Explanation We need to allow Windows BitLocker Drive Encryption on all client computers (including client computers that do not have Trusted Platform Module (TPM) chip). We can do this by enabling the option to allow BitLocker without a compatible TPM in the group policy. The "Allow BitLocker without a compatible TPM" option is a checkbox in the "Require additional authentication at startup" group policy setting. To access the "Allow BitLocker without a compatible TPM" checkbox, you need to first select Enabled on the "Require additional authentication at startup" policy setting. Reference: https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settin