like 2 password you need to enter as oppose to 1 password. Does that make sense? Because I want letters as well in the pin since without it, the pin would be all numbers? I don't see a elevenforum link to this part? But all you have to do is click on that and just click Enabled and that is all?
Yes, you want your own kind of 2 step verification before your computer will login. It is highly unusual for anyone to want to go to such extreme security measures at each logon, but as
@Brink posted, it can be done. Do not confuse your account pin/password with your bitlocker pin/key. They are 2 separate things, each independently handled by the TPM.
If you choose to use bitlocker, I agree with
@TraderGary (post 43). You are much safer tying this bitlocker key to your Microsoft account in case it is ever forgotten.
The way I see it,
@Brink gave you the solution in his post #21. You have to do what it says in BOTH tutorials he listed. And yes, to use letters in bitlocker pin you would have to Allow enhanced PINs for startup in group policy as you mentioned.
if I was to instead use the original microsoft account and log in to that account, would I need to remove mcafee and install windows updates again or not?
No. Once a computer is updated, it stays updated. When you uninstalled McAfee, it was completely removed for all users.
Maybe my take on having 2 accounts will offer some clarification for you. You
do not have to have 2 accounts. If you do not want 2, remove one of them. However, like some others here, I have 2 myself (one MS and one local).
Here's the reason I have 2 accounts. 1) It's just there as a means to get into the computer if for some reason I'm ever locked out of my main account and 2) it is a means of troubleshooting if I ever have account related issues in my main account.
If you choose to keep both accounts, the second account would NOT be used on a daily basis. You would have to choose which account you would consider to be your main account since files created in either account are not directly accessible from the other as file permissions prevents it. This is because files are owned by whatever account creates the file.
If you have enabled 'require bitlocker pin before logon' using either local group policy method or the reg file method Brink listed in post #21,
ANY user account on the machine will have to enter the bitlocker pin to logon.