• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Join the HP Community Solve‑a‑thon | Help Others & Share Your Solutions | Live on Zoom | 2:30 PM to 2:30 AM IST | Every Wednesday Click here to know more
HP Recommended
ZBook Fury G8

Essentially the same issue described in this thread several years ago. 

 

When using DriveLock on multiple drives, HP's UEFI prompts for a password on every drive, even if the same password is used for all of them, which is unusual and a behavior not found on Dell or Lenovo machines.

 

You might ask, "why not use Automatic DriveLock?". Here's why:

 

According to HP's documentation: When this setting is checked, the BIOS sets a randomly generated user password, sets the master password with the BIOS administrator password, and marks the drive as a member of an Automatic DriveLock group

This is problematic because, in addition to trusting the drive's OPAL implementation, you must now trust HP's UEFI to handle keys in a secure manner as well. Also, should your laptop break, you'll be unable to unlock your drives on a non-HP machine using third-party SED software - even with the BIOS administrator password - because some form of key derivation is apparently involved. I tested this by attempting to unlock the drive using third-party SED software and the cleartext BIOS administrator password, but it was unsuccessful. 

 

I'm not sure whether this is a bug or intended, but I see no reason for the UEFI to prompt for an SED password for every drive if the same password is being used. Also, neither Thinkpads nor Precision devices have this behavior.

 

3 REPLIES 3
HP Recommended

After having analyzed how the firmware handles this, it appears that this behavior is consistent across both current and older ZBook generations and is not a bug. I believe implementing password caching to unlock subsequent drives, similar to the functionality found in ThinkPad and Dell devices, would be a significant improvement without compromising security. Maybe a moderator could forward this feedback to the relevant engineering team?

 

Also, when using Automatic DriveUnlock, the BIOS admin and drive user passwords are stored in the BIOS NVRAM. Since the TPM is not involved, this implementation is rather a basic deterrent and is not going to withstand more sophisticated attacks.

HP Recommended

Hi @frankhub 

 

Welcome to the HP Support Community.

 

Thank you for posting your query.

 

HP's design can be read as more security-conservative, Caching one password to unlock every drive widens the Thank you for the detailed explanation and for sharing your findings regarding HP DriveLock and Automatic DriveLock behavior.

 

I understand that when multiple drives are protected with DriveLock using the same password, the system may still prompt for the password separately for each drive. I also understand your concern about the differences between HP's implementation and the behavior you have observed on Dell and Lenovo systems.

To investigate this further, could you please provide the exact HP product/model and BIOS version where you are observing this behavior? If possible, please also share the DriveLock configuration being used, including whether the drives are SATA/NVMe and whether they support OPAL/SED functionality.

 

Regarding Automatic DriveLock, the behavior described in HP documentation is part of its intended security design. However, questions regarding password handling, key derivation, BIOS NVRAM storage, and interoperability with third-party SED management software would require confirmation from HP's security/engineering documentation rather than assumptions based solely on observed behavior.radius if that single entry is ever captured, whereas separate per-drive entry limits exposure to one drive at a time. 

 

Eliminate Prompts Using Automatic DriveLock (Host System)

If you want all internal drives to unlock seamlessly without repeated POST password prompts:

  1. Turn on/restart the system and press F10 at the HP logo to enter Computer Setup (BIOS).
  2. Set a BIOS Administrator Password under Security > Create BIOS Administrator Password (if not already set).
  3. Navigate to Security > Hard Drive Utilities > DriveLock/Automatic DriveLock.
  4. Select each drive and check the Automatic DriveLock checkbox.
  5. Go to Main > Save Changes and Exit. The host system will now automatically unlock all drives together during POST without asking for passwords.

Use TPM-Backed OS Encryption (e.g., BitLocker)

If you require hardware-bound security without per-drive UEFI prompts or NVRAM-only storage:

  1. Enter BIOS Setup (F10) and disable DriveLock on all secondary drives.
  2. Ensure TPM Embedded Security is enabled under Security > TPM Embedded Security.
  3. Boot into Windows and enable BitLocker on all drives. The TPM automatically handles drive unlocking at boot while maintaining full data protection across secondary drives

 

Click here for detailed steps to Change or remove Drive lock

 

Click here for enabling and Disabling 

 

Hope this helps, Please revert if the issue persists.

 

Take care and have an amazing day!

I'm an HP Employee.


If this reply helped resolve your issue, please select the Accept as Solution as it helps others in the community quickly find the answer they’re looking for.


And if you found this reply helpful, clicking Yes below is a great way to let us know we’re providing the support you need, as it encourages us to keep improving and sharing helpful guidance.

HP Recommended

Hi @Pallipurath

 

Thank you for looking into this.

 

The relevant devices are the HP ZBook Fury G8 (01.25.00 Rev.A) and the HP ZBook X G1i 16 (01.06.05 Rev.A), both of which utilize NVMe OPAL SEDs.

 

As previously noted, Automatic DriveLock is not being employed for security reasons. Instead, manual DriveLock is being used in conjunction with TPM-based OS-level encryption to ensure maximum security. Anyway, the requirement to unlock each OPAL drive individually, three in the G8 and two in the G1i, is proving cumbersome, particularly as this is not an issue encountered with devices from other vendors which typically allow all drives with identical passwords to be unlocked at once. This provides a better experience without introducing any security risk.

† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.
-->