DavePa Posted March 31, 2017 Posted March 31, 2017 I love acronyms as much as the next man and have a few questions about the 3 above... ...we are using laptops supplied by @VeryPC_Colin_M (thanks Colin!) that have a TPM2 chip onboard. When we installed Windows 10 onto these we did it from standard media and with UEFI/Secure boot turned off. As GDPR is coming we are starting to look at ensuring all laptops are encrypted so:: Can I go from a non-UEFI, non-secureboot Windows 10 to a fully encrypted system without having to re-install everything? If I need to re-install everything will I need a different version of Windows? I've seen references to UEFI enabled Windows10, is that actually a thing? If I turn on UEFI in the BIOS the laptop refuses to boot so I'm guessing t will be a re-install...but would a windows image backup work? Backup, configure UEFI/TPM and then restore from backup - or does the Windows image backup work at the BIOS level?
ReadTheNetwork Posted April 4, 2017 Posted April 4, 2017 Morning DavePA, yes, you can just enable encryption and it should be able to just encrypt the HDD. As long as you're not using Windows 10 home you can use Bitlocker. UEFI is just the booting method (rather than BIOS), you don't need to enable UEFI. You'll need to enable TPM and look at using GPO to enable bitlocker encryption.
Blue_Cookeh Posted April 4, 2017 Posted April 4, 2017 (edited) If you're looking at doing this widespread, you're best off just doing a full reinstall otherwise you're going to waste a lot of time going round doing Windows repairs after enabling UEFI boot (Windows will have to remake the boot partition and associated files). As far as BitLocker goes you don't need UEFI, or even a TPM with Windows 8.1 and up. SecureBoot is probably worth the hassle nowadays though. You don't need any special version of Windows for UEFI, so long as UEFI boot is enabled on the machine, Windows will set it self up for it during install. @ReadTheNetwork you do need to enable UEFI boot, it's a UEFI option and Microsoft are starting to force people to use it over the old BIOS boot method because it's more secure. Edited April 4, 2017 by Blue_Cookeh
DavePa Posted April 4, 2017 Author Posted April 4, 2017 I had a look at this over the weekend and found a couple of guides on how to do it: https://social.technet.microsoft.com/wiki/contents/articles/14286.converting-windows-bios-installation-to-uefi.aspx https://superuser.com/questions/389971/how-to-move-an-existing-installation-of-window-7-64bit-to-uefi-from-legacy Just need to find time to be brave and go for it - but not that bave, I'll ensure I have a backup 1st
DavePa Posted April 4, 2017 Author Posted April 4, 2017 Initially it's going to be my machine only but in time it will be all new machines plus any old ones that are not due for replacement this year. We use SCCM as a deployment tool so for new machines it should be easy and I'm hoping the guides that I found will make it a relatively painless (although probably quite lengthy) process to do existing machines.
ReadTheNetwork Posted April 4, 2017 Posted April 4, 2017 I've not looked much on the VeryPC hardware but this article might be of use. You can create task sequences which flash/update the BIOS, then enable Bitlocker etc. But to do this, you'll need tools for the motherboard which allows you to do this. I have it working for some hardware but unfortunately not all. HP has a tool called BiosConfigUtility64. Maybe you could use the same tool or similar? https://gallery.technet.microsoft.com/scriptcenter/SCCM-2012-Automatically-a505f1a7
LeMarchand Posted April 4, 2017 Posted April 4, 2017 As far as BitLocker goes you don't need UEFI, or even a TPM with Windows 8.1 and up. SecureBoot is probably worth the hassle nowadays though. I think this may be hardware dependent. I recently had some laptops that just wouldn't activate Bitlocker unless I used UEFI: http://www.edugeek.net/forums/o-s-deployment/169815-uefi-image-problems.html#post1462845 @DavePa: I used the same VM to create the image from, but needed a "UEFI" capture and unattend file - so now I have "Standard" and "UEFI" capture and deploy images. (But plan on ditching the standard when/if all machines are UEFI compatible).
ReadTheNetwork Posted April 4, 2017 Posted April 4, 2017 I've managed to build laptops using bitlocker without UEFI, but I guess the newer models might enforce UEFI for TPM.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now