Sparta6 Posted May 15, 2018 Posted May 15, 2018 Hi All, I need to encrypt the hard drives of 20 staff laptops asap, I cant use bitlocker because the laptops don't have the TPM chip for full encryption, and as some of the laptops are 5 years old when I try to encrypt using Veracrypt it shows an error saying some sectors are unreadable it trys to write 0 to them sectors but it doesn't get any further along. Have also tried Compusec Free software but doesn't install and just says check log. Also tried using another program but it wasn't compatible with UEFI bios/ hard drives. Trying chkdsk now with /f and /r then veracrypt again but not having much confidence. Anymore further ideas I can try as I'm aware the deadline is approaching quickly! Thanks in advance Danny
LeMarchand Posted May 15, 2018 Posted May 15, 2018 (edited) Not tried with W10, but there's a group policy to allow you to use Bitlocker on non-TPM drives. Works with 8.1. P.S. Also with 8.1, have used VeraCrypt on some very old laptops without the sort of problem you describe. I normally go for the whole system apart from the Host area, IIRC. Edited May 15, 2018 by LeMarchand
DJ-1701 Posted May 15, 2018 Posted May 15, 2018 Not tried with W10, but there's a group policy to allow you to use Bitlocker on non-TPM drives. Works with 8.1. P.S. Also with 8.1, have used VeraCrypt on some very old laptops without the sort of problem you describe. I normally go for the whole system apart from the Host area, IIRC. You're right, details about Bitlocking Windows 10 without TPM chips can be found here: https://www.windowscentral.com/how-use-bitlocker-encryption-windows-10
Sparta6 Posted May 15, 2018 Author Posted May 15, 2018 Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it?
Steve21 Posted May 15, 2018 Posted May 15, 2018 It can do but then you need something like a USB to plug in to have the key to decrypt it which is a bit faffy Generally though if Veracrypt is failing I'd try a new HDD in it and use Veracrypt, would be an easy test to see if it is just a HDD issue as bitlocker would have the same if so Steve
LeMarchand Posted May 15, 2018 Posted May 15, 2018 Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it? I thought it did, but you do need to set a password or, as @Steve21 says use a USB.
DJ-1701 Posted May 15, 2018 Posted May 15, 2018 Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it? It's still encrypted, it's just the method of decrypting is different, Bitlocker without TPM is like any other encryption without TPM. It's password protected. The TPM under certain conditions allows automatic unlocking of the drive on bootup without the need for a password. 1
atcoates Posted May 15, 2018 Posted May 15, 2018 Yes we have used this method on many old laptops and it works fine. Lots of users don't shut down the laptop these days so it won't prompt them every time they need to use the laptop etc. You can also change the settings for usb drives once your doing this so encryption is enforced on those as well. That's what we have done for staff laptops that are used exclusively at home. We've also paid for extra licences for our cloud managed AV so we have greater visibility, and adds in some web filtering of malicious sites to help with protection against data loss.
NetworkServices Posted May 15, 2018 Posted May 15, 2018 (edited) I'm not sure what problems people have been seeing with not being able to encrypt the entire drive without a TPM chip but I've not had a problem doing it and nearly all of the laptops on site don't have one. I configured the below GPO and it's been working fine... They get prompted for a password at boot up. Edited May 15, 2018 by NetworkServices
Fazza Posted May 15, 2018 Posted May 15, 2018 Ive read about bitlocker without TPM but it doesn't encrypt the whole drive does it? Have you tried it? After you've set and applied the GPO to allow it, it takes a few seconds to start the Bitlocker Wizard and you are given the option to encrypt the whole drive (takes the longest time) or just where the current data is being stored. Even if you choose the quicker option of just the current data, it will still encrypt anything new that is saved on the laptop on the fly.
maark Posted May 15, 2018 Posted May 15, 2018 have used bitlocker at a previous school without tpm and using usb pens to boot. You can store recovery key in AD - when staff break/lose/forget the pen you can make them type in a really long recovery key :-)
atcoates Posted May 15, 2018 Posted May 15, 2018 Password bit here. Select “Enabled” at the top of the window, and ensure the “Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)” checkbox is enabled here. https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/
XiJ Posted May 15, 2018 Posted May 15, 2018 Yep done a load of non-TPM laptops with bitlocker encryption of the whole drive. Not even had any teacher complaints !
rosslaing Posted May 16, 2018 Posted May 16, 2018 Yes Non-TPM machines will bitlock fine, you don't need a usb key if it set up correctly using the GPO's. I have found the TPM chips to be very very problematic, mostly certain models of machines. Locking out all the time, not accepting PINS unless the network cable is plugged in, lots of weird stuff. HP EliteBook 840 G2's are the worst, only way to get them working was turn off the TPM, or, get the Motherboard replaced, incidentally TPM chip was the same model and firmware revision so go figure.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now