In the 'Advanced Settings' section, you can allow the user to postpone the restart for a certain number of days. For the BitLocker encryption process to occur, a computer has to be restarted.To opt for an alternative protection method for machines in which TPM is unavailable, toggle the setting 'Enable passphrase protection for machines without TPM.' This will prompt the user to enter a passphrase every time the computer is started.
#BITLOCKER DRIVE ENCRYPTION HOW TO#
How to create an encryption policy with which the full space is encrypted?įor full space encryption, enable only the 'Drive Encryption' setting and ensure that these options are disabled: 'Encrypt OS drives only' and 'Encrypt used space only.' By default, by enabling only the 'Drive Encryption' option, all drives and spaces will be fully encrypted. For more details, refer to this forum on full space encryption. The recommended solution to this security issue is full space BitLocker encryption. For computers that have been newly reset, files that were previously located on the disk can still be recovered if not overwritten by new information. Note: For optimal security, it is recommended that both used and unused spaces are encrypted. To encrypt only the used space, enable the option 'Encrypt used space only.' How to create an encryption policy with which only the used space is encrypted? Note: This option can be enabled for performance benefits such as quicker encryption time, however for optimal security, it is recommended that all drives (OS and data drives) are encrypted. This will ensure that all volumes in the OS drive are encrypted and that all other data drives will be or remain decrypted. To encrypt only the OS drive, enable the option 'Encrypt OS drives only' in the 'Encryption Settings' section. How to create an encryption policy with which only OS drives are encrypted? There are 3 types of encryption policies that can be created: Toggle the option 'Drive Encryption.' When this setting is enabled, the drives hereby mentioned in this policy will be BitLocker encrypted.Assign a name for your policy and if needed, add a description.Navigate to Desktop Central console > BitLocker > Policy creation > Create Policy.How to create an encryption policy in the BitLocker module? There are two main types of policies that can be constructed in Device Control Plus:
![bitlocker drive encryption bitlocker drive encryption](https://gravitypayments.com/wp-content/uploads/2020/02/Bit-Locker-9.png)
The numerous settings are easy to configure such that the data security and encryption needs for each computer can be met accordingly. The BitLocker add-on for Desktop Central enables the admin to quickly build flexible policies to encrypt drives.
![bitlocker drive encryption bitlocker drive encryption](https://i.postimg.cc/YCdMcm5Q/e80044ca-e1d4-40cc-92a7-e3515b621ad2.png)
BitLocker encryption requirements can vary for different machines within your network.