BitLocker Encryption guide (2024)

When you back up data to a removable drive, the data can be accessed by any computer the drive is connected to. This is of concern for drives that are stolen, lost or kept in offsite locations. BitLocker protects a removable drive from unauthorized access by encrypting the drive and locking it. Only when the drive is unlocked, can the data on it be accessed.

BitLocker is a Microsoft encryption solution that is supported by BackupAssist v8.3 and later for System Protection, File Protection and File Archiving backups to removable drive destinations.

BackupAssist's BitLocker implementation

This section explains how BackupAssist implements BitLocker, and how encryption keys and passwords work. It also explains what operating systems, backup types and backup destinations are supported by BackupAssist's implementation of BitLocker.

Show more

BackupAssist requires an unlocked drive to backup, restore and recover data. An unlocked drive will lock itself again if the drive is removed or if the server it is connected to is restarted. A drive can only be unlocked for a restore or recovery by manually entering the password that was provided when the drive was encrypted.

Note: Even though the key will unlock the drive for the backup, the password is still needed to perform a recovery. You can not perform a recovery without the password.

Encryption key

When a drive is encrypted, BitLocker creates an encryption key for that specific drive. The key is saved to a USB flash drive, and used by BackupAssist to unlock that drive each time the backup job runs.

Because of server restarts and media rotations, it should be assumed that an encrypted drive is always locked when a backup job runs. For this reason – the USB flash drive containing the encryption keys should always be connected to the server when a backup job backs up to an encrypted destination.

The USB flash drive will contain an encryption key for each drive that is encrypted, and should be used to store the encryption keys for all backup jobs on that server. Each server backing up to encrypted drives should have its own USB flash drive.

Note: The USB flash drive containing the encryption key should never be stored with the encrypted drive.

Password

When you create a backup job with BitLocker selected, you will be asked to provide a password. This password can be used to manually unlock the drives that were encrypted by the backup job. The BitLocker password must conform to requirements specified by the group policy, which may include minimum and maximum length requirements.

When you enter a password to unlock a drive, it must be the password that the backup job used to encrypt the drive. BackupAssist cannot retrieve the password if it is lost or forgotten.If you change the password after having used it to prepare external drives – the new password will only apply to drives that are prepared after the password was changed. It is suggested that all drives are prepared again so that the new password is applied to all drives used by the backup job

Supported operating systems

Windows Server versions:

  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012

Windows Desktop versions ( BackupAssist 9.5.5 and later):

  • Windows 10 Education, Pro, or Enterprise edition
  • Windows 8.1 Professional or Enterprise edition

Backup types supported

System Protection File Protection File Archiving
BitLocker encryption Yes Yes Yes
Alternative encryption None None Zip File Encryption

Backup destinations supported

Data container External disk RDXDrive
BitLocker encryption No Yes Yes

How to install BitLocker

BitLocker is included as an installable feature in Window Server 2008 and later server operating systems. By default, BitLocker is not installed but it can be added from the Windows Server features list. Adding BitLocker will make it available as an option for BackupAssist backups. For Windows Desktop operating systems, BitLocker is included as an option in the Control Panel.

Show more

To install BitLocker on Window Server 2012 and later versions

  1. Open Server Manager.
  2. Select Add Roles and Features from the Manage menu.
  3. Progress to the Features list under Select features.
  4. Tick BitLocker Drive Encryption. Other roles and features required for Windows to use BitLocker will be automatically selected.
  5. Select Add features.
  6. Select Next
  7. Select Install.

To install BitLocker on Window Server 2008 / Server 2008 R2

Note: BackupAssist support for the Windows Server 2008 and Windows Server 2008 R2 families, and Windows 7 and Windows 8, ended on May 1, 2020. To learn more, see Supported platforms

  1. Open Server Manager.
  2. Select the Add features option from the Features Summary Help menu.
  3. Tick BitLocker Drive Encryption.
  4. Select Install.

To install BitLocker on Windows Desktop

BitLocker is simply enabled by drive using an option in the Control Panel.

  • For Windows 7, select Control Panel > BitLocker Drive Encryption.
  • For Windows Desktop 8, 8.1 and 10, select Control Panel > System and Security > BitLocker Drive Encryption.

Note: After installing the BitLocker, Windows may require a restart before BitLocker can be used. If a reboot is required, it will indicated at the end of the install operation.

How to create a BitLocker backup job

This section explains how to create a backup job that uses BitLocker encryption. A backup job implements BitLocker using 3 of the backup job creation steps: Destination media where BitLocker is selected, Set up destination where BitLocker is configured and Prepare media where the removable drive is encrypted.

Show more

The Pre-requisites

  • You must be using Windows Server for the BitLocker feature to appear.
  • BitLocker must be installed, as explained in the previous section.
  • Your backup destination must be an External drive or RDX drive.
  • File Archiving also supports Flash drive destinations.
  • A USB flash drive is required to store the encryption key.

The steps

Follow these steps to use BitLocker encryption when you create a backup job:

  1. Destination Media
  2. This step is where you select Enable BitLocker encryption.

    The Enable BitLocker encryption option will:

  • Appear if you are running BackupAssist on a Windows Server
  • Be selectable when you select a supported removable drive as a backup destination.
  • Be greyed-out if BitLocker is not installed.
  • Set up destination
  • This step is used to select the destination media and Bitlocker encryption.

    The following two fields are used to provide BitLocker configuration information.

    • BitLocker encryption key location: this is used to identify the USB flash drive that the BitLocker encryption key is saved to. You can use the Detect option to identify the drive, or use the drop down list to select the Drive letter that has been allocated to the USB flash drive.
    • Password for encrypted backup drive: this field is where you enter the password that can be used to manually unlock any drive that was encrypted by this backup job.
    • Selecting Safely eject the hard drive after the backup has been completed, is a good way to lock the drive after the backup has been completed.

  • Prepare media
  • This step is used to prepare each of the drives that the backup job will use. By default, it will display drives based on the backup schedule.

    When you select the Prepare button next to each drive, that drive will be labeled by BackupAssist and selected for BitLocker encryption.

    • The encryption process will not start until the backup job has been created.
    • It is recommended that you prepare all of your drives so that they can be encrypted.
    • If the required drive is not encrypted when the backup job runs, the backup job will fail.
  • Next Steps
  • This is the final screen in the backup job creation process, and comes after you have named the backup job. If you have selected BitLocker Encryption, there will be a tick box for - Launch BitLocker encryption tool.

    When you select Finish, the backup job will be created and the BitLocker encryption tool will automatically start and begin encrypting the drives that you Prepared in the Prepare media step.

    • When you select Finish, the backup job will be created and the BitLocker encryption tool will open.
    • When you select the start icon next to a drive that you prepared, and the encryption process will begin.
    • If you deselect this box, the drives will not be encrypted.
    • If the backup job runs and its drive has not been encrypted, the backup job will fail.

    During the encryption process, the drive’s encryption key is saved to the USB flash drive and the password is assigned to the drive. The key will be saved as a hidden system file.

    If you want to prepare more drives after the encryption process has finished, you can as follows:

    1. Select the Jobs tab Manage menu.
    2. Select the backup job and select Edit from the lower menu.
    3. Select Prepare media from the job menu.
    4. Select Prepare for each drive that you want to encrypt.
    5. Select the BitLocker encryption tool using the link inside the window.

    The BitLocker Encryption tool will open and begin the encryption process.

    The BitLocker encryption tool

    If you create a backup job with Enable BitLocker encryption selected, there will be a step at the end of the job creation called Next steps which will open the BitLocker encryption tool when you select Finish. The tool is used to encrypt the drives that the backup job will use. This should be done before the backup job runs, because if an unencrypted drive is used for a BitLocker backup job, the job will fail.

    Show more

    If you finish creating the backup job without encrypting the drives, you can open the BitLocker encryption tool by going to the Job tab's Manage menu, opening the backup job and selecting Prepare media from the top menu. This will open the Prepare media dialog, which contains a link to the BitLocker encryption tool.

    The BitLocker encryption tool can run in the background after BackupAssist has been closed. The encryption process will tell you how much has been encrypted and how long the process will take. You can encrypt more than one drive at a time, reducing the total time required to encrypt your set of prepared drives.

    The encryption tool has 4 action buttons, which will become available when the drive is attached:

    • Refresh and display any new drives that have been attached
    • Start an encryption process that has been paused
    • Pause the encryption process.
    • Eject the removable drive. You cannot eject a drive that is being encrypted.

    Note: If you do not resume a paused encryption, the drive will be partially encrypted. A partially encrypted drive can still be accessed in Windows but it cannot be used as a backup destination for a BitLocker job. To decrypt the encrypted part of the drive, open BitLocker from the Windows Control Panel, select the drive and click Turn off BitLocker.

    Note: If you have previously encrypted a drive using the Windows BitLocker UI, you must unlock the drive before preparing (encrypting) the drive using BackupAssist.

    How to restore from an encrypted drive

    When you perform a restore from an encrypted drive, you can give the restore job access to the data by providing the password when prompted during the restore process, or by inserting the encryption key before the restore process begins.

    Show more

    Using the password.

    If the encryption key is not detected, you will be prompted for the password when the restore job tries to access the backup. Entering the password will allow you to access the data as long as the password is the one that was assigned when the drive was encrypted. For example, if you are using the Integrated Restore Console, you will be prompted to enter the password when you select Restore at the very last step.

    Using the encryption key

    To unlock an encrypted drive using the key, connect the USB flash drive to the server running BackupAssist. BackupAssist will use the key to unlock the drive that you are restoring from. You will not be prompted to do anything other than the normal restore steps.

    How to recover from an encrypted drive

    When you perform a recovery, you MUST use the password to access an encrypted drive. The RecoverAssist media will boot the system and ask for the location of the image backup that you want to recover from. When you select the encrypted drive, you will be prompted to enter the password. BackupAssist cannot retrieve the password if it is lost or forgotten.

    Drive encryption duration

    BitLocker encrypts the drive that the backup resides on at the sector level. This means you only need to encrypt the drive once, but because all the encryption takes place up front, it can take a long time. Microsoft estimates that BitLocker encryption can take 1 minute per 500mb, so you should plan when to perform the encryption based on the information below.

    Show more

    How long the encryption process takes depends on:

    • The size of the drive
    • The performance of the drive and the server
    • The operating system you are using
    • How much data is on the drive (for Windows 2012 and later)

    If you are using Windows 8 or Windows Server 2012 and later, BitLocker will only encrypt the used space. It does not encrypt unused disk space or disk space containing deleted files. This makes the process very fast when there is not much data on the drive.

    Encryption time examples

    The below table provides examples for how long the encryption process could take in different scenarios, using sensible estimates.

    Windows Server 2012 and later

    Disk Size Duration
    New disk 1 - 5 minutes
    1 TB Drive with 300 GB used 10 hours
    2 TB Drive with 1.5 TB used 50 hours

    Windows Server 2008

    Disk Size Duration
    500 GB Drive 17 hours
    1 TB Drive 33 hours
    2 TB Drive 67 hours

    To learn more, see the Microsoft BitLocker FAQ

    Windows BitLocker Pop up message

    When an encrypted drive is attached to a server that is logged on, Windows will display a pop-up message to tell you that the drive is available and a password is required to access it. Having a USB drive with an encryption key means you do not need to respond to this prompt for your backup job to proceed.

    Show more

    This message will have no impact on your backup job. You do not need to enter the password as long as you have the USB flash drive with the encryption key attached.

    Because this is a Windows security pop-up, and because it needs to be allowed to appear for encrypted drives that are not managed by BackupAssist, it’s important to understand how the message applies to BackupAssist.

    • If you see this message, you can select Cancel and ignore it. Your backup job will not be affected because the encryption key will be used to unlock the drive.
    • If you enter the password into the pop-up and tick Automatically unlock on this computer from now on, the pop-up will not appear again. However, this means that the drive will be automatically unlocked every time it is attached. For security reasons, we recommended that you use the encryption key on the USB flash drive to unlock the drive rather than have it auto unlock.
    • Using the encryption key means the drive is only unlocked while the backup job is running. The key unlocks the drive when the backup starts and, if you have the drive set to eject, it will be locked again when the drive ejects at the end of the backup job.
    • Using the password auto unlock means the drive will be unlocked for as long as it is attached to the server.

    BitLocker Encryption guide (2024)

    FAQs

    Is BitLocker enough for encryption? ›

    BitLocker lets users choose to encrypt just their data. Although it's not the most secure way to encrypt a drive, this option can reduce encryption time by more than 99 percent, depending on how much data that needs to be encrypted. For more information, see Used Disk Space Only encryption.

    How many times can you fail BitLocker? ›

    This means that a user could quickly attempt to use a key with the wrong authorization value 32 times. For each of the 32 attempts, the TPM records if the authorization value was correct or not. This inadvertently causes the TPM to enter a locked state after 32 failed attempts.

    Is there a downside for using BitLocker? ›

    Cons of BitLocker

    Asking a nontechnical user to know things about encryption keys and proper storage or backup of these keys is a bit much. Not having the key can lock legitimate users out of their own data and using BitLocker can significantly impact performance (up to 45%) in some cases.

    Why does my computer keep doing BitLocker recovery? ›

    If you experiences that the computer shows BitLocker recovery screen after power on, it means that the HDD/SDD has been encrypted. (HDD/SDD is locked.) Once PC hardware components have been replaced or BIOS settings have been changed, all may cause system shows BitLocker recovery screen after power on.

    What triggers BitLocker recovery? ›

    Per Microsoft, some of the causes of BitLocker recovery include: An attacker has modified your computer. This is applicable for a computer with a Trusted Platform Module (TPM) because the TPM checks the integrity of boot components during startup. Moving the BitLocker-protected drive into a new computer.

    Is BitLocker obsolete? ›

    For your data protection needs, Microsoft recommends that you use Microsoft Purview Information Protection and Microsoft Purview Data Loss Prevention. Note: BitLocker to Go as a feature is still supported.

    What are the weaknesses of BitLocker? ›

    The recovery process can be cumbersome when users forget their BitLocker password or encounter a hardware failure. Recovering encrypted data often involves using a recovery key, which, if not stored securely, could lead to unauthorized access.

    Is BitLocker 100% safe? ›

    Not 100% Secure: While BitLocker provides strong protection against most cyber threats, there are some cases where it can be bypassed by malicious actors with sophisticated techniques. As such, organizations must also consider other layers of protection when utilizing this software.

    How do I unlock BitLocker forever? ›

    1. Type and search [Manage BitLocker] in the Windows search bar①, then click [Open]②.
    2. Click [Turn off BitLocker]③ on the drive that you want to decrypt. ...
    3. Confirm whether you want to decrypt your drive, then select [Turn off BitLocker]④ to start turning off BitLocker, and your drive will not be protected anymore.
    Oct 24, 2023

    How do I surpass BitLocker recovery? ›

    Skip the first Bitlocker recovery key prompt by pressing Esc 4. Skip the second Bitlocker recovery key prompt by selecting Skip This Drive in the bottom right 5. Navigate to Troubleshoot > Advanced Options > Command Prompt 6. Type bcdedit /set {default} safeboot minimal, then press Enter 7.

    Does resetting a PC remove BitLocker? ›

    Resetting computer will remove the BitLocker drive, and the drive will be lost forever. The recovery key won't change, but it is meaningless to keep the recovery key since the BitLocker drive is no longer recoverable.

    Does BitLocker encrypt the entire drive? ›

    It encrypts your entire drive, providing a high level of security using the TPM module. You can set up BitLocker to automatically save keys to Active Directory. There are no additional licensing costs, as a native Windows function. Negligible impact on read performance, and no impact on write performance.

    Can a virus trigger BitLocker? ›

    If the PC does not have a 'data partition' other than the operating system partition, the malware is able to create (and encrypt with BitLocker) a file containing a virtual partition (VHD) and move all the user's documents into this 'virtual partition' (this is referred to as 'VHD Locker Ransomware').

    Does BitLocker slow down SSD? ›

    Does BitLocker slow down SSD? The answer is YES, and the speed of SSD can be reduced by up to 45% with software-based encryption activated.

    How do I get my computer out of BitLocker mode? ›

    Follow the steps given below to remove bitlocker encryption in GUI mode,
    1. Click Start, click Control Panel, click System and Security, and then click BitLocker Drive Encryption.
    2. Look for the drive on which you want BitLocker Drive Encryption turned off, and click Turn Off BitLocker.

    How do I fix BitLocker suspended? ›

    Causes: BitLocker suspension can occur if the hard drive is removed from the computer or if changes are made to the operating system or hardware. Solutions: To resolve BitLocker suspension, reconnect the hard drive to the computer, and then unlock the drive using the BitLocker recovery key.

    How to unlock BitLocker? ›

    To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

    Top Articles
    Experience Modification Rate (EMR) & Workers' Comp | AmTrust Financial
    How to Plan a Trip with Friends (with Pictures) - wikiHow
    Pollen Count Los Altos
    Katie Pavlich Bikini Photos
    The Potter Enterprise from Coudersport, Pennsylvania
    Snarky Tea Net Worth 2022
    Bed Bath And Body Works Hiring
    Sunday World Northern Ireland
    Goldsboro Daily News Obituaries
    Immediate Action Pathfinder
    Conscious Cloud Dispensary Photos
    Echat Fr Review Pc Retailer In Qatar Prestige Pc Providers – Alpha Marine Group
    Who called you from +19192464227 (9192464227): 5 reviews
    Erica Banks Net Worth | Boyfriend
    Promiseb Discontinued
    Iu Spring Break 2024
    Today Was A Good Day With Lyrics
    The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
    Vernon Dursley To Harry Potter Nyt Crossword
    University Of Michigan Paging System
    Marquette Gas Prices
    Znamy dalsze plany Magdaleny Fręch. Nie będzie nawet chwili przerwy
    Foodsmart Jonesboro Ar Weekly Ad
    Jurassic World Exhibition Discount Code
    Delete Verizon Cloud
    Kqelwaob
    Alternatieven - Acteamo - WebCatalog
    Deepwoken: Best Attunement Tier List - Item Level Gaming
    King Soopers Cashiers Check
    What Is The Lineup For Nascar Race Today
    Loopnet Properties For Sale
    Metra Union Pacific West Schedule
    404-459-1280
    Marine Forecast Sandy Hook To Manasquan Inlet
    Agematch Com Member Login
    Andhra Jyothi Telugu News Paper
    ENDOCRINOLOGY-PSR in Lewes, DE for Beebe Healthcare
    Evil Dead Rise (2023) | Film, Trailer, Kritik
    Colorado Parks And Wildlife Reissue List
    Craigslist en Santa Cruz, California: Tu Guía Definitiva para Comprar, Vender e Intercambiar - First Republic Craigslist
    Chase Bank Zip Code
    Enr 2100
    Greg Steube Height
    Phone Store On 91St Brown Deer
    Big Brother 23: Wiki, Vote, Cast, Release Date, Contestants, Winner, Elimination
    Abigail Cordova Murder
    Automatic Vehicle Accident Detection and Messageing System – IJERT
    Heat Wave and Summer Temperature Data for Oklahoma City, Oklahoma
    Lira Galore Age, Wikipedia, Height, Husband, Boyfriend, Family, Biography, Net Worth
    Service Changes and Self-Service Options
    Ippa 番号
    Latest Posts
    Article information

    Author: Laurine Ryan

    Last Updated:

    Views: 6485

    Rating: 4.7 / 5 (57 voted)

    Reviews: 88% of readers found this page helpful

    Author information

    Name: Laurine Ryan

    Birthday: 1994-12-23

    Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

    Phone: +2366831109631

    Job: Sales Producer

    Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

    Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.