Bit Locker Guide
Bit Locker Guide
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 1
3. Configure TPM platform validation profile Set to Enable, and use the recommended defaults except for PCR 10: Boot Manager. BitLocker gets unhappy if you have that option selected, particularly if the system goes into hibernation. It will usually ask for a recovery password when the system wakes from hibernation, or on reboot.
Now configure the corresponding applicable options for fixed data drives and removable data drives under Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Fixed Data Drives and Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Removable Data Drives respectively.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 2
6. Under permissions - select Full Control, and click next. 7. Click Finish.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 3
Using BitLocker with a computer that has TPM v1.2 hardware is highly recommended. The computer is limited to booting with a USB Flash drive containing the BitLocker information if it does not have TPM v1.2 hardware. The following procedure assumes the existence of TPM v1.2 hardware. BitLocker also requires two separate partitions. If the computer is not already set up for this, you may use the BitLocker Drive Preparation Tool to allocate an additional partition for this purpose. See http://support.microsoft.com/kb/930063 for more information. The required size of this drive has been reduced to 100MB in Windows 7. 1.5GB is needed in Windows Vista.
Enabling BitLocker
1. 1. Launch BitLocker Drive Encryption from the Control Panel, or from searching in the Start Search box. 2. If the User Account Control prompt appears, verify that the displayed action is what you requested, and then click Continue. 3. Click Turn on BitLocker.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 4
4. At this point you may choose to Use BitLocker without additional keys, Require a PIN at every startup, or Require Startup USB key at every startup if your group policy settings permit these options. 5. You will now be able to save or print the password if your group policy settings permit these options. 6. Click Run BitLocker system check (recommended), and then Continue - The computer will reboot and will begin encrypting if successful. 7. Log in and verify disk encryption is in progress. The encryption process will take several hours depending on the speed of the machine, however the computer may be used as normal. If a computer is shut down or rebooted, it will continue encrypting once it is powered on again.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 5
10. If the User Account Control prompt appears, verify that the displayed action is what you requested, and then click Continue. 11. 12. Click Manage BitLocker Keys. 12. 13. Click Duplicate the recovery password. 13. 14. Click Save the password in a folder - The default network location will appear if youve specified that with a policy; otherwise you can navigate to the location of your choice.
Using an Encrypted Drive on a Windows 7 Client 1. Insert the removable drive. A window will appear stating This drive is protected by BitLocker Drive Encryption... Enter the password that was specified in step 2 above. Alternatively, it can be unlocked using the recovery key by clicking I forgot my password. If you wish, you may also select Automatically unlock on this computer from now on to avoid having to type the password in each time. Click Unlock after all of the required information is provided, and you will be able to use the drive normally. Using an Encrypted Drive on a Windows Vista or XP SP 3 Client 1. Insert the removable drive, and open it in Windows Explorer. Launch the BitLockerToGo.exe program located on the removable drive. You'll notice a bunch of other files that were placed on the drive when BitLocker encrypted the drive. Do not modify or delete any of the files. They are needed to access the encrypted data on the drive. 2. Enter the password for the removable drive. 3. You can now drag files or folders from the BitLocker To Go Reader to your a location on your computer in order to open them. Alternatively, double clicking on a file will also give you the option of copying a file to your desktop. Caution: Any files copied to another computer are no longer encrypted when they are copied off of the removable drive unless that computer's drive(s) are also protected by BitLocker or other disk encryption software.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 7
1. Launch BitLocker Drive Encryption control panel. 2. Click Unlock Volume (Volume F: in this case) on the encrypted volume that youre recovering the data from.
3. Select method of enter the BDE recovery password Loading from removable media, or manual input.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 8
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 9
4. The drive is now temporarily unlocked and available to Windows to recover data. You may now also turn off BitLocker completely and decrypt the drive that was just unlocked through the BDE control panel.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 10
Method Two BitLocker Repair Tool 1. Download BitLocker Repair Tool and copy the appropriate ..\x86\executables, or ..\x64\executables to local location. e.g. - c:\repairbde. 2. Attach empty external storage (Volume G: in this case) This particular process will completely overwrite the G: volume. 3. Open an elevated command prompt, and use repair-bde. 4. In this case: c:\repairbde\repair-bde F: G: -rp [recovery password] lf c:\repairlog.txt 5. After the process is complete, the decrypted contents of the volume (F:) will be copied to the external volume (G:) . You may also send the output to a windows .img file. 6. Use repair-bde /? for a full set of options. For additional data recovery methods using BitLocker Repair Tool see: http://support.microsoft.com/kb/928201.
University of Minnesota - College of Education and Human Development Last Revised February 16, 2010 by Tom Ruddle Page 11