Jump to content

Recommended Posts

Posted

I love acronyms as much as the next man and have a few questions about the 3 above...

 

...we are using laptops supplied by @VeryPC_Colin_M (thanks Colin!) that have a TPM2 chip onboard. When we installed Windows 10 onto these we did it from standard media and with UEFI/Secure boot turned off. As GDPR is coming we are starting to look at ensuring all laptops are encrypted so::

 

Can I go from a non-UEFI, non-secureboot Windows 10 to a fully encrypted system without having to re-install everything?

If I need to re-install everything will I need a different version of Windows? I've seen references to UEFI enabled Windows10, is that actually a thing?

If I turn on UEFI in the BIOS the laptop refuses to boot so I'm guessing t will be a re-install...but would a windows image backup work? Backup, configure UEFI/TPM and then restore from backup - or does the Windows image backup work at the BIOS level?

Posted

Morning DavePA, yes, you can just enable encryption and it should be able to just encrypt the HDD.

As long as you're not using Windows 10 home you can use Bitlocker.

 

UEFI is just the booting method (rather than BIOS), you don't need to enable UEFI. You'll need to enable TPM and look at using GPO to enable bitlocker encryption.

Posted (edited)

If you're looking at doing this widespread, you're best off just doing a full reinstall otherwise you're going to waste a lot of time going round doing Windows repairs after enabling UEFI boot (Windows will have to remake the boot partition and associated files). As far as BitLocker goes you don't need UEFI, or even a TPM with Windows 8.1 and up. SecureBoot is probably worth the hassle nowadays though. You don't need any special version of Windows for UEFI, so long as UEFI boot is enabled on the machine, Windows will set it self up for it during install.

 

@ReadTheNetwork you do need to enable UEFI boot, it's a UEFI option and Microsoft are starting to force people to use it over the old BIOS boot method because it's more secure.

Edited by Blue_Cookeh
Posted
Initially it's going to be my machine only but in time it will be all new machines plus any old ones that are not due for replacement this year. We use SCCM as a deployment tool so for new machines it should be easy and I'm hoping the guides that I found will make it a relatively painless (although probably quite lengthy) process to do existing machines.
Posted

I've not looked much on the VeryPC hardware but this article might be of use. You can create task sequences which flash/update the BIOS, then enable Bitlocker etc. But to do this, you'll need tools for the motherboard which allows you to do this. I have it working for some hardware but unfortunately not all.

 

HP has a tool called BiosConfigUtility64.

Maybe you could use the same tool or similar?

https://gallery.technet.microsoft.com/scriptcenter/SCCM-2012-Automatically-a505f1a7

Posted
As far as BitLocker goes you don't need UEFI, or even a TPM with Windows 8.1 and up. SecureBoot is probably worth the hassle nowadays though.

 

I think this may be hardware dependent. I recently had some laptops that just wouldn't activate Bitlocker unless I used UEFI: http://www.edugeek.net/forums/o-s-deployment/169815-uefi-image-problems.html#post1462845

@DavePa: I used the same VM to create the image from, but needed a "UEFI" capture and unattend file - so now I have "Standard" and "UEFI" capture and deploy images. (But plan on ditching the standard when/if all machines are UEFI compatible).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...