{"id":411557,"date":"2024-06-29T22:02:20","date_gmt":"2024-06-29T22:02:20","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=411557"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=411557","title":{"rendered":"<span>How to Configure BitLocker Encryption For an Internal HDD or External USB Drive in Windows<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-1\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">Read this article to find out how to protect your internal or external storage from unauthorized access by encrypting it. How to configure and use the integrated Windows feature \u2013 BitLocker encryption. The operating system lets you encrypt local disks and removable drives with the integrated encryption tool \u2013 BitLocker. When the TrueCrypt team closed their project suddenly, they recommended their users to switch to BitLocker.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/e11\/69d\/564\/e1169d564c2d3deb7e8b4e658b4079d6.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/e11\/69d\/564\/e1169d564c2d3deb7e8b4e658b4079d6.jpg\" data-blurred=\"true\"\/><br \/>  <a name=\"habracut\"><\/a>  <\/p>\n<h2>How to turn on BitLocker?<\/h2>\n<p>  To work with BitLocker disk encryption software and BitLocker To Go, you will need a Professional or Enterprise edition of Windows 8, 8.1 or 10, or Windows 7 Ultimate edition. However, the kernel of Windows 8.1 includes the \u201cDevice Encryption\u201d function for accessing encrypted devices.<\/p>\n<p>  To enable BitLocker, open Control Panel and browse to System and Security \/ BitLocker Drive Encryption. Also, you can open Windows File Explorer, right-click on a disk and select \u201cTurn on BitLocker.\u201d If you don\u2019t see this option, it means your version of Windows doesn\u2019t support this feature.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/7f3\/456\/ef9\/7f3456ef93f83df797894905173e369a.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/7f3\/456\/ef9\/7f3456ef93f83df797894905173e369a.jpg\" data-blurred=\"true\"\/><\/p>\n<p>  Click on the option \u201cTurn on BitLocker\u201d next to the system drive, any logical disk or removable disk to enable encryption. However, dynamic disks cannot be encrypted with BitLocker.<\/p>\n<p>  There are two encryption types available:<\/p>\n<ul>\n<li>For logical partitions. It allows encrypting any built-in non-removable disks, system or not. When the computer is turned on, the loader starts Windows from the System Reserved partition and suggests choosing a method to unlock \u2013 for example, using a password. After that, BitLocker decrypts the disk and starts Windows. The encryption \/ decryption process is on-the-go, and you can work with the computer in the same way as before encryption was enabled. You can also encrypt other disks in your computer as well \u2013 it is available not only the disk with the operating system. You will have to enter a password when you address such disk for the first time.<\/li>\n<li>For removable devices: External media, such as USB drives and external hard disks, can be encrypted with BitLocker To Go. You\u2019ll be suggested to enter a password to unlock the media when you connect it to the computer. Users who have no password won\u2019t be able to access files stored in such media.<\/li>\n<\/ul>\n<p>  &lt;img src=&#187;<img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/8ca\/a20\/544\/8caa2054462b786f078997af69cbad44.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/8ca\/a20\/544\/8caa2054462b786f078997af69cbad44.jpg\" data-blurred=\"true\"\/>&#187; alt=\u00abimage\u00bb\/><\/p>\n<h2>Use BitLocker without TPM<\/h2>\n<p>  If your computer doesn\u2019t have a Trusted Platform Module (TPM), then you will see this message when turning on BitLocker:<\/p>\n<p>  \u201cThis device cannot use a Trusted Platform Module. Your administrator must set the \u201cAllow BitLocker without a compatible TPM\u201d option in the \u201cRequire additional authentication at start-up\u201d policy for OS volumes.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/bbc\/220\/826\/bbc2208263d476568ee327a666c44c6f.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/bbc\/220\/826\/bbc2208263d476568ee327a666c44c6f.jpg\" data-blurred=\"true\"\/><\/p>\n<p>  By default, encryption with BitLocker requires a TPM module to be available on your PC, to ensure security of the system drive. TPM is actually a microchip integrated into the computer\u2019s motherboard. BitLocker can save the encryption key to the TPM, which is much safer than keeping it elsewhere on your hard disk. The TPM chip will only give you the encryption key only after checking the computer\u2019s condition. This way, intruders can\u2019t just steal the hard disk from your PC or create an image of the encrypted disk and then decrypt it on another computer.<\/p>\n<p>  To enable drive encryption without a TPM chip, you need to have administrator\u2019s rights. Open the Local Group Policy Editor and change some settings.<\/p>\n<p>  Open the Run window by pressing the Windows + R shortcut, type the command gpedit.msc and press Enter. In the Local Group Policy Editor, go to Computer Configuration \/ Administrative Templates \/ Windows Components \/ BitLocker Drive Encryption \/ Operating System Drives. Double-click on Require additional authentication at startup. Change the setting to Enabled and make sure the box is checked for Allow BitLocker without a compatible TPM, then click OK to save the changes.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/9b3\/2e5\/54f\/9b32e554fb43f8e9be08afbac124872d.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/9b3\/2e5\/54f\/9b32e554fb43f8e9be08afbac124872d.jpg\" data-blurred=\"true\"\/><\/p>\n<h2>Select your unlock method<\/h2>\n<p>  After that, it\u2019s time to decide how to unlock the disk at startup. You can choose from several options. If your computer doesn\u2019t have a TPM, the disk can be unlocked by entering a password or inserting a special USB drive that would act as a hardware key.<\/p>\n<p>  If your computer does have a TPM chip, there will be more options to explore. For example, automatic unlocking at startup. The computer will address the TPM for the password and then decrypt the disk automatically.<\/p>\n<p>  To improve security, you can enable PIN code at startup. The PIN will be used for reliable encryption of the key which is stored in the TPM.<\/p>\n<p>  Select your preferred unlocking method and follow directions for further setup.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/5bc\/d12\/c8a\/5bcd12c8a063cd3f4e5bf2b99fa93afe.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/5bc\/d12\/c8a\/5bcd12c8a063cd3f4e5bf2b99fa93afe.jpg\" data-blurred=\"true\"\/><\/p>\n<h2>Save the recovery key to a safe place<\/h2>\n<p>  Before encrypting the disk, BitLocker will give you a recovery key. This key will decrypt an encrypted disk if the password is lost. For example, if you happen to lose the password or the USB drive used as the hardware key, or if the TPM stops working suddenly and so on.<\/p>\n<p>  You can save the key to a file, print it and keep with other important documents, save it to a USB drive, or upload it to your Microsoft account. If you save your recovery key to your Microsoft account, you\u2019ll be able to access it later by following this link \u2013 <a href=\"https:\/\/onedrive.live.com\/recoverykey\">onedrive.live.com\/recoverykey<\/a>.<\/p>\n<p>  Make sure you are going to keep this key in a safe place \u2013 if anyone gets it, they will be able to decrypt the disk and get access to your files. It is reasonable to have several copies of the key and keep them in different places \u2013 if you have no key and something happens to your main unlock method, your encrypted files will be lost forever.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/653\/39a\/809\/65339a80943a82853b3b38f9f6311aa2.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/653\/39a\/809\/65339a80943a82853b3b38f9f6311aa2.jpg\" data-blurred=\"true\"\/><\/p>\n<h2>Disk encryption and unlocking<\/h2>\n<p>  After BitLocker is turned on, it will automatically encrypt new files as they are created or modified, but you can choose what to do with the files that already exist on your hard disk. You can encrypt used space only or encrypt the entire drive. Encrypting the entire drive takes much longer but it will protect you against recovering deleted files. If you are setting up BitLocker on a new computer, then encrypt used space only \u2013 it will be faster. If you are configuring BitLocker on a computer you have been using before, you should encrypt the entire disk.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/858\/5f0\/c63\/8585f0c631b7cbd5927b315725b8ae2e.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/858\/5f0\/c63\/8585f0c631b7cbd5927b315725b8ae2e.jpg\" data-blurred=\"true\"\/><\/p>\n<p>  You will be suggested to run the BitLocker check and restart the PC. When it restarts, the disk will be encrypted for the first time. In the system tray, the BitLocker icon appears, so click on it to see the progress. You can use the computer while the process is running, but encryption will make it slower.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/e58\/1e2\/89a\/e581e289ab3bbbd75e26733654b1b9e9.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/e58\/1e2\/89a\/e581e289ab3bbbd75e26733654b1b9e9.jpg\" data-blurred=\"true\"\/><\/p>\n<p>  When the PC restarts, you will see the field to enter the BitLocker password, PIN or the suggestion to insert a USB key.<\/p>\n<p>  Press Escape if you can\u2019t unlock the disk. You will be suggested to enter the recovery key.<\/p>\n<p>  If you selected removable drive encryption with BitLocker To Go, you will see a similar wizard, but the drive can be encrypted without the need to reboot your PC. Make sure not to disconnect the removable drive during the encryption.<\/p>\n<p>  When you plug the encrypted USB flash drive or external storage into the computer, you will need to enter a password to unlock it. After the disk is encrypted, there will be a special icon shown on the disk in Windows Explorer.<\/p>\n<p>  You can manage protected disks in the BitLocker control panel \u2013 change passwords, disable BitLocker, back up the recovery key and much more. Right-click on the encrypted disk and choose Manage BitLocker to go to Control Panel.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/a62\/9f6\/929\/a629f69297806881d11033b0387dfe5c.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/a62\/9f6\/929\/a629f69297806881d11033b0387dfe5c.jpg\" data-blurred=\"true\"\/><\/p>\n<p>  As any encryption process, BitLocker is quite resource-intensive. The official Microsoft data on BitLocker says that usually, the extra load is less than 10%. If you work with important documents and encryption is a must, this will still be an acceptable point of equilibrium between security and performance.<\/p>\n<p>  See the <a href=\"https:\/\/hetmanrecovery.com\/recovery_news\/how-to-configure-bitLocker-encryption-of-the-hard-disk-drive-or-an-external-usb-drive-in-windows.htm\">full article<\/a> with all additional video tutorials. If you still have any questions, please ask in a comments. Also visit our <a href=\"https:\/\/www.youtube.com\/channel\/UCu-D9QnPsAPn7AtxL4HXLUg\">Youtube channel<\/a>, there are over 400 video tutorials.<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/549860\/\"> https:\/\/habr.com\/ru\/articles\/549860\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-1\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">Read this article to find out how to protect your internal or external storage from unauthorized access by encrypting it. How to configure and use the integrated Windows feature \u2013 BitLocker encryption. The operating system lets you encrypt local disks and removable drives with the integrated encryption tool \u2013 BitLocker. When the TrueCrypt team closed their project suddenly, they recommended their users to switch to BitLocker.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/post_images\/e11\/69d\/564\/e1169d564c2d3deb7e8b4e658b4079d6.jpg\" alt=\"image\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/e11\/69d\/564\/e1169d564c2d3deb7e8b4e658b4079d6.jpg\" data-blurred=\"true\"\/>  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-411557","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/411557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=411557"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/411557\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=411557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=411557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=411557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}