Techie2000 Posted February 7, 2016 Posted February 7, 2016 My school management team emailed me last week about an encryption tool and was wondering what people used? I've seen Bitlocker but have to say I haven't really seen much of anything on the reporting side from it? I've also looked at the Sophos SafeGuard Encryption and like its extensibility, but I haven;t had a quote for it yet, so I suppose that'll help me decide on that one! Does anyone have any recommendations? Reporting is an important thing as our Governors are keen to see whats happening.
DJ-1701 Posted February 7, 2016 Posted February 7, 2016 (edited) What kind of reporting are you looking for? In the past I have used CompuSec which has been free, though this only supports up to Windows 7 so moving forward I will be using Bitlocker. I believe Sophos Encryption only encrypts up to Windows 7 and just manages Bitlocker for Windows 8 and above. Edited February 7, 2016 by DJ-1701 1
jmak Posted February 7, 2016 Posted February 7, 2016 Bitlocker seems to have less impact on machine performance than Sophos - I haven't measured, but feels that way. I used Sophos because Bitlocker wasn't available on the version of Windows we had. In the Sophos console you can see a dashboard of which clients are encrypted - quite a popular approach seems to be to encrypt with Bitlocker and then manage with the Sophos console, but that only makes sense if you're not paying any extra to do that (it's included through our country anti virus provision). I'd be interested on what kind of reporting your governors are after - I would have thought a statement from you saying "all of our clients are encrypted using x product and it's applied by Group Policy" would be appropriate. 1
PotNoodleTech Posted February 8, 2016 Posted February 8, 2016 Worth noting that to use bitlocker on you're domain, you need to be licenced for the enterprise version of Windows client. 1
Techie2000 Posted February 8, 2016 Author Posted February 8, 2016 Thanks for the info! Does anyone have a good guide for deploying bitlocker? We have Win 7 Enterprise deployed but not sure how to go about deploying Bitlocker!
korifugi Posted February 8, 2016 Posted February 8, 2016 (edited) It's best set up through a GPO - With Win7 Enterprise, you've already got it installed. It's just a case of turning it on. The GPO for it is in Computer Configuration>Administrative Templates>Windows Components>BitLocker Drive Encryption. Edited February 8, 2016 by korifugi more info 1
LeMarchand Posted February 8, 2016 Posted February 8, 2016 IIRC if you're on Win 7 and your machines don't have TPM you will need a USB key set up to unlock the device. If you're on Windows 8 or later you can use a password. I was using TrueCrypt or later VeraCrypt for Win 7 clients without TPM, which was OK for me (didn't have that many to manage) but may be difficult if you have lots! 1
DJ-1701 Posted February 8, 2016 Posted February 8, 2016 IIRC if you're on Win 7 and your machines don't have TPM you will need a USB key set up to unlock the device. If you're on Windows 8 or later you can use a password. I was using TrueCrypt or later VeraCrypt for Win 7 clients without TPM, which was OK for me (didn't have that many to manage) but may be difficult if you have lots! I can confirm you are correct sir!
sted Posted February 8, 2016 Posted February 8, 2016 the main advantage of bitlocker is it stores the recovery keys in active directory so they are easy to find hard to loose. Yes pre 8(or 8.1 possibly) if the device diddnt have a tpm chip you needed a usb/sd card to store the user decryption information
LeMarchand Posted February 8, 2016 Posted February 8, 2016 the main advantage of bitlocker is it stores the recovery keys in active directory so they are easy to find hard to loose. Yep, but the opposite is true of a USB key!
sparkeh Posted February 8, 2016 Posted February 8, 2016 We use Bitlocker on Windows 8.1 and 10 machines and use a password to unlock. Had an absolute 'mare with Sophos Safeguard on Win 7 and getting bcd boot errors and was glad to see the back of it. As said above, from 8.1 onwards Safeguard just manages Bitlocker so can really see the point of it? Also, not sure what kind of reporting you are after?
sted Posted February 8, 2016 Posted February 8, 2016 Yep, but the opposite is true of a USB key! true but if laptop has an sd card glue it in lol there are no perfect answers but bitlocker is simpleish and works \and use 8.1/10 and the usb issue isnt an issue
jmak Posted February 8, 2016 Posted February 8, 2016 Worth noting that to use bitlocker on you're domain, you need to be licenced for the enterprise version of Windows client. From Windows 8 onwards you only need the Pro Editions of the operating system - not relevant for @Techie2000, but it was useful for me. Also means I can use it at home.
Michael Posted February 8, 2016 Posted February 8, 2016 The other difference worth noting, is Windows 7's version of Bitlocker and lots of other third party utilities will encrypt the whole volume. So if you have 100MB of data on a 1TB hard drive, it'll encrypt all that empty space. Windows 10's version of Bitlocker is more intelligent and will encrypt data 'on the fly' without having to encrypt the whole volume.
deKay Posted February 8, 2016 Posted February 8, 2016 Interested to know how people using Bitlocker with USB devices deal with staff and students using Macs or Chromebooks at school or at home.
Michael Posted February 8, 2016 Posted February 8, 2016 Interested to know how people using Bitlocker with USB devices deal with staff and students using Macs or Chromebooks at school or at home. There are no official solutions from Microsoft, only third party offerings by App developers. It's something Microsoft need to seriously look at, even just to offer 'read only' access on other platforms. They do for example offer an RDP client for Mac, so it's unclear as to why they can't offer a Bitlocker equivalent.
Techie2000 Posted February 8, 2016 Author Posted February 8, 2016 It's best set up through a GPO - With Win7 Enterprise, you've already got it installed. It's just a case of turning it on. The GPO for it is in Computer Configuration>Administrative Templates>Windows Components>BitLocker Drive Encryption. So far I have configured Bitlocker via GPO, however I assume I will need to run some form of script to initialize the encryption? Or is this to be done manually on any machine that needs encrypting via the wizard? I'm completely new to Bitlocker so apologies if I'm missing something!
sted Posted February 8, 2016 Posted February 8, 2016 So far I have configured Bitlocker via GPO, however I assume I will need to run some form of script to initialize the encryption? Or is this to be done manually on any machine that needs encrypting via the wizard? I'm completely new to Bitlocker so apologies if I'm missing something! it dosent turn on no but iirc mdt can do it as part of the task sequence but i prefer starting it manually so i know its done 1
fiza Posted June 23, 2016 Posted June 23, 2016 Does anyone know if when encrypting a laptop it can be switched off or not? Will the encryption resume without incident when the laptop is switched on again? With 1TB possibly taking over 33 hours to encrypt and staff not wanting to go without their laptops for that long I was hoping we could start the encryption and then hand the laptop back to them. I read this on technet but not sure if I believe it or not: What happens if the computer is turned off during encryption or decryption? If the computer is turned off or goes into hibernation, the BitLocker encryption and decryption process will resume where it stopped the next time Windows starts. This is true even if the power is suddenly unavailable.
DJ-1701 Posted June 23, 2016 Posted June 23, 2016 BitLocker when I have used it continues the process you last asked it to do even after reboot. Therefore if you asked it to encrypt, on reboot it will continue to do so.
sparkeh Posted June 23, 2016 Posted June 23, 2016 Bitlocker has always paused and resumed without incident for us. However, I never hand a laptop over until I know its finished anyway.
LeMarchand Posted June 23, 2016 Posted June 23, 2016 I've turned machines off during encryption and it's always been fine. Never tried a "power cut" sort of shutdown though.
fiza Posted June 23, 2016 Posted June 23, 2016 First on the list is the Head who cant do without the laptop for the time it takes to encrypt.
DJ-1701 Posted June 23, 2016 Posted June 23, 2016 I've turned machines off during encryption and it's always been fine. Never tried a "power cut" sort of shutdown though. I've had to force one off before and Bitlocker just continued like nothing happened when turned back on. I was worried as in the past I had used CompuSec and that is very unforgiving.
fiza Posted July 14, 2016 Posted July 14, 2016 We have been given a USB hard drive to encrypt which has data on it. It is also split into 2 partitions! Before we attempt to bitlocker it does anyone know how bitlocker deals with usb hard drives that have multiple partitions?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now