@GossiTheDog that's one reason why I had a local offline account before upgrading to Win 11 and enabling BitLocker. I then set BitLocker to not trust any TPM chip, even the one in my PC, and force the passcode being needed by default. My recovery media is on an encrypted drive as well, stored off prim.
cyphercryptic_reboot
@cyphercryptic_reboot@defcon.social