We manage Dell laptops with BitLocker enabled and ThreatLocker application and DNS controls. Over the past two months, seven systems have become unusable after Windows updates or Dell Command Update runs. In some cases, the laptop powers on with a lit screen but never shows the Dell logo. Holding the power button for about 30 seconds allows BIOS recovery to appear, but settings such as Secure Boot may be disabled and the machine then enters a reboot loop. Dell's recovery tools sometimes repair the partition or boot configuration, but usually the system has to be wiped and reloaded. Other systems repeatedly cycle through BitLocker recovery and Windows startup. Even with the recovery key, Windows Recovery may crash and reboot again. Offline SFC and DISM attempts have not resolved the issue, and SupportAssist repair is inconsistent. We are trying to identify a common cause involving BIOS updates, Windows updates, BitLocker, ThreatLocker, TPM or Secure Boot, and find a reliable repair process that avoids a full reinstall.
3 Answers
Collect the Windows Update and Dell Command Update logs from an affected drive before wiping it. The useful locations include the Windows Update log directory and Dell’s UpdateService log directory. Comparing the last installed BIOS, firmware, driver, and Windows packages may reveal whether the failures follow a particular release. Updating the BIOS before deploying Windows may also help if the laptops arrived with an older firmware version.
With seven machines affected, I’d treat this as a shared update or configuration problem rather than unrelated hardware failures. Compare the exact BIOS versions, Windows updates, Dell Command Update releases, TPM state, Secure Boot state, and ThreatLocker policies on working and failed systems. Preserve the BitLocker recovery keys before changing BIOS or disk settings, and consider pausing the suspected update path until you find a pattern.
A long power-button hold can do more than discharge residual power; on some Dell systems it can trigger a hardware or BIOS reset. That may explain why recovery becomes available afterward and why Secure Boot settings appear changed. SupportAssist has also been associated with unexpected BitLocker recovery prompts. If entering the recovery key only returns to the same screen, the issue is likely deeper than BitLocker itself, such as damaged boot files, firmware state, or a failed update. Capture logs and test one machine offline before doing another wipe.
The recovery keys are available, but entering one causes another crash and reboot back to the BitLocker screen. We have also tried disabling BitLocker from WinPE and running Windows Recovery tools without success. The 30-second reset is currently necessary on systems that do not even reach the Dell logo, although we are testing a recovered production laptop in more detail.

I found documentation describing Dell Latitude and Precision systems getting stuck in a boot loop after a BIOS update, so that is one possibility. I’m still comparing the affected machines to determine whether the same BIOS or update version is involved.