# Issues enabling BitLocker hardware encryption (Windows Encrypted Hard Drive) on AMD 7840

**URL:** <https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415>\
**Category:** Framework Laptop 13\
**Tags:** windows\
**Created:** [November 4, 2023, 3:11pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415 "2023-11-04T15:11:21Z")\
**Posts on this page:** 20\
**Page:** 4

<div class="post-metadata">

**Author:** ![Juan\_Shihfu](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/juan_shihfu/32/20736_2.png) [@Juan\_Shihfu](https://community.frame.work/u/Juan_Shihfu)\
**Post date:** [September 23, 2024, 8:32pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/61 "2024-09-23T20:32:11Z")

</div>

Try “Disable Block SID”

---

<div class="post-metadata">

**Author:** ![Vicky](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/vicky/32/34862_2.png) [@Vicky](https://community.frame.work/u/Vicky)\
**Post date:** [September 23, 2024, 8:50pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/62 "2024-09-23T20:50:40Z")

</div>

Where? If I did find it then I wouldn’t be here to begin with.  
I stated in my post that there are no options to be found.  
This is precisely why this whole topic exists…

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [September 23, 2024, 9:15pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/63 "2024-09-23T21:15:54Z")

</div>

> [@Vicky](#):
>
> Where?

Maybe here (screenshot):

> [@Issues enabling BitLocker hardware encryption (Windows Encrypted Hard Drive) on AMD 7840](http://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/22):
>
> I am experiencing the same issue as @Damian_Edwards when trying to use a Samsung 990Pro’s OPAL2 hardware encryption. In my case the system is a FW13 13th Gen Intel CPU. Following the guides completely, I got Windows 11 installed where it enabled hardware encrypted bitlocker. Upon next boot I am receiving the same Boot Manager message where the UEFI cannot see the drive to boot from. Doesn’t matter whether I have Secure Boot enable and enforced, optional or disabled, the very same issue occur…

---

<div class="post-metadata">

**Author:** ![Vicky](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/vicky/32/34862_2.png) [@Vicky](https://community.frame.work/u/Vicky)\
**Post date:** [September 23, 2024, 9:33pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/64 "2024-09-23T21:33:18Z")

</div>

Well like I said I don’t have this menu at all, that’s exactly what I meant.

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [September 23, 2024, 9:37pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/65 "2024-09-23T21:37:24Z")

</div>

> [@Vicky](#):
>
> Well like I said I don’t have this menu at all, that’s exactly what I meant.

Ah, understood. That’s a bummer then.

Just caught up with the rest of the thread…damn, quiet since December. " We haven’t tested an 990 Pro or another SSD with hardware encryption"…I wonder how enterprise clients are handling this.

---

<div class="post-metadata">

**Author:** ![Alex\_I](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/alex_i/32/30907_2.png) [@Alex\_I](https://community.frame.work/u/Alex_I)\
**Post date:** [November 22, 2024, 8:05am UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/66 "2024-11-22T08:05:44Z")

</div>

+1 it is disappointing to see this bug lingering for over a year.

While it might be not most used feature, it should be quite high on security/privacy scale, and treated as such.

---

<div class="post-metadata">

**Author:** ![kenneb](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/kenneb/32/24737_2.png) [@kenneb](https://community.frame.work/u/kenneb)\
**Post date:** [November 22, 2024, 6:02pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/67 "2024-11-22T18:02:19Z")

</div>

If anyone is curious, 4.06 BETA bios update does not solve the issue for AMD Ryzen 7040 and Samsung 990 Pro (nothing is mentioned in the changelog regarding this issue, so it’s not a surprise)

---

<div class="post-metadata">

**Author:** ![wth](https://avatars.discourse-cdn.com/v4/letter/w/848f3c/32.png) [@wth](https://community.frame.work/u/wth)\
**Post date:** [May 29, 2025, 4:44pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/68 "2025-05-29T16:44:18Z")

</div>

I have the very same issue with Samsung’s 980. My drive is not bootable with hardware encryption enabled. I was using 3.09 BIOS.

---

<div class="post-metadata">

**Author:** ![wth](https://avatars.discourse-cdn.com/v4/letter/w/848f3c/32.png) [@wth](https://community.frame.work/u/wth)\
**Post date:** [May 29, 2025, 4:49pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/69 "2025-05-29T16:49:46Z")

</div>

@nrp a year and a half ago you said the issue is put on the list to look at. Has it been looked at?

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 9, 2025, 2:03pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/70 "2025-08-09T14:03:43Z")

</div>

It’s been a long wait but we might have something here: [Framework Laptop 13 Ryzen 7040 BIOS 3.16 Release BETA](https://community.frame.work/t/framework-laptop-13-ryzen-7040-bios-3-16-release-beta/73325/1) - I’m specifically looking at the issue here: [Cannot boot from partially locked self-encrypting drives · Issue #42 · FrameworkComputer/SoftwareFirmwareIssueTracker · GitHub](https://github.com/FrameworkComputer/SoftwareFirmwareIssueTracker/issues/42)

It isn’t the bug they have open that references this thread, but it does appear to be related. It’s worth testing, at any rate, as it involves how the BIOS interacts with drives using OPAL.

I’ll install the BIOS update soon, and I’ll try to test the encryption when I can - although that’s a more time-consuming task because I have to wipe the drive of course.

---

<div class="post-metadata">

**Author:** ![Quin\_Chou](https://avatars.discourse-cdn.com/v4/letter/q/cdc98d/32.png) [@Quin\_Chou](https://community.frame.work/u/Quin_Chou)\
**Post date:** [August 13, 2025, 8:58am UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/71 "2025-08-13T08:58:26Z")

</div>

We have a solution for the no-boot issue with hardware encryption on **OPAL** devices and will begin implementing it across all products.

Here is the validation steps we did with Samsung 990pro

1. Prepare the SSD  
1.a To get started, install the SSD and have your Windows 11 Pro installation media ready.  
1.b If the SSD was previously locked, perform a PSID Revert and Secure Erase to clean the drive.

2. Clean the SSD during the Windows installation process.  
On the Windows installation screen:  
Press Shift + F10 to open Command Prompt.  
Type:  
-\>diskpart  
-\>list disk  
-\>sel disk 0 (select the disk where Windows will be installed, e.g., Samsung 990 Pro)  
-\>clean (This will erase all data on the disk)  
Close Command Prompt, refresh the installer, and proceed with Windows installation.

3. Verify Encrypted Drive Support  
After completing the Windows installation, install Samsung Magician. Once installed, confirm that “Encrypted Drive” is enabled in the drive information. (This requires an internet connection.)

4. Enable hardware encryption for BitLocker  
-\>Open Edit Group Policy (Run gpedit.msc).  
-\>Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Operating System Drives  
-\>Open “Configure use of hardware-based encryption for operating system drives”.  
-\>Set it to Enabled.  
-\>(Leave additional options as default; no need to select specific encryption types.)

5. Encrypt the drive using BitLocker  
Reboot the system.  
In Windows, right-click Local Disk (C:) → select “Turn on BitLocker”.  
Choose a method to unlock the drive (e.g., Microsoft recommended option).  
Save the recovery key to a secure location.  
Complete the BitLocker setup wizard.

6. Verify encryption progress  
Open Command Prompt as Administrator.  
-\>manage-bde -status  
Confirm:  
Encryption Method: Hardware Encryption  
Percentage Encrypted: 0% (initial state).

7. Reboot and complete encryption  
Restart the system.  
-\>Run manage-bde -status again to confirm:  
Encryption Method: Hardware Encryption  
Percentage Encrypted: 100%

8. Restart the system again to verify that it still boots properly.

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 13, 2025, 1:48pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/72 "2025-08-13T13:48:27Z")

</div>

This is awesome, thank you @Quin_Chou!

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 13, 2025, 1:57pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/73 "2025-08-13T13:57:00Z")

</div>

Also, this is a easy and succinct guide for anyone wanting to use hardware Bitlocker.

---

<div class="post-metadata">

**Author:** ![Scott\_H](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Scott\_H](https://community.frame.work/u/Scott_H)\
**Post date:** [August 14, 2025, 3:38am UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/74 "2025-08-14T03:38:16Z")

</div>

Please update this thread after you’ve had a chance to try it out on your system.

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 14, 2025, 1:04pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/75 "2025-08-14T13:04:48Z")

</div>

I’m hoping to try it this weekend. If I have time…

---

<div class="post-metadata">

**Author:** ![Scott\_H](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Scott\_H](https://community.frame.work/u/Scott_H)\
**Post date:** [August 14, 2025, 1:15pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/76 "2025-08-14T13:15:31Z")

</div>

I hear you. I use the laptop almost daily and the last thing I want to do is go through the reinstall, etc for it to not work…..

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 17, 2025, 3:12pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/77 "2025-08-17T15:12:29Z")

</div>

So… the steps provided by @Quin_Chou did not work. They left the SSD in a weird state where HW bitlocker was enabled, but the drive would not encrypt. I had forgotten about the BLOCK\_SID stuff, it’s been too long - I suspect that not toggling that was what got in the way.

Interestingly, even after a BIOS reset, TPM clear, PSID revert, and secure erase, the BLOCK\_SID and SSD security management options are still missing from the BIOS. I’m currently building a Windows 2 Go stick to try enabling HW bitlocker with the instructions I’d previously used here: [https://blog.odenthal.cc/content/files/2023/04/Hardware-Encryption-on-a-Samsung-980-PRO-SSD-with-Windows-11-using-Bitlocker.pdf](https://blog.odenthal.cc/content/files/2023/04/Hardware-Encryption-on-a-Samsung-980-PRO-SSD-with-Windows-11-using-Bitlocker.pdf) - the example SSD is a Samsung 980 but the directions work the same. I know they work too since I’ve used them on two GPD laptops and a Gigabyte TRX40 motherboard.

The Win2Go stick prep takes forever so I’ll report back with results eventually.

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 18, 2025, 12:50am UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/78 "2025-08-18T00:50:32Z")

</div>

OK. It works. The drive is encrypted in hardware, and survives reboots. As expected, the machine is much snappier and runs cooler. I haven’t had time or baseline benchmarks on this machine for battery life but based on my experiences with other machines I expect it’ll help that too.

I’m not a huge fan of having removed BIOS accessibility of BLOCK\_SID enable/disablement. Doing it via powershell is fine but there’s no confirmation on reboot like there should be - that’s the whole “physical presence” bit.

---

<div class="post-metadata">

**Author:** ![Pouasson](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/pouasson/32/18524_2.png) [@Pouasson](https://community.frame.work/u/Pouasson)\
**Post date:** [August 18, 2025, 12:28pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/79 "2025-08-18T12:28:59Z")

</div>

Thank you so much for taking the time to try for all of us !

What does “will begin implementing it across all products” means in @Quin_Chou‘s message ? Is it ready for me to reproduce if I just use the last BIOS 3.09 ?

---

<div class="post-metadata">

**Author:** ![Ansley\_Barnes](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/ansley_barnes/32/20157_2.png) [@Ansley\_Barnes](https://community.frame.work/u/Ansley_Barnes)\
**Post date:** [August 18, 2025, 1:14pm UTC](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415/80 "2025-08-18T13:14:04Z")

</div>

I suspect “implementing it across all products” means adding the fix to all framework models’ BIOS. This issue was present in the 12th gen intel (that I was able to reproduce) and apparently the others had the same issue as well.

3.09 does not have the fix. 3.16 (for the 7040 series 13” AMD) has the fix.

EDIT: for weird phrasing I noticed much later

[Previous page](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415.md?page=3)

[Next page](https://community.frame.work/t/issues-enabling-bitlocker-hardware-encryption-windows-encrypted-hard-drive-on-amd-7840/39415.md?page=5)
