Home

How to Encrypt your Windows 7 Hard Disk with BitLocker

Comments | Serdar Yegulalp, BYTE | July 14, 2011 03:17 AM


BYTE -- Sad but true. Your IT guy has to enable BitLocker in Windows 7 before you can use this excellent encryption tool. So talk IT into it. I've included instructions at the end of this piece in case you need to help them out a bit.

Once it is enabled, it's time to get going with encrypting your drive. First, find Bitlocker on your PC Windows 7 system drive. Right click on the drive and select Turn on BitLocker.


BitLocker will scan your system to make sure the setup process can proceed. It might inform you that a new system drive will be created from free space on drive C. This is where BitLocker stores its boot-time components . After this is done, reboot.


Next, configure the decryption key. Just plug in a USB drive with the decryption key on it at boot time. Or supply a PIN at startup for additional security.


When you select Require a Startup Key, the system will prompt you to insert a USB flash drive. This will store the decryption key. It'll also prompt you to save a separate copy of the recovery key, which you should save to decrypt the drive in the event the Startup key ever gets damaged or goes missing.

TIP: Don't save the recovery key to the same place as your Startup key. It's like putting your house and car keys on same ring. Not smart.



Before starting the encryption process, BitLocker will offer to run a system check. This ensures the Startup key is readable at boot time and that decryption works. The whole process shouldn’t take more than a couple of minutes, and I strongly recommend you take it up on its offer.



Note: When your system boots with the Startup key plugged in, a message that says Remove disks or other media could pop up. If it does, press any key to restart.

CAUTION: Do not remove the startup key when you see this message. If you take the key out at this time, the startup check will fail and you’ll have to begin again from a much earlier step. So just press a key and continue the boot process.

Once the startup check succeeds, BitLocker will begin encrypting the system drive in the background. The encryption process could take several hours. During this time the computer will still be usable -- and in fact even be suspended, shut down or restarted.

That said, the system will be slower respond while it encrypts the system drive. Don’t expect to get a great deal done at this time.

If you double-click on the tray icon for BitLocker, you can see a progress window for the encryption process.


Drives encrypted by BitLocker will have a lock icon. Note that only the system drive has been protected. Notice the other drives in this system, which are for such auxiliary user data as downloads, are not encrypted. You'll have to encrypt them manually.


Remember, BitLocker is included in most versions of Windows, but not in home versions. You'll have to seek another solution, like TrueCrypt.

Enjoy your newly secure boot drive.

As promised at the beginning, your system administrator will have enable BitLocker in Windows. Here's a guide you can show them to help them figure that out.

FOR ADMINISTRATORS: If you've got BitLocker up and visible on your system drive, just jump ahead to the configure process. Launch gpedit.msc by typing that command in the Start Menu’s Search box and pressing Enter.

Navigate to Local Computer Policy >> Computer Configuration >> Administrative Templates >> Windows Components >> BitLocker Drive Encryption >> Operating System. Here is what you'll see.


Double-click on Require additional authentication at startup and select Enabled. Then check this: Allow BitLocker without a compatible TPM. The other options should each be set to Allow. Click OK and close the Group Policy Editor.


Based in New York, Serdar Yegululp is managing editor of reviews at BYTE. Follow him @syegulalp or email him at Serdar.Yepululp@BYTE.com.

Follow Serdar Yegulalp and BYTE on Twitter and Google+:



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events