Rod Posted May 13, 2014 Posted May 13, 2014 hi, I have an existing cohort of ~100 laptops running Windows 7. I have been asked to encrypt the drives. Anybody got experience of deploying Bitlocker or similar. P.S. The machines do have TPM.
featured_spectre Posted May 13, 2014 Posted May 13, 2014 We didn't do bitlocker here, not because of lack of resources, just that truecrypt was better for us. Bitlocker v trucrypt on the laptops we did, bitlocker took 6-8 hours to do a 1TB HDD, whereas trucrypt was around 4-6 hours. It isn't much of a time difference, but can be the difference in the long run. Also trucrypt allows multibooting (such as linux/windows) whereas bitlocker doesn't, so its worth considering also.
Arthur Posted May 13, 2014 Posted May 13, 2014 bitlocker took 6-8 hours to do a 1TB HDD Did you increase the size of your "System Reserved" partition? I've found that makes a huge difference to the encryption times with Bitlocker. Ours is 1.2GB (rather than the default of 100MB-350MB). 1
featured_spectre Posted May 13, 2014 Posted May 13, 2014 We altered the default from 350MB to 1GB flat.
markwilfan Posted May 13, 2014 Posted May 13, 2014 Yeh we bitlocker all laptops that have TPM modules. With the bitlocker stuffs in GPO it works a dream for key recovery. We weren't bothered by encryption times as they are done before depliyment
LeMarchand Posted May 14, 2014 Posted May 14, 2014 We didn't do bitlocker here, not because of lack of resources, just that truecrypt was better for us. Bitlocker v trucrypt on the laptops we did, bitlocker took 6-8 hours to do a 1TB HDD, whereas trucrypt was around 4-6 hours. Weird! I've always found BL encryption MUCH faster than TC, and only use the latter when there is no TPM. I did find a post suggesting that it's possible to use BL on W8 without TPM, but have yet to test this theory. Anyhow, never deployed BL en masse (only do staff laptops) so my only advice is that you may need to activate TPM in BIOS and to avoid changing partition size/structure after encryption.
Sam_Brown Posted May 14, 2014 Posted May 14, 2014 We use SCCM to deploy our images here and just have it encrypting the laptops as an extra step in the task sequence. Recovery keys are stored in AD alongside the computer account automatically and we've had no issues whatsoever. If build time is an important factor for you it's worth knowing that you have the option of either encrypting during the OS deployment itself or you can allow it to encrypt in the background after it's built. If you decide to allow it to encrypt in the background once it's built then you can easily knock ~4-6 hours off your build time and the overheads of it encrypting in the background aren't a massive issue as it will tend to only encrypt when the laptop isn't in heavy use.
Sam_Brown Posted May 14, 2014 Posted May 14, 2014 Did you increase the size of your "System Reserved" partition? I've found that makes a huge difference to the encryption times with Bitlocker. Ours is 1.2GB (rather than the default of 100MB-350MB). Ahhh didn't know about this. Will give it a go.
Duke5A Posted May 15, 2014 Posted May 15, 2014 How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write.
sted Posted May 15, 2014 Posted May 15, 2014 How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write. on my surface pro near 0 and being windows 8.1 you can set it to only encrypt used portions of the drive so it takes much less time to deploy 1
LeMarchand Posted May 15, 2014 Posted May 15, 2014 How much of a performance hit do you guys see when running Bit Locker? Laptops with mechanical drives are already painfully slow and this worried me implementing this would only exacerbate the problem. Our standard fleet of laptops right now is the Dell Latitude E5400 with 5400 RPM drives that do about 60MB/59MB on sequential read/write. Not noticed one (no SSDs), but then I've only tested it on freshly-imaged machines. That said, not had complaints from staff so presumably OK. 1
TheScarfedOne Posted May 15, 2014 Posted May 15, 2014 We use SCCM to deploy our images here and just have it encrypting the laptops as an extra step in the task sequence. Recovery keys are stored in AD alongside the computer account automatically and we've had no issues whatsoever. If build time is an important factor for you it's worth knowing that you have the option of either encrypting during the OS deployment itself or you can allow it to encrypt in the background after it's built. If you decide to allow it to encrypt in the background once it's built then you can easily knock ~4-6 hours off your build time and the overheads of it encrypting in the background aren't a massive issue as it will tend to only encrypt when the laptop isn't in heavy use. Do exactly the same here...works well - apart from staff who are adament that they are typing the right password and "it locks them out".... 1
Sam_Brown Posted May 15, 2014 Posted May 15, 2014 Do exactly the same here...works well - apart from staff who are adament that they are typing the right password and "it locks them out".... Funnily enough just had this happen now!
cooka Posted May 15, 2014 Posted May 15, 2014 (edited) We also bitlocker before deployment so bitlocker only takes around an hour tops to encrypt. Recovery is easy and it's all easy to manage. EDIT: The drives are 350gb SSDs Edited May 15, 2014 by cooka
mac_shinobi Posted May 15, 2014 Posted May 15, 2014 SSD's and software encryption http://www.anandtech.com/show/6891/hardware-accelerated-bitlocker-encryption-microsoft-windows-8-edrive-investigated-with-crucial-m500 http://www.anandtech.com/show/7572/samsung-ssd-news-1tb-840-evo-msata-rapid-for-840-pro-edrive-for-840-evo Windows 8 or 8.1 should support e drive which takes advantage of the SSD's hardware encryption , only takes seconds or minutes to enable and doesn't have a performance hit , at least not as much as the software encryption does Obviously the ssd in question has to support edrive which the M500 does and the 840 evo will after a firmware update as per the links
Arthur Posted May 15, 2014 Posted May 15, 2014 The drives are 350GB SSDs That's an unusual size for an SSD.
mac_shinobi Posted May 15, 2014 Posted May 15, 2014 That's an unusual size for an SSD. I was thinking that but thought it was most likely a typo
jamin100 Posted May 15, 2014 Posted May 15, 2014 We're just in ten process of encrypting staff laptops with bitlocker Non if our machines have TPMs so we're using USB keys to unlock them. Laptops are taking about 4/5 hours to encrypt but we just leave them overnight We haven't seen any slow down of the laptops in normal use
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now