Bitlocker Download Windows 7 Professional

0 views
Skip to first unread message

Mette Florida

unread,
Aug 5, 2024, 12:02:34 PM8/5/24
to redebebin
Ihave enabled the Store Bitlocker recovery information in Active Directory GPO and when running a gp result I see the gpo has been applied. My first issue is that when starting the bitlocker wizard I am still prompted for a place to save or print the key. This is not supposed to happen if I am understanding correctly. My second issue is that the bitlocker key is not being stored in AD even if you select to save or print the key. Does anyone have this set up with server 2016 and windows 10 Pro?

This guide is more of a reflection on the steps I took to publish the BitLocker recovery keys of machines deployed on an Active Directory domain. Microsoft has gobs and gobs of information on this subject which can be a tad overwhelming,...


I would like to protect my Windows 11 Pro desktop and laptop with Bitlocker and password/pin. Here's my struggle after I encryped the drive and want to protect the drives in the case the entire pc is stolen. Thanks for you help.


Do I setup password using bitlocker boot pin? I've read it's no longer available on Windows 11.Do I setup password using windows login? I've read that it can be reset by booting from usb.Do I setup admin and power-on passwords from BIOS? What happens to TPM chip when CMOS is reset on desktop? For laptop there's website that'll provide password reset for locked BIOS.I used local account setup on all the machines.


If My Windows 10 system fails, and i want to access the Cyptomator folders on a new system with Linux Ubuntu, will the files from Pcloud will be accessible from the backup using the new machine or can only retrieve on a Windows 10 PRO machine?


Hi.

The Cryptomator encryption is independent from the OS, so you can open your vault on any system that has Cryptomator installed.

Bitlocker should not have an impact on the Cryptomator files. For example: if you create a textile on your windows (bitlocker encrypted) system and upload it to cloud, it is still accessible with other systems that are not encrypted with bitlocker.


First, once you do have Bitlocker enabled you should not be asked for the Bitlocker key pretty much ever. Bitlocker essentially locks the drive to the tpm chip on the device that encrypts it. Bitlocker also only encrypts the hard drive not the device. Worst case scenario the data on the drive would be lost. I can't confirm the virtual keyboard would work but you absolutely could use a wired one. The screen that pops up does appear to be part of the OS, so I would assume the virtual one appears but not sure. You will want to make sure you have the code backed up somewhere if you lose it and the data is gone. I believe is automatically backed up to your account if you sign into windows with a Microsoft account.


As for the admistrator password usually there is a way to reset it manually on laptops and desktops but again not sure about the Go. If it can't be reset and the password is forgotten you just wouldn't be able to make changes to the bios. Not sure if I have the right one here as there are a few passwords you can set up in the bios on different devices. Havent personally looked at the legions ones. I assume this one you want to use to lock down the bios.


Hard drive is the general term for the computer storage. A spinning disk is a drive with you guessed it spinning disks. The fixed state or solid state drivers are another type. Hard drive would be the correct term and all hard drive types can be encrypted.


I haven't heard of Bitlocker PIN so I checked it out. Maybe we mean the same things but are using different different terminology when you say the whole device. Like this won't lock down the bios on the Go it only locks down the hard drive. This extra step makes it so you also need a PIN before it loads since BitLocker will automatically start once it verifies the TPM has the key. "Preboot authentication is designed to prevent the encryption keys from being loaded to system memory without the trusted user supplying another authentication factor." This link has in-depth details on the feature. -us/windows/security/operating-system-security/data-protection/bitlocker/countermeasures



I also found a few articles from Microsoft and other forums that state the virtual keyboard works with it. This is at the Windows OS level so that function should be available when it prompts for the PIN. Reliably getting the Virtual keyboard to appear may be another thing. I regularly run into the where I need to use the button shortcuts to have it pop up. Plugging in a USB wired or wireless keyboard should work at all stages of your computer so it should be a reliable option if you run into issues. I can't say if a Bluetooth keyboard would work. In theory, it should work but setting this up may stop it from loading certain features or drivers before the PIN is entered.

-infrastructure-and-security/bitlocker-pin-on-surface-pro-3-and-other-tablets/ba-p/257348



You should be able to test it with minimal risk if you want. The risk would be losing any data on the drive. Just make sure you have the key saved somewhere other than on the Go in case it is required. Drives with BitLocker encryption can be unlocked on a different computer with the key. In the worst-case scenario, you can connect it to another computer and decrypt it. As BWWWJ1st mentioned theirs popped up asking for a code. Most of the time it shouldn't ask for a key, but there are a few rare cases where it may ask for the Bitlocker code. Usually, this occurs when you reboot after an update(even Windows updates). I very rarely see it at work, but it is a pain when it happens if you don't have the key nearby. Hopefully, you can find someone who runs it if you need that extra knowledge to take the jump. It may not be a bad idea to post to the Reddit forums as there is a larger base of users perhaps someone there has done this.


Just as a little more detail for anyone reading this. There is a little relief to manually retaining the keys yourself. I have been looking into this for work because of the changes Microsoft is making. New Windows 11 devices will automatically enable BitLocker which is not ideal for enterprise management as it adds more work for us when deploying computers to our users. If you log in to Windows with a Microsoft account it will store your keys on your profile.

-us/windows/finding-your-bitlocker-recovery-key-in-windows-6b71ad27-0b89-ea08-f143-056f5ab347d6

3a8082e126
Reply all
Reply to author
Forward
0 new messages