Jump to content

Recommended Posts

Posted

hi,

I have an existing cohort of ~100 laptops running Windows 7. I have been asked to encrypt the drives.

 

Anybody got experience of deploying Bitlocker or similar.

 

P.S. The machines do have TPM.

Posted

We didn't do bitlocker here, not because of lack of resources, just that truecrypt was better for us. Bitlocker v trucrypt on the laptops we did, bitlocker took 6-8 hours to do a 1TB HDD, whereas trucrypt was around 4-6 hours. It isn't much of a time difference, but can be the difference in the long run.

 

Also trucrypt allows multibooting (such as linux/windows) whereas bitlocker doesn't, so its worth considering also.

Posted
bitlocker took 6-8 hours to do a 1TB HDD

Did you increase the size of your "System Reserved" partition? I've found that makes a huge difference to the encryption times with Bitlocker. Ours is 1.2GB (rather than the default of 100MB-350MB).

  • Thanks 1
Posted
Yeh we bitlocker all laptops that have TPM modules. With the bitlocker stuffs in GPO it works a dream for key recovery. We weren't bothered by encryption times as they are done before depliyment
Posted
We didn't do bitlocker here, not because of lack of resources, just that truecrypt was better for us. Bitlocker v trucrypt on the laptops we did, bitlocker took 6-8 hours to do a 1TB HDD, whereas trucrypt was around 4-6 hours.

 

Weird! I've always found BL encryption MUCH faster than TC, and only use the latter when there is no TPM. I did find a post suggesting that it's possible to use BL on W8 without TPM, but have yet to test this theory.

 

Anyhow, never deployed BL en masse (only do staff laptops) so my only advice is that you may need to activate TPM in BIOS and to avoid changing partition size/structure after encryption.

Posted

We use SCCM to deploy our images here and just have it encrypting the laptops as an extra step in the task sequence. Recovery keys are stored in AD alongside the computer account automatically and we've had no issues whatsoever.

 

If build time is an important factor for you it's worth knowing that you have the option of either encrypting during the OS deployment itself or you can allow it to encrypt in the background after it's built. If you decide to allow it to encrypt in the background once it's built then you can easily knock ~4-6 hours off your build time and the overheads of it encrypting in the background aren't a massive issue as it will tend to only encrypt when the laptop isn't in heavy use.

Posted
Did you increase the size of your "System Reserved" partition? I've found that makes a huge difference to the encryption times with Bitlocker. Ours is 1.2GB (rather than the default of 100MB-350MB).

 

Ahhh didn't know about this. Will give it a go.

Posted
How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write.
Posted
How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write.

 

on my surface pro near 0 and being windows 8.1 you can set it to only encrypt used portions of the drive so it takes much less time to deploy

  • Thanks 1
Posted
How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write.

 

Not noticed one (no SSDs), but then I've only tested it on freshly-imaged machines. That said, not had complaints from staff so presumably OK.

  • Thanks 1
Posted
We use SCCM to deploy our images here and just have it encrypting the laptops as an extra step in the task sequence. Recovery keys are stored in AD alongside the computer account automatically and we've had no issues whatsoever.

 

If build time is an important factor for you it's worth knowing that you have the option of either encrypting during the OS deployment itself or you can allow it to encrypt in the background after it's built. If you decide to allow it to encrypt in the background once it's built then you can easily knock ~4-6 hours off your build time and the overheads of it encrypting in the background aren't a massive issue as it will tend to only encrypt when the laptop isn't in heavy use.

 

Do exactly the same here...works well - apart from staff who are adament that they are typing the right password and "it locks them out"....

  • Thanks 1
Posted
Do exactly the same here...works well - apart from staff who are adament that they are typing the right password and "it locks them out"....

 

Funnily enough just had this happen now!

Posted (edited)

We also bitlocker before deployment so bitlocker only takes around an hour tops to encrypt. Recovery is easy and it's all easy to manage.

 

EDIT: The drives are 350gb SSDs

Edited by cooka
Posted

SSD's and software encryption

 

http://www.anandtech.com/show/6891/hardware-accelerated-bitlocker-encryption-microsoft-windows-8-edrive-investigated-with-crucial-m500

 

 

 

http://www.anandtech.com/show/7572/samsung-ssd-news-1tb-840-evo-msata-rapid-for-840-pro-edrive-for-840-evo

 

Windows 8 or 8.1 should support e drive which takes advantage of the SSD's hardware encryption , only takes seconds or minutes to enable and doesn't have a performance hit , at least not as much as the software encryption does

 

Obviously the ssd in question has to support edrive which the M500 does and the 840 evo will after a firmware update as per the links

Posted

We're just in ten process of encrypting staff laptops with bitlocker

Non if our machines have TPMs so we're using USB keys to unlock them. Laptops are taking about 4/5 hours to encrypt but we just leave them overnight

 

We haven't seen any slow down of the laptops in normal use

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...