Difference between revisions of "Bitlocker"

From ITSwiki
Jump to: navigation, search
[quality revision][quality revision]
Line 6: Line 6:
  
  
<big>Bitlocker is a Windows feature that encrypts data on all fixed drives (i.e. C:). The encryption protects data from unauthorized access in the events of theft or lost equipment.</big>
+
Bitlocker is a Windows feature that encrypts data on disks. At DTU Compute only local (internal) disks will be encrypted (i.e. C :). Encryption protects your data against unauthorized access in the event of theft or loss of hardware.
  
  
=Which computers are Bitlocker encrypted?=
+
=Which computers are encrypted with Bitlocker?=
  
Only laptops installed at DTU Compute IT support will have Bitlocker activated. Laptops installed before February XX, 2021 will not have Bitlocker automatically activated.
+
Only laptops installed at DTU Compute IT support will have Bitlocker enabled. Laptops installed before February XX, 2021 will not automatically have Bitlocker enabled.
  
If "DTU Software Center" is found in the Start menu, it can be activated manually by IT support on request. If it doesn't have "DTU Software Center", the laptop has to be reinstalled before Bitlocker can be activated.
+
If "DTU Software Center" is found in the Start menu, Bitlocker can be manually enabled by IT support on demand. If there is no "DTU Software Center", the laptop must be reinstalled before Bitlocker can be enabled.
  
  
=How can I check if Bitlocker is activated?=
+
=How to check if Bitlocker is enabled or encrypting?=
  
If Bitlocker encryption has not finished when you receive the laptop from IT support, the encryption should start within 2 hours, but only if if you have logged on while either on campus or connected to DTU network through VPN.  
+
If the Bitlocker encryption has not been completed when the laptop is received from the IT support staff, the encryption should start within 2 hours, but only if you log in on campus or connect to the DTU network via VPN.
  
The encryption process begins automatically through an automated network profile update, without the need for user interaction. You should not experience any changes, but you might notice a temporary message either as a popup or in the Message Center.  
+
The encryption process starts automatically without user interaction. You should not experience any changes, but you may see a temporary message in a pop-up window or in the Message Center.
  
 
The encryption does not require the laptop to be connected to the network once it has commenced.
 
The encryption does not require the laptop to be connected to the network once it has commenced.
Line 28: Line 28:
 
   
 
   
  
You will be able to work as normally during the Bitlocker encryption. If the laptop is shutdown or goes into sleepmode during the encryption, the process will resume the next time you turn on the laptop and login.
+
During Bitlocker encryption, you will be able to work normally. If the computer is powered off or enters sleep mode during the encryption process, the next time you turn on the computer and log in, the process will resume.
  
If you are unaware if Bitlocker is already active on your laptop, you can open "This PC" and check for a padlock icon on your C: drive. If present, it indicates that the drive is encrypted.
+
If you don't know if Bitlocker is already enabled on your laptop, you can open "This PC" and check the padlock icon on the C: drive. If it exists, it means the drive is encrypted.
  
  
Line 36: Line 36:
  
  
You can check the status of the encryption process in the Control Panel -> Bitlocker Drive Encryption.
+
You can check the status of the encryption process in Control Panel Bitlocker Drive Encryption.
  
  
Line 44: Line 44:
  
  
If upon booting your laptop you are prompted with the "Bitlocker recovery" screen and the message "enter the recovery key for this drive" you will need to contact IT support to get your recovery password.  
+
If when you start your laptop, you are prompted with the "Bitlocker Recovery" screen and the message "Enter the recovery key for this drive" is displayed, then you need to contact IT support to obtain the recovery password.
  
After entering the password, you should be able to boot normally. After booting and logging in, you should restart your computer to verify that the Bitlocker Recovery screen does not occur a second time.
+
After entering the password, you should be able to boot normally. After booting and logging in, the computer should be restarted to ensure that the Bitlocker Recovery screen does not appear the second time.
  
 
If it does, this could indicate a problem with your laptop's configuration that should be addressed by IT support.
 
If it does, this could indicate a problem with your laptop's configuration that should be addressed by IT support.
  
 
==Recovery screen instructions==
 
==Recovery screen instructions==
# Contact DTU Compute IT support from another device or phone. You will be asked for the first 8 characters in the Recovery Key ID shown on the screen and your DTU login name.
+
# Contact DTU Compute IT support from another device or phone. You will be asked to provide the first 8 charactersof the Recovery Key ID displayed on the screen and your DTU login name.
# IT support will retrieve the 48 characters long Recovery key that must be typed into the textbox on the Recovery screen.
+
# IT support will retrieve the 48-character recovery key, which must be typed in the text box on the "Recovery" screen.
# You should be able to boot into Windows. Restart the laptop to verify the Bitlocker recovery screen does not occur a second time.
+
# You should be able to start Windows. Restart the laptop to ensure that the Bitlocker recovery screen does not appear a second time.
* In some cases these steps are also needed:
+
 
# After logon go to Control Panel -> BitLocker Drive Encryption
+
In some cases, these steps are also required, but it's best to follow them every time just to be sure:
# Click "Suspend protection" option next to the C: drive
+
# After logon go to Control Panel BitLocker Drive Encryption
# Click "Yes" to the "Do you want to suspend BitLocker protection?" and now wait a few minutes
+
# Click on "Suspend Protection"
# Click the "Resume protection" option to update BitLocker TPM.
+
# Click "Yes" to the "Do you want to suspend BitLocker protection?" Now wait a few minutes
 +
# Click on "Resume protection" to update BitLocker TPM.
  
  
Line 64: Line 65:
  
  
=What causes Bitlocker to ask for recovery key?=
+
=What causes Bitlocker to request the recovery key?=
  
It can be caused by many reasons for example: hardware changes, BIOS changes (i.e. disabling Secure Boot), motherboard replacement, malware attack, hard drive crash, system crash, or the program believes the data might be under attack.
+
There may be many reasons, such as hardware changes, BIOS changes (i.e. disabling secure boot), motherboard replacement, malware attacks, hard drive crashes, system crashes, or the program believes that data may be attacked.
  
 
[[Category:DTU]]
 
[[Category:DTU]]

Revision as of 11:29, 18 February 2021

UNDER CONSTRUCTION


MBAM-banner-2.jpg


Bitlocker is a Windows feature that encrypts data on disks. At DTU Compute only local (internal) disks will be encrypted (i.e. C :). Encryption protects your data against unauthorized access in the event of theft or loss of hardware.


Which computers are encrypted with Bitlocker?

Only laptops installed at DTU Compute IT support will have Bitlocker enabled. Laptops installed before February XX, 2021 will not automatically have Bitlocker enabled.

If "DTU Software Center" is found in the Start menu, Bitlocker can be manually enabled by IT support on demand. If there is no "DTU Software Center", the laptop must be reinstalled before Bitlocker can be enabled.


How to check if Bitlocker is enabled or encrypting?

If the Bitlocker encryption has not been completed when the laptop is received from the IT support staff, the encryption should start within 2 hours, but only if you log in on campus or connect to the DTU network via VPN.

The encryption process starts automatically without user interaction. You should not experience any changes, but you may see a temporary message in a pop-up window or in the Message Center.

The encryption does not require the laptop to be connected to the network once it has commenced.


MBAM-1.jpg


During Bitlocker encryption, you will be able to work normally. If the computer is powered off or enters sleep mode during the encryption process, the next time you turn on the computer and log in, the process will resume.

If you don't know if Bitlocker is already enabled on your laptop, you can open "This PC" and check the padlock icon on the C: drive. If it exists, it means the drive is encrypted.


Padlock-C-Drive.png


You can check the status of the encryption process in Control Panel → Bitlocker Drive Encryption.


Bitlocker recovery screen

Bitlocker-recovery-info.jpg


If when you start your laptop, you are prompted with the "Bitlocker Recovery" screen and the message "Enter the recovery key for this drive" is displayed, then you need to contact IT support to obtain the recovery password.

After entering the password, you should be able to boot normally. After booting and logging in, the computer should be restarted to ensure that the Bitlocker Recovery screen does not appear the second time.

If it does, this could indicate a problem with your laptop's configuration that should be addressed by IT support.

Recovery screen instructions

  1. Contact DTU Compute IT support from another device or phone. You will be asked to provide the first 8 charactersof the Recovery Key ID displayed on the screen and your DTU login name.
  2. IT support will retrieve the 48-character recovery key, which must be typed in the text box on the "Recovery" screen.
  3. You should be able to start Windows. Restart the laptop to ensure that the Bitlocker recovery screen does not appear a second time.

In some cases, these steps are also required, but it's best to follow them every time just to be sure:

  1. After logon go to Control Panel → BitLocker Drive Encryption
  2. Click on "Suspend Protection"
  3. Click "Yes" to the "Do you want to suspend BitLocker protection?" Now wait a few minutes
  4. Click on "Resume protection" to update BitLocker TPM.


Bitlocker-suspend.png


What causes Bitlocker to request the recovery key?

There may be many reasons, such as hardware changes, BIOS changes (i.e. disabling secure boot), motherboard replacement, malware attacks, hard drive crashes, system crashes, or the program believes that data may be attacked.