Академический Документы
Профессиональный Документы
Культура Документы
Procedure Notes:
Go to the
Start --> Control Panel --> Security Settings -> Enable Bitlocker
Note:
If this is an initial configuration you will get the error at the bottom of the
screen. You will need to 'Enable' the integrated TPM chip.
Start --> Control Panel --> Security Settings -> Enable Bitlocker
You will be prompted for credentials in order to make this change. Enter
your power user credentials.
The system will prompt you to save or print the Bitlocker Encryption Key.
(see below where to save the key)
Rename the Key to include the Laptop name and Save the Key to the
server
The system will check for compatibility and will reboot again to verify the
encryption key as stored in the TPM chip and to 'actually' enable and
make available the Bitlocker chip functionality.
Disk Encryption
Once the reboot is complete the computer will prompt for login as usual
and will begin the formal encrypt process. We have selected consolidated
logon and will not be requiring an additional pin or third party encryption
option. This should simplify this process for us in the configuration phase
and the users moving forward.
For the purposes of this procedure we will assume that this is a portable
device that has been in user for some time.
Run Checkdisk
This process, technically, can be skipped. However, for systems wherein the data is of a
sensitive or valuable nature that have been deployed for more than a year, it is highly
recommended
To insure that the decrypt completes without error best practices dictate that we compete a
disk verification with the following flags /r /f. Use both flags as the flag /f doesn't check for
bad sectors while /r does.
Click Start --> Search programs and Files --> type CMD.
You should receive the warning that ChkDsk cannot run because the volume is in use by
another process. Would you like to schedule this volume to be checked the next time the
system restarts? (Y/N)
Type Y (for Yes, obviously ;P ) and then press ENTER to schedule the disk check, and then
restart your computer to start the disk check. Depending upon the size and age of the drive
this process could complete relatively quickly (winin 10 minutes) or it could take hours.
This process will both locate bad sectors, and recover readable information.
Decrypt Process
Start --> Settings --> Control Panel --> Turn Off Bitlocker