What I want to know is if Not Enabled means not encrypted. I can see the disk being shipped with the encryption enabled but it a bypass state where the TPM always allows access as it waits for that final step, a properly authenticated M$ account or Active Directory account to disable the bypass...