0

I would like to turn on BitLocker encryption on a remote computer I don't have physical access to. What I am afraid of is that:

  • The operating system will not be able to boot after enabling BitLocker (for example, will stuck on some screen asking for password, key or something like that and will need a physical access)
  • The operating system will encrypt all the drives, not only several of them selected by me
  • The operating system will automatically encrypt every drive plugged in in the future

How justified are these fears?

1 Answer 1

0

The operating system will not be able to boot after enabling BitLocker (for example, will stuck on some screen asking for password, key or something like that and will need a physical access)

Guaranteed if the machine does not have a TPM (as that's the default passwordless unlock mechanism), but also possible even if it does.

With a TPM, the "recovery password" screen is much less likely to occur if Secure Boot is enabled, but there is still no guarantee that you can avoid it.

The operating system will encrypt all the drives, not only several of them selected by me

"Enabling" BitLocker only enables it on the selected partition. If you enable it on the system volume, it has no effect on data partitions.

BitLocker in "hardware" mode (when it uses the disk's built-in TCG OPAL encryption) may affect other partitions on the same physical disk, but not on other disks. Windows stopped using BitLocker in hardware mode by default a long while ago.

The operating system will automatically encrypt every drive plugged in in the future

BitLocker doesn't do that. Some third-party "data leak prevention" products might.

I don't have physical access to

Next time make sure your server has iLO / IDRAC / IP-KVM.

You must log in to answer this question.

Not the answer you're looking for? Browse other questions tagged .