Configuring Bitlocker on 3 x SSDs whole drives and partitions


  1. Posts : 247
    Windows 10 Pro version 21H2 (standalone licence)
       #1

    Configuring Bitlocker on 3 x SSDs whole drives and partitions


    O/S version 21H2

    I have new PC with three SSDs.
    1 x M2 drive O/S [C]
    1 x M2 drive data (one partition) [D]
    1 x standard SSD (two partitions [E & F]
    The mobo is UEFI with TPM

    I believe that none of the Samsung Drives are Self Encrypting (or if they are this is poorly implemented by Samsung and others and as a result MS has updated Windows to default to Bitlocker software encryption).
    If I have understood all that correctly this means that even on my TPM enabled motherboard I now have to resort to software encryption. I hope there are still advantages to TPM beyond hardware encryption as I only upgraded as a result of Windows 11 not supporting non TPM hardware.
    So, this is what I am trying to achieve:
    1. I would like to configure all drives to be encrypted with bitlocker using a strong key for booting into windows on C (rather than relying on a much less secure Windows Login PW with PM)
    2. I would like drive D and partition E to be mounted on boot.
    3. I would like partition F to remain unmounted until it is mounted manually.
    Before I started to attempt this I read through this post I started to configure using GPEDIT and got some error messages about bitlocker processes being in progress and to wait until these had completed. This error message cleared on reboot. So now I am going to have another go having returned all Group Policy bitlocker options to default of 'not configured'.
    So I think I have to:
    Leaving TPM support on on the BIOS
    Edit Group Policy to enable requirement for password at boot on OS drive at boot
    Edit group policy to enable requirement for password on data drives
    Encrypt drives C and D and partition E using same password/key
    Encrypt partition F using different password/key so that it is not mounted at boot.
    Have I understood all this correctly and can I confifure for all drives/partitions to be mounted at boot apart from F?
    Thank you for your time and patience with any replies.




    .
      My Computer


  2. Posts : 27
    Windows 10 Pro x64
       #2

    Please see the following to ensure you meet the requirements

    https://docs.microsoft.com/en-us/win...quirements-faq

    And, DO NOT, I repeat DO NOT ever forget the Identifier and Recovery key or you will not be repairing Windows or recovering data if something goes wrong.

    How to Save and Recover BitLocker Recovery Keys
      My Computer


  3. Posts : 247
    Windows 10 Pro version 21H2 (standalone licence)
    Thread Starter
       #3

    AdvancedSetup said:
    Please see the following to ensure you meet the requirements

    https://docs.microsoft.com/en-us/win...quirements-faq

    And, DO NOT, I repeat DO NOT ever forget the Identifier and Recovery key or you will not be repairing Windows or recovering data if something goes wrong.

    How to Save and Recover BitLocker Recovery Keys
    Thanks. That very nicely tells me what it will do and has maybe answered one of my questions, but still gives me no idea how to grapple with achieving my intended outcome in practice.

    I think that it confirms that as my motherboard has TPM it would can be used with TPM secure boot to encrypt in software with Bitlocker, possibly with another authentication factor. When I am sure that question makes sense and my conclusion is correct then I may be able to proceed.

    What I do understand about encryption at a basic level is that losing the key, identifier or recovery key is a not a good idea and sort of defeats the whole purpose.
      My Computer


  4. Posts : 1,068
    windows 10
       #4

    Yes you can unlock drives and volumes (partitions) at the same time as your system drive (with pin code and others...). When you have activated bitlocker on your drives and volumes, you will have in bitlocker drive encryption an option "turn on (or off) auto unlock" for each drive and volume". You will have to unlock your drives and volumes first to activate this option. To the partition you don't want to unlock automatically you will have a password to enter.

    the cmd and powershell command line to enable auto unlock if it didn't work in the bitlocker drive encryption window:

    manage-bde -autounlock -enable X:

    in powershell:
    PS C:\>Enable-BitLockerAutoUnlock -MountPoint "X:"


    Replace X with the drive letter or partition.
    Last edited by itsme1; 20 Feb 2022 at 15:13.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 02:19.
Find Us




Windows 10 Forums