BitLocker content move
@ -1,16 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: BCD settings and BitLocker
|
title: BCD settings and BitLocker
|
||||||
description: This article for IT professionals describes the BCD settings that are used by BitLocker.
|
description: This article for IT professionals describes the BCD settings that are used by BitLocker.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Boot Configuration Data settings and BitLocker
|
# Boot Configuration Data settings and BitLocker
|
@ -2,26 +2,25 @@
|
|||||||
metadata:
|
metadata:
|
||||||
title: BitLocker and Active Directory Domain Services (AD DS) FAQ (Windows 10)
|
title: BitLocker and Active Directory Domain Services (AD DS) FAQ (Windows 10)
|
||||||
description: Learn more about how BitLocker and Active Directory Domain Services (AD DS) can work together to keep devices secure.
|
description: Learn more about how BitLocker and Active Directory Domain Services (AD DS) can work together to keep devices secure.
|
||||||
ms.prod: windows-client
|
|
||||||
ms.technology: itpro-security
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
audience: ITPro
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
author: paolomatarazzo
|
||||||
|
ms.author: paoloma
|
||||||
|
appliesto:
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/supported-versions-windows-client target=_blank>Windows 11</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/supported-versions-windows-client target=_blank>Windows 10</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2022</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2019</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2016</a>
|
||||||
title: BitLocker and Active Directory Domain Services (AD DS) FAQ
|
title: BitLocker and Active Directory Domain Services (AD DS) FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
**Applies to:**
|
||||||
- Windows 10 and later
|
- Windows 10 and later
|
||||||
- Windows Server 2016 and later
|
- Windows Server 2016 and later
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
||||||
questions:
|
questions:
|
@ -1,26 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker basic deployment
|
title: BitLocker basic deployment
|
||||||
description: This article for the IT professional explains how BitLocker features can be used to protect your data through drive encryption.
|
description: This article for the IT professional explains how BitLocker features can be used to protect your data through drive encryption.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker basic deployment
|
# BitLocker basic deployment
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article for the IT professional explains how BitLocker features can be used to protect data through drive encryption.
|
This article for the IT professional explains how BitLocker features can be used to protect data through drive encryption.
|
||||||
|
|
||||||
## Using BitLocker to encrypt volumes
|
## Using BitLocker to encrypt volumes
|
@ -1,26 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker Countermeasures
|
title: BitLocker Countermeasures
|
||||||
description: Windows uses technologies including TPM, Secure Boot, Trusted Boot, and Early Launch Anti-malware (ELAM) to protect against attacks on the BitLocker encryption key.
|
description: Windows uses technologies including TPM, Secure Boot, Trusted Boot, and Early Launch Anti-malware (ELAM) to protect against attacks on the BitLocker encryption key.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker Countermeasures
|
# BitLocker Countermeasures
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
Windows uses technologies including trusted platform module (TPM), secure boot, and measured boot to help protect BitLocker encryption keys against attacks. BitLocker is part of a strategic approach to securing data against offline attacks through encryption technology. Data on a lost or stolen computer is vulnerable. For example, there could be unauthorized access, either by running a software attack tool against the computer or by transferring the computer's hard disk to a different computer.
|
Windows uses technologies including trusted platform module (TPM), secure boot, and measured boot to help protect BitLocker encryption keys against attacks. BitLocker is part of a strategic approach to securing data against offline attacks through encryption technology. Data on a lost or stolen computer is vulnerable. For example, there could be unauthorized access, either by running a software attack tool against the computer or by transferring the computer's hard disk to a different computer.
|
||||||
|
|
||||||
BitLocker helps mitigate unauthorized data access on lost or stolen computers before the authorized operating system is started. This mitigation is done by:
|
BitLocker helps mitigate unauthorized data access on lost or stolen computers before the authorized operating system is started. This mitigation is done by:
|
@ -12,11 +12,6 @@ metadata:
|
|||||||
ms.custom: bitlocker
|
ms.custom: bitlocker
|
||||||
title: BitLocker frequently asked questions (FAQ)
|
title: BitLocker frequently asked questions (FAQ)
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
||||||
questions:
|
questions:
|
@ -1,25 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker deployment comparison
|
title: BitLocker deployment comparison
|
||||||
description: This article shows the BitLocker deployment comparison chart.
|
description: This article shows the BitLocker deployment comparison chart.
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker deployment comparison
|
# BitLocker deployment comparison
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article depicts the BitLocker deployment comparison chart.
|
This article depicts the BitLocker deployment comparison chart.
|
||||||
|
|
||||||
## BitLocker deployment comparison chart
|
## BitLocker deployment comparison chart
|
@ -1,27 +1,14 @@
|
|||||||
---
|
---
|
||||||
title: Overview of BitLocker Device Encryption in Windows
|
title: Overview of BitLocker Device Encryption in Windows
|
||||||
description: This article provides an overview of how BitLocker Device Encryption can help protect data on devices running Windows.
|
description: This article provides an overview of how BitLocker Device Encryption can help protect data on devices running Windows.
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Overview of BitLocker Device Encryption in Windows
|
# Overview of BitLocker device encryption
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article explains how BitLocker Device Encryption can help protect data on devices running Windows. See [BitLocker](bitlocker-overview.md) for a general overview and list of articles.
|
This article explains how BitLocker Device Encryption can help protect data on devices running Windows. See [BitLocker](bitlocker-overview.md) for a general overview and list of articles.
|
||||||
|
|
||||||
@ -31,7 +18,6 @@ When users travel, their organization's confidential data goes with them. Wherev
|
|||||||
|
|
||||||
The below table lists specific data-protection concerns and how they're addressed in Windows 11, Windows 10, and Windows 7.
|
The below table lists specific data-protection concerns and how they're addressed in Windows 11, Windows 10, and Windows 7.
|
||||||
|
|
||||||
|
|
||||||
| Windows 7 | Windows 11 and Windows 10 |
|
| Windows 7 | Windows 11 and Windows 10 |
|
||||||
|---|---|
|
|---|---|
|
||||||
| When BitLocker is used with a PIN to protect startup, PCs such as kiosks can't be restarted remotely. | Modern Windows devices are increasingly protected with BitLocker Device Encryption out of the box and support SSO to seamlessly protect the BitLocker encryption keys from cold boot attacks.<br><br>Network Unlock allows PCs to start automatically when connected to the internal network. |
|
| When BitLocker is used with a PIN to protect startup, PCs such as kiosks can't be restarted remotely. | Modern Windows devices are increasingly protected with BitLocker Device Encryption out of the box and support SSO to seamlessly protect the BitLocker encryption keys from cold boot attacks.<br><br>Network Unlock allows PCs to start automatically when connected to the internal network. |
|
@ -2,25 +2,21 @@
|
|||||||
metadata:
|
metadata:
|
||||||
title: BitLocker FAQ (Windows 10)
|
title: BitLocker FAQ (Windows 10)
|
||||||
description: Find the answers you need by exploring this brief hub page listing FAQ pages for various aspects of BitLocker.
|
description: Find the answers you need by exploring this brief hub page listing FAQ pages for various aspects of BitLocker.
|
||||||
ms.prod: windows-client
|
author: paolomatarazzo
|
||||||
ms.technology: itpro-security
|
ms.author: paoloma
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
audience: ITPro
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
appliesto:
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/supported-versions-windows-client target=_blank>Windows 11</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/supported-versions-windows-client target=_blank>Windows 10</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2022</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2019</a>
|
||||||
|
- ✅ <a href=https://learn.microsoft.com/windows/release-health/windows-server-release-info target=_blank>Windows Server 2016</a>
|
||||||
title: BitLocker frequently asked questions (FAQ) resources
|
title: BitLocker frequently asked questions (FAQ) resources
|
||||||
summary: |
|
summary: This article links to frequently asked questions about BitLocker. BitLocker is a data protection feature that encrypts drives on computers to help prevent data theft or exposure. BitLocker-protected computers can also delete data more securely when they're decommissioned because it's much more difficult to recover deleted data from an encrypted drive than from a non-encrypted drive.
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
This article links to frequently asked questions about BitLocker. BitLocker is a data protection feature that encrypts drives on computers to help prevent data theft or exposure. BitLocker-protected computers can also delete data more securely when they're decommissioned because it's much more difficult to recover deleted data from an encrypted drive than from a non-encrypted drive.
|
|
||||||
|
|
||||||
- [Overview and requirements](bitlocker-overview-and-requirements-faq.yml)
|
- [Overview and requirements](bitlocker-overview-and-requirements-faq.yml)
|
||||||
- [Upgrading](bitlocker-upgrading-faq.yml)
|
- [Upgrading](bitlocker-upgrading-faq.yml)
|
@ -1,19 +1,11 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker Group Policy settings
|
title: BitLocker Group Policy settings
|
||||||
description: This article for IT professionals describes the function, location, and effect of each Group Policy setting that is used to manage BitLocker Drive Encryption.
|
description: This article for IT professionals describes the function, location, and effect of each Group Policy setting that is used to manage BitLocker Drive Encryption.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker group policy settings
|
# BitLocker group policy settings
|
@ -1,16 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker How to deploy on Windows Server 2012 and later
|
title: BitLocker How to deploy on Windows Server 2012 and later
|
||||||
description: This article for the IT professional explains how to deploy BitLocker and Windows Server 2012 and later
|
description: This article for the IT professional explains how to deploy BitLocker and Windows Server 2012 and later
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker: How to deploy on Windows Server 2012 and later
|
# BitLocker: How to deploy on Windows Server 2012 and later
|
@ -1,16 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker - How to enable Network Unlock
|
title: BitLocker - How to enable Network Unlock
|
||||||
description: This article for the IT professional describes how BitLocker Network Unlock works and how to configure it.
|
description: This article for the IT professional describes how BitLocker Network Unlock works and how to configure it.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker: How to enable Network Unlock
|
# BitLocker: How to enable Network Unlock
|
@ -7,16 +7,10 @@ metadata:
|
|||||||
author: frankroj
|
author: frankroj
|
||||||
ms.author: frankroj
|
ms.author: frankroj
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
audience: ITPro
|
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
title: BitLocker Key Management FAQ
|
title: BitLocker Key Management FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
@ -1,15 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker management
|
title: BitLocker management
|
||||||
description: Refer to relevant documentation, products, and services to learn about managing BitLocker and see recommendations for different computers.
|
description: Refer to relevant documentation, products, and services to learn about managing BitLocker and see recommendations for different computers.
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker management
|
# BitLocker management
|
||||||
@ -18,7 +11,7 @@ The ideal solution for BitLocker management is to eliminate the need for IT admi
|
|||||||
|
|
||||||
Though much Windows [BitLocker documentation](bitlocker-overview.md) has been published, customers frequently ask for recommendations and pointers to specific, task-oriented documentation that is both easy to digest and focused on how to deploy and manage BitLocker. This article links to relevant documentation, products, and services to help answer this and other related frequently asked questions, and also provides BitLocker recommendations for different types of computers.
|
Though much Windows [BitLocker documentation](bitlocker-overview.md) has been published, customers frequently ask for recommendations and pointers to specific, task-oriented documentation that is both easy to digest and focused on how to deploy and manage BitLocker. This article links to relevant documentation, products, and services to help answer this and other related frequently asked questions, and also provides BitLocker recommendations for different types of computers.
|
||||||
|
|
||||||
[!INCLUDE [bitlocker](../../../../includes/licensing/bitlocker-management.md)]
|
[!INCLUDE [bitlocker](../../../../../includes/licensing/bitlocker-management.md)]
|
||||||
|
|
||||||
## Managing domain-joined computers and moving to cloud
|
## Managing domain-joined computers and moving to cloud
|
||||||
|
|
@ -10,14 +10,8 @@ metadata:
|
|||||||
audience: ITPro
|
audience: ITPro
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.reviewer:
|
|
||||||
ms.custom: bitlocker
|
|
||||||
title: BitLocker Network Unlock FAQ
|
title: BitLocker Network Unlock FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
@ -7,19 +7,13 @@ metadata:
|
|||||||
author: frankroj
|
author: frankroj
|
||||||
ms.author: frankroj
|
ms.author: frankroj
|
||||||
manager: aaroncz
|
manager: aaroncz
|
||||||
audience: ITPro
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: faq
|
ms.topic: faq
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
title: BitLocker Overview and Requirements FAQ
|
title: BitLocker Overview and Requirements FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
@ -1,32 +1,17 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker
|
title: BitLocker overview
|
||||||
description: This article provides a high-level overview of BitLocker, including a list of system requirements, practical applications, and deprecated features.
|
description: This article provides a high-level overview of BitLocker, including a list of system requirements, practical applications, and deprecated features.
|
||||||
ms.author: frankroj
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker
|
# BitLocker overview
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article provides a high-level overview of BitLocker, including a list of system requirements, practical applications, and deprecated features.
|
This article provides a high-level overview of BitLocker, including a list of system requirements, practical applications, and deprecated features.
|
||||||
|
|
||||||
## BitLocker overview
|
|
||||||
|
|
||||||
BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned computers.
|
BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned computers.
|
||||||
|
|
||||||
BitLocker provides the maximum protection when used with a Trusted Platform Module (TPM) version 1.2 or later versions. The TPM is a hardware component installed in many newer computers by the computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer hasn't been tampered with while the system was offline.
|
BitLocker provides the maximum protection when used with a Trusted Platform Module (TPM) version 1.2 or later versions. The TPM is a hardware component installed in many newer computers by the computer manufacturers. It works with BitLocker to help protect user data and to ensure that a computer hasn't been tampered with while the system was offline.
|
||||||
@ -48,7 +33,7 @@ There are two additional tools in the Remote Server Administration Tools that ca
|
|||||||
- **BitLocker Drive Encryption Tools**. BitLocker Drive Encryption Tools include the command-line tools, manage-bde and repair-bde, and the BitLocker cmdlets for Windows PowerShell. Both manage-bde and the BitLocker cmdlets can be used to perform any task that can be accomplished through the
|
- **BitLocker Drive Encryption Tools**. BitLocker Drive Encryption Tools include the command-line tools, manage-bde and repair-bde, and the BitLocker cmdlets for Windows PowerShell. Both manage-bde and the BitLocker cmdlets can be used to perform any task that can be accomplished through the
|
||||||
BitLocker control panel, and they're appropriate to be used for automated deployments and other scripting scenarios. Repair-bde is provided for disaster recovery scenarios in which a BitLocker-protected drive can't be unlocked normally or by using the recovery console.
|
BitLocker control panel, and they're appropriate to be used for automated deployments and other scripting scenarios. Repair-bde is provided for disaster recovery scenarios in which a BitLocker-protected drive can't be unlocked normally or by using the recovery console.
|
||||||
|
|
||||||
[!INCLUDE [bitlocker](../../../../includes/licensing/bitlocker-enablement.md)]
|
[!INCLUDE [bitlocker](../../../../../includes/licensing/bitlocker-enablement.md)]
|
||||||
|
|
||||||
## System requirements
|
## System requirements
|
||||||
|
|
@ -1,29 +1,15 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker recovery guide
|
title: BitLocker recovery guide
|
||||||
description: This article for IT professionals describes how to recover BitLocker keys from Active Directory Domain Services (AD DS).
|
description: This article for IT professionals describes how to recover BitLocker keys from Active Directory Domain Services (AD DS).
|
||||||
ms.prod: windows-client
|
|
||||||
ms.technology: itpro-security
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
ms.reviewer: rafals
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker recovery guide
|
# BitLocker recovery guide
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article describes how to recover BitLocker keys from AD DS.
|
This article describes how to recover BitLocker keys from AD DS.
|
||||||
|
|
||||||
Organizations can use BitLocker recovery information saved in Active Directory Domain Services (AD DS) to access BitLocker-protected data. It's recommended to create a recovery model for BitLocker while planning for BitLocker deployment.
|
Organizations can use BitLocker recovery information saved in Active Directory Domain Services (AD DS) to access BitLocker-protected data. It's recommended to create a recovery model for BitLocker while planning for BitLocker deployment.
|
@ -13,12 +13,6 @@ metadata:
|
|||||||
ms.custom: bitlocker
|
ms.custom: bitlocker
|
||||||
title: BitLocker Security FAQ
|
title: BitLocker Security FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
||||||
questions:
|
questions:
|
@ -13,9 +13,6 @@ metadata:
|
|||||||
ms.custom: bitlocker
|
ms.custom: bitlocker
|
||||||
title: BitLocker To Go FAQ
|
title: BitLocker To Go FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
@ -13,10 +13,6 @@ metadata:
|
|||||||
ms.custom: bitlocker
|
ms.custom: bitlocker
|
||||||
title: BitLocker Upgrading FAQ
|
title: BitLocker Upgrading FAQ
|
||||||
summary: |
|
summary: |
|
||||||
**Applies to:**
|
|
||||||
- Windows 10 and later
|
|
||||||
- Windows Server 2016 and later
|
|
||||||
|
|
||||||
|
|
||||||
sections:
|
sections:
|
||||||
- name: Ignored
|
- name: Ignored
|
@ -1,29 +1,15 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker Use BitLocker Drive Encryption Tools to manage BitLocker
|
title: BitLocker Use BitLocker Drive Encryption Tools to manage BitLocker
|
||||||
description: This article for the IT professional describes how to use tools to manage BitLocker.
|
description: This article for the IT professional describes how to use tools to manage BitLocker.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker: Use BitLocker Drive Encryption Tools to manage BitLocker
|
# BitLocker: Use BitLocker Drive Encryption Tools to manage BitLocker
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article for the IT professional describes how to use tools to manage BitLocker.
|
This article for the IT professional describes how to use tools to manage BitLocker.
|
||||||
|
|
||||||
BitLocker Drive Encryption Tools include the command-line tools manage-bde and repair-bde and the BitLocker cmdlets for Windows PowerShell.
|
BitLocker Drive Encryption Tools include the command-line tools manage-bde and repair-bde and the BitLocker cmdlets for Windows PowerShell.
|
@ -1,19 +1,11 @@
|
|||||||
---
|
---
|
||||||
title: BitLocker Use BitLocker Recovery Password Viewer
|
title: BitLocker Use BitLocker Recovery Password Viewer
|
||||||
description: This article for the IT professional describes how to use the BitLocker Recovery Password Viewer.
|
description: This article for the IT professional describes how to use the BitLocker Recovery Password Viewer.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.collection:
|
ms.collection:
|
||||||
- highpri
|
- highpri
|
||||||
- tier1
|
- tier1
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# BitLocker: Use BitLocker Recovery Password Viewer
|
# BitLocker: Use BitLocker Recovery Password Viewer
|
Before Width: | Height: | Size: 4.0 KiB After Width: | Height: | Size: 4.0 KiB |
Before Width: | Height: | Size: 18 KiB After Width: | Height: | Size: 18 KiB |
Before Width: | Height: | Size: 395 KiB After Width: | Height: | Size: 395 KiB |
Before Width: | Height: | Size: 126 KiB After Width: | Height: | Size: 126 KiB |
Before Width: | Height: | Size: 69 KiB After Width: | Height: | Size: 69 KiB |
Before Width: | Height: | Size: 263 KiB After Width: | Height: | Size: 263 KiB |
Before Width: | Height: | Size: 18 KiB After Width: | Height: | Size: 18 KiB |
Before Width: | Height: | Size: 1.2 MiB After Width: | Height: | Size: 1.2 MiB |
Before Width: | Height: | Size: 118 KiB After Width: | Height: | Size: 118 KiB |
Before Width: | Height: | Size: 82 KiB After Width: | Height: | Size: 82 KiB |
Before Width: | Height: | Size: 96 KiB After Width: | Height: | Size: 96 KiB |
Before Width: | Height: | Size: 82 KiB After Width: | Height: | Size: 82 KiB |
Before Width: | Height: | Size: 91 KiB After Width: | Height: | Size: 91 KiB |
Before Width: | Height: | Size: 916 B After Width: | Height: | Size: 916 B |
@ -1,26 +1,12 @@
|
|||||||
---
|
---
|
||||||
title: Prepare the organization for BitLocker Planning and policies
|
title: Prepare the organization for BitLocker Planning and policies
|
||||||
description: This article for the IT professional explains how can to plan for a BitLocker deployment.
|
description: This article for the IT professional explains how can to plan for a BitLocker deployment.
|
||||||
ms.reviewer:
|
|
||||||
ms.prod: windows-client
|
|
||||||
ms.localizationpriority: medium
|
|
||||||
author: frankroj
|
|
||||||
ms.author: frankroj
|
|
||||||
manager: aaroncz
|
|
||||||
ms.topic: conceptual
|
ms.topic: conceptual
|
||||||
ms.date: 11/08/2022
|
ms.date: 11/08/2022
|
||||||
ms.custom: bitlocker
|
|
||||||
ms.technology: itpro-security
|
|
||||||
---
|
---
|
||||||
|
|
||||||
# Prepare an organization for BitLocker: Planning and policies
|
# Prepare an organization for BitLocker: Planning and policies
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows 11
|
|
||||||
- Windows Server 2016 and above
|
|
||||||
|
|
||||||
This article for the IT professional explains how to plan BitLocker deployment.
|
This article for the IT professional explains how to plan BitLocker deployment.
|
||||||
|
|
||||||
When BitLocker deployment strategy is defined, define the appropriate policies and configuration requirements based on the business requirements of the organization. The following sections will help with collecting information. Use this information to help with the decision-making process about deploying and managing BitLocker systems.
|
When BitLocker deployment strategy is defined, define the appropriate policies and configuration requirements based on the business requirements of the organization. The following sections will help with collecting information. Use this information to help with the decision-making process about deploying and managing BitLocker systems.
|
@ -0,0 +1,74 @@
|
|||||||
|
items:
|
||||||
|
- name: Overview
|
||||||
|
href: bitlocker-overview.md
|
||||||
|
- name: BitLocker device encryption
|
||||||
|
href: bitlocker-device-encryption-overview-windows-10.md
|
||||||
|
- name: BitLocker frequently asked questions (FAQ)
|
||||||
|
href: bitlocker-frequently-asked-questions.yml
|
||||||
|
items:
|
||||||
|
- name: Overview and requirements
|
||||||
|
href: bitlocker-overview-and-requirements-faq.yml
|
||||||
|
- name: Upgrading
|
||||||
|
href: bitlocker-upgrading-faq.yml
|
||||||
|
- name: Deployment and administration
|
||||||
|
href: bitlocker-deployment-and-administration-faq.yml
|
||||||
|
- name: Key management
|
||||||
|
href: bitlocker-key-management-faq.yml
|
||||||
|
- name: BitLocker To Go
|
||||||
|
href: bitlocker-to-go-faq.yml
|
||||||
|
- name: Active Directory Domain Services
|
||||||
|
href: bitlocker-and-adds-faq.yml
|
||||||
|
- name: Security
|
||||||
|
href: bitlocker-security-faq.yml
|
||||||
|
- name: BitLocker Network Unlock
|
||||||
|
href: bitlocker-network-unlock-faq.yml
|
||||||
|
- name: General
|
||||||
|
href: bitlocker-using-with-other-programs-faq.yml
|
||||||
|
- name: "Prepare your organization for BitLocker: Planning and policies"
|
||||||
|
href: prepare-your-organization-for-bitlocker-planning-and-policies.md
|
||||||
|
- name: BitLocker deployment comparison
|
||||||
|
href: bitlocker-deployment-comparison.md
|
||||||
|
- name: BitLocker basic deployment
|
||||||
|
href: bitlocker-basic-deployment.md
|
||||||
|
- name: Deploy BitLocker on Windows Server 2012 and later
|
||||||
|
href: bitlocker-how-to-deploy-on-windows-server.md
|
||||||
|
- name: BitLocker management
|
||||||
|
href: bitlocker-management-for-enterprises.md
|
||||||
|
- name: Enable Network Unlock with BitLocker
|
||||||
|
href: bitlocker-how-to-enable-network-unlock.md
|
||||||
|
- name: Use BitLocker Drive Encryption Tools to manage BitLocker
|
||||||
|
href: bitlocker-use-bitlocker-drive-encryption-tools-to-manage-bitlocker.md
|
||||||
|
- name: Use BitLocker Recovery Password Viewer
|
||||||
|
href: bitlocker-use-bitlocker-recovery-password-viewer.md
|
||||||
|
- name: BitLocker Group Policy settings
|
||||||
|
href: bitlocker-group-policy-settings.md
|
||||||
|
- name: BCD settings and BitLocker
|
||||||
|
href: bcd-settings-and-bitlocker.md
|
||||||
|
- name: BitLocker Recovery Guide
|
||||||
|
href: bitlocker-recovery-guide-plan.md
|
||||||
|
- name: BitLocker Countermeasures
|
||||||
|
href: bitlocker-countermeasures.md
|
||||||
|
- name: Protecting cluster shared volumes and storage area networks with BitLocker
|
||||||
|
href: protecting-cluster-shared-volumes-and-storage-area-networks-with-bitlocker.md
|
||||||
|
- name: Troubleshoot BitLocker
|
||||||
|
items:
|
||||||
|
- name: Troubleshoot BitLocker
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-issues-troubleshooting
|
||||||
|
- name: "BitLocker cannot encrypt a drive: known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-cannot-encrypt-a-drive-known-issues
|
||||||
|
- name: "Enforcing BitLocker policies by using Intune: known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/enforcing-bitlocker-policies-by-using-intune-known-issues
|
||||||
|
- name: "BitLocker Network Unlock: known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-network-unlock-known-issues
|
||||||
|
- name: "BitLocker recovery: known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-recovery-known-issues
|
||||||
|
- name: "BitLocker configuration: known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-configuration-known-issues
|
||||||
|
- name: Troubleshoot BitLocker and TPM issues
|
||||||
|
items:
|
||||||
|
- name: "BitLocker cannot encrypt a drive: known TPM issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-cannot-encrypt-a-drive-known-tpm-issues
|
||||||
|
- name: "BitLocker and TPM: other known issues"
|
||||||
|
href: /troubleshoot/windows-client/windows-security/bitlocker-and-tpm-other-known-issues
|
||||||
|
- name: Decode Measured Boot logs to track PCR changes
|
||||||
|
href: /troubleshoot/windows-client/windows-security/decode-measured-boot-logs-to-track-pcr-changes
|
@ -2,79 +2,7 @@ items:
|
|||||||
- name: Overview
|
- name: Overview
|
||||||
href: index.md
|
href: index.md
|
||||||
- name: BitLocker
|
- name: BitLocker
|
||||||
href: ../../information-protection/bitlocker/bitlocker-overview.md
|
href: bitlocker/toc.yml
|
||||||
items:
|
|
||||||
- name: Overview of BitLocker Device Encryption in Windows
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-device-encryption-overview-windows-10.md
|
|
||||||
- name: BitLocker frequently asked questions (FAQ)
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-frequently-asked-questions.yml
|
|
||||||
items:
|
|
||||||
- name: Overview and requirements
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-overview-and-requirements-faq.yml
|
|
||||||
- name: Upgrading
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-upgrading-faq.yml
|
|
||||||
- name: Deployment and administration
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-deployment-and-administration-faq.yml
|
|
||||||
- name: Key management
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-key-management-faq.yml
|
|
||||||
- name: BitLocker To Go
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-to-go-faq.yml
|
|
||||||
- name: Active Directory Domain Services
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-and-adds-faq.yml
|
|
||||||
- name: Security
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-security-faq.yml
|
|
||||||
- name: BitLocker Network Unlock
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-network-unlock-faq.yml
|
|
||||||
- name: General
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-using-with-other-programs-faq.yml
|
|
||||||
- name: "Prepare your organization for BitLocker: Planning and policies"
|
|
||||||
href: ../../information-protection/bitlocker/prepare-your-organization-for-bitlocker-planning-and-policies.md
|
|
||||||
- name: BitLocker deployment comparison
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-deployment-comparison.md
|
|
||||||
- name: BitLocker basic deployment
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-basic-deployment.md
|
|
||||||
- name: Deploy BitLocker on Windows Server 2012 and later
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-how-to-deploy-on-windows-server.md
|
|
||||||
- name: BitLocker management
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-management-for-enterprises.md
|
|
||||||
- name: Enable Network Unlock with BitLocker
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-how-to-enable-network-unlock.md
|
|
||||||
- name: Use BitLocker Drive Encryption Tools to manage BitLocker
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-use-bitlocker-drive-encryption-tools-to-manage-bitlocker.md
|
|
||||||
- name: Use BitLocker Recovery Password Viewer
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-use-bitlocker-recovery-password-viewer.md
|
|
||||||
- name: BitLocker Group Policy settings
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-group-policy-settings.md
|
|
||||||
- name: BCD settings and BitLocker
|
|
||||||
href: ../../information-protection/bitlocker/bcd-settings-and-bitlocker.md
|
|
||||||
- name: BitLocker Recovery Guide
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-recovery-guide-plan.md
|
|
||||||
- name: BitLocker Countermeasures
|
|
||||||
href: ../../information-protection/bitlocker/bitlocker-countermeasures.md
|
|
||||||
- name: Protecting cluster shared volumes and storage area networks with BitLocker
|
|
||||||
href: ../../information-protection/bitlocker/protecting-cluster-shared-volumes-and-storage-area-networks-with-bitlocker.md
|
|
||||||
- name: Troubleshoot BitLocker
|
|
||||||
items:
|
|
||||||
- name: Troubleshoot BitLocker
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-issues-troubleshooting
|
|
||||||
- name: "BitLocker cannot encrypt a drive: known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-cannot-encrypt-a-drive-known-issues
|
|
||||||
- name: "Enforcing BitLocker policies by using Intune: known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/enforcing-bitlocker-policies-by-using-intune-known-issues
|
|
||||||
- name: "BitLocker Network Unlock: known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-network-unlock-known-issues
|
|
||||||
- name: "BitLocker recovery: known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-recovery-known-issues
|
|
||||||
- name: "BitLocker configuration: known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-configuration-known-issues
|
|
||||||
- name: Troubleshoot BitLocker and TPM issues
|
|
||||||
items:
|
|
||||||
- name: "BitLocker cannot encrypt a drive: known TPM issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-cannot-encrypt-a-drive-known-tpm-issues
|
|
||||||
- name: "BitLocker and TPM: other known issues"
|
|
||||||
href: /troubleshoot/windows-client/windows-security/bitlocker-and-tpm-other-known-issues
|
|
||||||
- name: Decode Measured Boot logs to track PCR changes
|
|
||||||
href: /troubleshoot/windows-client/windows-security/decode-measured-boot-logs-to-track-pcr-changes
|
|
||||||
- name: Encrypted Hard Drive
|
- name: Encrypted Hard Drive
|
||||||
href: encrypted-hard-drive.md
|
href: encrypted-hard-drive.md
|
||||||
- name: Personal Data Encryption (PDE)
|
- name: Personal Data Encryption (PDE)
|
||||||
|