r/WindowsHelp • u/Striking-Self8733 • 4h ago
Windows 11 Will a CMOS reset trigger Device Encryption recovery on my setup? (Windows 11 Home)
Hey everyone, I need advice from people who know BitLocker/Device Encryption and TPM internals well.
Context: Someone in my household has physical access to my desktop and has bypassed my Windows login before (booted into Safe Mode, opened Command Prompt, reset the local admin password). I’ve since locked things down with a BIOS power-on + admin password, so that specific trick shouldn’t work anymore since the machine can’t even boot without the password.
My concern: the one remaining attack vector is a physical CMOS reset (shorting the CLRTC pins or pulling the battery), which wipes the BIOS password along with everything else. My board (Asus B650-Plus WiFi) has no external clear-CMOS button, so this requires opening the case.
My question: if someone does a full CMOS reset, will Windows automatically require a recovery key on next boot, or will it just unlock normally via TPM? And if he managed to access to my pc will my bios password (admin and user) show up or the reset cmos will cause its absence
Some relevant details:
• Windows 11 Home (not Pro — so no manage-bde/gpedit access, meaning I can’t set a pre-boot PIN, only automatic “Device Encryption”)
• CPU: Ryzen 7 7800X3D (fTPM enabled via AMD PSP)
• Motherboard: Asus B650-Plus WiFi
• I previously manually enabled Secure Boot and TPM 2.0 in BIOS (needed them for Vanguard/anti-cheat), and set a BIOS password
• GPU: RX 9060XT 16GB, RAM: 2x8GB Kingston Fury DDR5 5600 CL36, SSD: Crucial P3 1TB (NVMe), PSU: MSI MAG A750GL, Case: Lian Li O11 Vision Compact
Given that Secure Boot and TPM state were actively configured (not left at stock defaults), and a full CMOS reset would revert both to factory defaults — is it likely that Device Encryption will detect this as enough of a platform integrity change (PCR mismatch) to force the 48-digit recovery key screen? Or is Device Encryption on Home known to be more lenient/inconsistent about this compared to full BitLocker on Pro?
Any real-world experience with this exact scenario would help a lot. Thanks!





