Jump to content

Windows 10 UEFI drive encryption nightmare cant use bitlocker (No TPM) or veracrypt!


Recommended Posts

Posted

Hi All,

 

I need to encrypt the hard drives of 20 staff laptops asap, I cant use bitlocker because the laptops don't have the TPM chip for full encryption, and as some of the laptops are 5 years old when I try to encrypt using Veracrypt it shows an error saying some sectors are unreadable it trys to write 0 to them sectors but it doesn't get any further along. Have also tried Compusec Free software but doesn't install and just says check log. Also tried using another program but it wasn't compatible with UEFI bios/ hard drives.

 

Trying chkdsk now with /f and /r then veracrypt again but not having much confidence.

 

Anymore further ideas I can try as I'm aware the deadline is approaching quickly!

 

Thanks in advance

 

Danny

Posted (edited)

Not tried with W10, but there's a group policy to allow you to use Bitlocker on non-TPM drives. Works with 8.1.

 

P.S. Also with 8.1, have used VeraCrypt on some very old laptops without the sort of problem you describe. I normally go for the whole system apart from the Host area, IIRC.

Edited by LeMarchand
Posted
Not tried with W10, but there's a group policy to allow you to use Bitlocker on non-TPM drives. Works with 8.1.

 

P.S. Also with 8.1, have used VeraCrypt on some very old laptops without the sort of problem you describe. I normally go for the whole system apart from the Host area, IIRC.

 

You're right, details about Bitlocking Windows 10 without TPM chips can be found here: https://www.windowscentral.com/how-use-bitlocker-encryption-windows-10

Posted

It can do but then you need something like a USB to plug in to have the key to decrypt it which is a bit faffy :p

 

Generally though if Veracrypt is failing I'd try a new HDD in it and use Veracrypt, would be an easy test to see if it is just a HDD issue as bitlocker would have the same if so

 

Steve

Posted
Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it?

 

It's still encrypted, it's just the method of decrypting is different, Bitlocker without TPM is like any other encryption without TPM. It's password protected.

The TPM under certain conditions allows automatic unlocking of the drive on bootup without the need for a password.

  • Thanks 1
Posted
Yes we have used this method on many old laptops and it works fine. Lots of users don't shut down the laptop these days so it won't prompt them every time they need to use the laptop etc. You can also change the settings for usb drives once your doing this so encryption is enforced on those as well. That's what we have done for staff laptops that are used exclusively at home. We've also paid for extra licences for our cloud managed AV so we have greater visibility, and adds in some web filtering of malicious sites to help with protection against data loss.
Posted (edited)

I'm not sure what problems people have been seeing with not being able to encrypt the entire drive without a TPM chip but I've not had a problem doing it and nearly all of the laptops on site don't have one. I configured the below GPO and it's been working fine...

 

Untitled.png

 

They get prompted for a password at boot up.

Edited by NetworkServices
Posted
Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it?

 

Have you tried it?

 

After you've set and applied the GPO to allow it, it takes a few seconds to start the Bitlocker Wizard and you are given the option to encrypt the whole drive (takes the longest time) or just where the current data is being stored.

 

Even if you choose the quicker option of just the current data, it will still encrypt anything new that is saved on the laptop on the fly.

Posted
have used bitlocker at a previous school without tpm and using usb pens to boot. You can store recovery key in AD - when staff break/lose/forget the pen you can make them type in a really long recovery key :-)
Posted
Yep done a load of non-TPM laptops with bitlocker encryption of the whole drive. Not even had any teacher complaints !
Posted
Yes Non-TPM machines will bitlock fine, you don't need a usb key if it set up correctly using the GPO's. I have found the TPM chips to be very very problematic, mostly certain models of machines. Locking out all the time, not accepting PINS unless the network cable is plugged in, lots of weird stuff. HP EliteBook 840 G2's are the worst, only way to get them working was turn off the TPM, or, get the Motherboard replaced, incidentally TPM chip was the same model and firmware revision so go figure.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...