|
Which laptops support TPM for BitLocker?
Haven’t identified a single one yet that has a Vista driver updated BIOS. I’ll update this Q&A as I learn of ones that do. Please keep me informed!
What happens if we lose the startup key or the TPM breaks?
You will only be able to recover the data if you can locate a copy of the recovery key. BitLocker allows you to save and/or print the recovery at the time you set up BitLocker. You can also configure Vista to automatically save the recovery key to Active Directory. For more help see my decision tree.
What’s the best way to manage recovery keys?
- If you are relatively small shop you could simply keep a USB drive around expressly for the purpose of storing recovery keys. BitLocker creates a unique file name for each recovery key which means you can store them all in the same place. Of course, you need to keep the recovery key USB drive secure and maintain a backup of it off-site. The easiest way to do this might be to back it up to a secure folder on any server that is regularly backed up to offsite storage.
- You can also save recovery keys to a shared folder on a file server. You could set up the permissions on the folder to allow everyone List and Create but limit Read access to administrators. That way you could save recovery keys to the folder as any user but users wouldn’t be able to access each other’s keys. BitLocker creates a unique file name for each recovery key and displays this when you try to recover a PC. That makes it easy to locate the correct file.
- If you are a larger shop, consider using the store to Active Directory feature. In fact, group policy allows you to require a successful save to Active Directory before enabling BitLocker.
- For more help see my decision tree.
What does it take to keep recovery keys in Active Directory?
You have to update the AD schema before Vista can store recovery keys in AD. Click here for more information.
But wait!
How do you access the recovery key from AD once you need it? Until recently there was no easy-to-use tool available for accessing those backed up keys once you need them.
We have the solution for you in 2 editions
|