If the device can boot without a password or PIN, there are some surprising ways to get into it just by switching networks (if network drives are mounted it will sometimes send NTLM hashes), or by good old brute-forcing.
[1] https://blog.kaniski.eu/2020/12/utilman-exe-to-cmd-exe-and-b...
I would guess extracting the keys from the tpm in other ways is not impossible, but probably sufficiently hard to be not worth it in most situations.
is this for real...?
Since the account was a local account, not one signed into a Microsoft account, the Bitlocker keys were not backed up an all data was lost. I was stunned, I've been doing laptop repair for almost 10 years and I've never seen something this stupid.
It's also designed to not be able to be able to extract the key material out of it.
[0] https://news.ycombinator.com/item?id=27655320
[1] https://news.ycombinator.com/item?id=27656144
Can someone on the inside confirm that my using a new chip won't make me unable to boot into my Windows 11 install "Sorry you need your double secret trusted components to use them with our TPM modules, and thus your* software install."
* "Your" meaning ours, licensed to you until we decide to change the license.
Then, in the case of full drive encryption, you'll be asked for the BitLocker recovery key at bootup.
If you used Windows Hello for authentication, that option wouldn't be available - making you have to use your password instead to login.