Jump to content

Recommended Posts

Posted

We are a very small Junior School and use a set of 2 USB disks for the backup of the server.

 

The disks are alternated daily and taken off-site overnight.

 

Using the integrated Windows Server Backup application, the OS doesn't give the drives a letter.

 

Given the nature of the data contained in the backups I need to have these disks encrypted.

 

A little Googling has pointed me in the direction of Bitlocker and I would like to ask how easy and safe enabling this will be.

 

Is it as simple as giving the disks a drive letter and turning on Bitlocker on the server?

 

Will I be OK giving both disks in the set the same drive letter (as they are only used alternately)?

 

What are the chances of having an issue and losing all the backup data (VSS is the method used I think and it appears to alternate between full and some sort of incremental backup spanning both disks)?

Posted
If it's Bitlockered to the TPM on the server, and the server MB dies, it will be difficult to recover! If you have a second DC, the Bitlocker recovery keys can be stored in AD to aid this, but if your entire AD goes down that's out of the window. Some possibility of a second DC would be my first port of call here - it doesn't need to be much of a thing (a Microserver or a NUC will do it).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...