Hi Damian Kowalik,
From your description, the most likely cause is a Secure Boot or firmware change that BitLocker interprets as a potential tampering event. Even if TPM shows as healthy and ready, BitLocker will trigger recovery if it detects unexpected changes in the boot configuration or Secure Boot policies. The error string you shared aligns with this type of mismatch.
The first step is to confirm that the Secure Boot configuration is consistent across all affected laptops and that no recent firmware or BIOS updates introduced new keys or altered boot policies. If changes were made, re‑enabling BitLocker protection after clearing and re‑establishing the TPM ownership can help reset the baseline. Another option is to suspend BitLocker before applying firmware updates, then resume protection afterward to avoid repeated recovery prompts.
You should also check Group Policy settings related to BitLocker, as certain policies can force recovery if they don’t match the current hardware state. Running manage-bde -status can provide additional insight into the protection state and whether BitLocker is detecting configuration mismatches.
In short, the issue is usually tied to Secure Boot or firmware changes rather than TPM errors. Resetting the baseline by suspending and resuming BitLocker, or re‑establishing TPM ownership, often resolves the repeated recovery prompts.
I hope this gives you a clear path forward. If you find this answer helpful, please consider clicking Accept Answer so others can benefit too.
Jason.