I am setting up a brand new machine with the above drive and have installed a discrete TPM 2.0 header on the motherboard to allow me to use hardware encryption with BitLocker. Windows 10 Pro x64 1903 is in use.
I installed Windows and Samsung Magician 6.0 and switched on drive encryption within the Encrypted Drive part of the tool. It shows "Ready to Enable" as a status. I create the Secure Erase tool, but the tool cannot find the drive. Going back into Windows I updated the drive's firmware to 2B2QEXM7. I reboot and run Secure Erase. The drive is successfully detected and the tool reports that it completed successfully. On rebooting the computer cannot detect bootable media, indicating success.
I disable Legacy USB and CSM support in UEFI, then boot my Windows 10 USB installer. The drive is showing as empty, no partitions. I create a single disk partition (with Windows creating its standard recovery partitions) and finish the install.
After booting into Windows I install Samsung Magician, but Encrypted Drive is still reporting the drive as "Ready to Enable" rather than "Enabled". I try repeating the Secure Erase and installing Windows process, but the status is still "Ready to Enable".
I've done this previously (on a different computer) with a Samsung SS 840 EVO, but did not encounter this problem. At this point I am not sure what more I can do. It would seem that Secure Erase is not flipping whatever switch it is supposed to, but it's not reporting any errors and is erasing the drive. The Windows 10 install is on a completely fresh drive.
I have this problem too. I bought SSD M.2 Samsung 970 EVO Plus and I can't enable hardware encryption. Status of my SSD is "ready to enable". Also I Have 970 PRO and on the same PC is hardware encrypted and work correctly as bootable disk. I asked ASRock (motherboard factory) about this problem. But they tell me about good work of hardware encryption of 970 Evo Plus ( they send me screenshot with the same PC: same motherboard, same BIOS, same CPU). But I see one thing. ASRock use 970 Evo plus with firmware 1B2QEXM7 and older Samsung Magician, but I use firmware 2B2QEXM7 and new Samsung Magician 6.0. I think problem with firmware 2B2QEXM7 and Samsung must to update firmware of 970 EVO Plus. What do you think about it, Samsung?
Under the old firmware, I couldn't get Secure Erase to see the drive.
I contacted Samsung support regarding this issue, but got no where. They are blaming the motherboard (an ASUS PRIME X570-P) and suggesting that it may not support hardware encryption for an NVME device, but ASUS say that it does. Samsung also pointed me at Microsoft, though I'm not sure what it is to do with them in this instance.
So basically I'm stuck in software encryption at the moment as everyone says it's not them.
You are lucky. I bought SSD with new firmware and I can't dawngrade this firmware. I wrote to Samsung, but they are silent. Very awful support of Samsung.
Can you test speed of SSD with software encryption in crystaldiskmark? I want to check speed with software encryption and without encryption.
I'll drop them a line, but steps to do this isn't a problem, I've done it before on my 840 Evo. Multiple times in fact. Still, let's see if they have a fresh perspective.
I can clarify a few things here.
First you don't need a motherboard that supports Bitlocker eDrive to change the SSD state from "ready to enable" to "enabled".
I have a Asus Prime X570-PRO motherboard and faced the exact same issue. The motherboard supports hardware encryption, but when it comes to enabling it in the samsung SSD, I am not sure what is happening. I had to put the SSD on another computer (a HP 820 G3 - that does not support bitlocker hardware encryption - and after doing a secure erase on that laptop the Encrypted Drive status switched to Enabled.
Changed the drive back to my Asus motherboard, and was able to install windows and enable Hardware Encryption using bitlocker. Had to set the Group policy to require hardware encryption and enable the fTPM.
But there is a problem changing the Encrypted drive status to enabled. And the drive doesn't require a motherboard that supports bitlocker eDrive to do it.
I performed a PSID revert, and tried to enable the Encrypted Drive on the Asus motherboard again, but it won't do it. I can only do it on my HP 820 G3 that doesn't even support that feature.
BTW is not just Asus, I have the exact same problem on a HP 830 G5 that does support Bitlocker eDrive, but after doing a secure erase it won't change from Ready to Enable to Enabled.
I don't know if it's a Samsung problem, but it happens on completely different motherboards.
My SSD is a 970 Evo Plus btw