored on uninstall |
It never writes a PIN to a log, a file or a command line and, outside a PIN reset, never removes a working protector before its replacement is verified.
| Code | Meaning | Intune mapping |
|---|---|---|
0 |
Enrollment mechanism installed | Success |
1618 |
Not ready: encrypting, suspended, or escrow unconfirmed | Retry |
3010 |
Success, soft reboot | Soft reboot |
1 |
Hard blocker: no TPM, missing payload, verification failed | Failed |
0 even when no PIN is set yet is deliberate. This installs the mechanism;
the PIN comes later from the dialog, which re-checks every precondition each run.
Rehearse recovery first. A pre-boot PIN turns a forgotten password into a recovery-key event. Confirm your service desk can find a key in Entra today.
- Pilot with 5-10 devices. Not a ring. Not a department.
- Exclude shared, kiosk and Wake-on-LAN devices. A pre-boot prompt stops unattended boot dead, and self-service reset only trusts the one user who enrolled the device.
- Self-service on Entra-joined devices needs Windows Hello for Business. The password fallback checks the password Windows has cached for the account. A user who has only ever signed in with Hello has none, so even the right password fails with 1326; they can reset only through Hello.
- The Hello gate stops a passer-by, not malware. It protects an unlocked, unattended session. Code already running as the signed-in user is beyond what it can defend against.
- Uninstalling deliberately leaves the PIN in place. Removing a deployment
tool must not quietly weaken a device;
-RemovePinProtectoris the explicit rollback.
MIT, see LICENSE. ServiceUI.exe and IntuneWinAppUtil.exe are
Microsoft's, licensed by Microsoft, and are not distributed here.



