It is ON originally and is for encryption. My disk is encrypted by the bit locker and the key is stored by TPM. If the TPM is off, I have to input 48-digit key every boot, which is annoying. Currently, I can only decrypt my disk for convenience.
The bitlocker with TPM is by default for almost...