To the famous Diana Ross tune I’m Coming Out*
I’m BitLocker’d up, I want the world to know, Got to let it show, I’m BitLocker’d up, I want the world to know, Got to let it show…
I’m BitLocker’d up,
I want the world to know,
Got to let it show,
Got to let it show…
I don’t know why it took me so long to get started. My new laptop has a TPM chip in it, and even though it doesn’t contain any customer data on it, it deserves to be encrypted. And so, this morning I went into Control Panel and set BitLocker encryption. It was an incredibly easy process. To demonstrate, here’s the four things I had to do:
And for four hours, this message moved across my screen while I continued working
And that’s it. I’ve now got a fully encrypted laptop, with an encryption system certified by the CESG (The Govt’s National Technical Authority for Information Assurance).
Having read that last week’s data loss could be up to 1.7 million people’s records (is anybody keeping a count?), then I will sleep easier..
(And if you just want to BitLocker an USB memory stick, to protect some data being transported, read Jerry’s BitLocker instructions here)
* Note to self: If Diana Ross song leads in wrong direction, I might have to disable comments on this post!
As far as I'm aware Bitlocker is not available to Vista Business user, only Ultimate & Enterprise (http://technet.microsoft.com/en-us/library/cc766200.aspx#BKMK_HSRequirements).
I wholeheartedly agree with you though. It is such a simple process I can't understand why it isn't more commonplace to do this within any business (government or otherwise)as standard rollout procedure
Hi Thommck
The trick is to buy the right licence at the point you get your computer, or upgrade, as BitLocker is part of Software Assurance.
I've tried to simplify the steps on this blog post:
http://blogs.msdn.com/ukschools/archive/2008/09/25/making-sure-you-buy-the-right-version-of-windows.aspx
(And I agree entirely with the comment about the fact that this should just be standard practice on a rollout - it is much easier to do it at install time - mainly because it saves time, and you can be absolutely sure you've got secure laptops all over the school)
Ray