BitLocker

From UMIACS
Revision as of 14:57, 8 November 2017 by Mbaney (talk | contribs) (Created page with "==Overview== BitLocker Drive Encryption is a data protection feature available from Microsoft starting in Windows 7. Having BitLocker integrated with the operating system addr...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Overview

BitLocker Drive Encryption is a data protection feature available from Microsoft starting in Windows 7. Having BitLocker integrated with the operating system addresses the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned computers.

Data on a lost or stolen computer is vulnerable to unauthorized access, either by running a software-attack tool against it or by transferring the computer's hard disk to a different computer. BitLocker helps mitigate unauthorized data access by enhancing file and system protections. BitLocker also helps render data inaccessible when BitLocker-protected computers are decommissioned or recycled.

Official Microsoft documentation can be found at https://docs.microsoft.com/en-us/windows/device-security/bitlocker/bitlocker-overview

BitLocker at UMIACS

All of our Business Office desktops as well as our Enterprise supported laptops will have BitLocker enabled by UMIACS staff as part of each machine's install process.

Recovery Key Prompts

Ordinarily, no interaction should be required with BitLocker to keep it in a functional state. However, a few circumstances may lead to BitLocker detecting changes to the system boot information and prevent the computer from reaching Windows. This is by design.

Some factors that may cause this (not exhaustive):

  • BIOS updates -- some manufacturer automatic driver update utilities include these by default - beware!
  • External DVD or USB drives plugged in during boot
  • Malware on the system

The first step should always be to disconnect any external devices and then power the machine off and back on. This ensures that the hardware configuration of the machine is the same as it was when UMIACS staff initially enabled BitLocker. If the prompt still pops up, please contact UMIACS staff for further troubleshooting.