Find the Secure Boot option and change it to Disabled. Save the changes and reboot again. We recommend keeping Secure Boot enabled unless you're sure it needs to be disabled. This article explains how ...
If you use an add-on TPM module ($25ish), rather than using the chip's built-in emulator, I don't think you lose your Bitlocker key when you do a BIOS update. You just have to remember to switch the ...