Saturday, May 29, 2021

How to use BitLocker Drive Encryption on Windows 10

 

How to use BitLocker Drive Encryption on Windows 10


If you have a laptop or device that stores sensitive files, use this guide to enable and configure BitLocker encryption to add an extra layer of security on Windows 10.


On Windows 10, if you keep sensitive files on your device, it is crucial to take the necessary steps to protect them, and this is when BitLocker comes in handy. BitLocker is a feature that has been around for a long time, and it provides a way to encrypt the data on the hard drive to prevent unauthorized access to your information.

In a nutshell, encryption is the process of making any data unreadable without proper authorization. When you use encryption to scramble your data, it will continue to be unreadable even when sharing it with other people. Only you with the proper encryption key can decrypt the data to make it usable.

If you've never use BitLocker before, the feature offers two methods of encryption, including hardware-based encryption using Trusted Platform Module (TPM) chip and software-based encryption using a password or USB flash drive to decrypt the drive and continue booting into Windows 10. Also, the feature allows protecting the data on the installation drive, secondary storage, and removable media with "BitLocker To Go."

In this Windows 10 guide, we will walk you through the steps to set up BitLocker on your computer to make sure your sensitive data stays secure.

  • Before using BitLocker
  • How to check if device has TPM support to use BitLocker
  • How to enable (hardware-based) BitLocker on the operating system drive
  • How to enable (software-based) BitLocker on the operating system drive
  • How to enable BitLocker on fixed data drives
  • How to enable BitLocker To Go on removable drives
  • How to disable BitLocker on Windows 10

Before using BitLocker

Here are a few details you need to know before using these instructions:

  • BitLocker Drive Encryption is available on Windows 10 Pro and Enterprise. Windows 10 Home edition has its version of BitLocker on select devices. You can use these steps to set it up.
  • Trusted Platform Module (TPM) chip is needed for the best result. This is a special chip that enables the device to support advanced security features.
  • BitLocker is available without TPM by using software-based encryption, but it requires some extra steps for additional authentication.
  • Computer firmware must support TPM or USB devices during startup. If the feature isn't available, check the computer manufacturer for the Basic Input Output System (BIOS) or Unified Extensible Firmware Interface (UEFI) update.
  • Computer's hard drive must have two partitions, including a system partition with the necessary files to start the system and a partition with the Windows 10 installation. If the device does not meet the requirements, BitLocker will create them automatically. Also, the hard drive partitions must be formatted with the NTFS file system.
  • The encryption process is not complicated, but it can take a lot of time, depending on the drive's amount of data and size.
  • Keep the computer connected with an uninterrupted power supply (UPS) throughout the entire process.

Although BitLocker does a good job securing your data, any system change carries its risks. It's always recommended that you make a full backup of your system before proceeding with this guide.

How to check if device has TPM support to use BitLocker

To check if a computer has TPM on Windows 10, use these steps:

  1. 1. Open Start.
  2. 2. Search for Device Manager and click the top result to open the app.
  3. 3. Expand the Security devices branch.
  4. 4. Confirm the item that reads "Trusted Platform Module" with the version number.


  1. Quick note: The TPM version must be version 1.2 or later to support BitLocker.

Alternatively, you can also check your manufacturer's support website for details on whether the computer includes the security chip and the instructions to enable the security feature.

If you have a Surface device, likely it includes a Trusted Platform Module with support for BitLocker encryption.

How to enable (hardware-based) BitLocker on the operating system drive

To enable BitLocker on a device with TPM, use these steps:

  1. 1. Open Start.
  2. 2. Search for Control Panel and click the top result to open the app.
  3. 3. Click on System and Security.
  4. 4. Click on BitLocker Drive Encryption.


  5. 5. Under the "Operating system drive" section, click the Turn on BitLocker option.



  1. 6. Select the option to save the recovery key:

  • Save to your Microsoft account.
  • Save to a file.
  • Print the recovery.

        Quick tip: If you trust the cloud, choose to save your recovery key in your Microsoft account using the Save to your Microsoft account option. You can always retrieve the encryption key at this OneDrive location.

      1. 7. Click the Next button.


      8. Select how much the drive space to encrypt:

      • Encrypt used disk space only (faster and best for new PCs and drives).
      • Encrypt the entire drive (slower but best for PCs and drives already in use).

      9. Choose between the two encryption options:

      • New encryption mode (best for fixed drives on this device).
      • Compatible mode (best for drives that can be moved from this device).

      1. 10. Click the Next button.
      2. 11. Check the Run BitLocker system check option.



      1. 12. Click the Continue button.
      2. 13. Click the Restart now button.

      After you complete the steps, the device will restart, BitLocker will enable, and you will not be prompted to enter a decryption password to continue starting Windows 10.

      Although the device will boot quite fast, on Control Panel > System and Security > BitLocker Drive Encryption, you will notice that BitLocker is still encrypting the drive. Depending on the option you selected and the size of the drive, this process can take a long time, but you can continue to work on the computer.

      After the encryption process is complete, the drive will include a lock icon, and the label will read BitLocker on.

      BitLocker options

      Once the drive encryption is enabled, several options will become available, including:

      • Suspend protection: This option will stop protecting your files. Typically, you would use this option when upgrading to a new version of Windows 10, firmware, or hardware. If you don't resume the encryption protection, BitLocker will resume automatically during the next reboot.
      • Back up your recovery key: If you lose the recovery key and are still signed into your account, you can use this option to create a new backup of the key with the options mentioned in Step 6.
      • Change password: Creates a new encryption password, but you will still need to supply the current password to make the change.
      • Remove password: You cannot use BitLocker without a form of authentication. You can remove a password only when you configure a new method of authentication.
      • Turn off BitLocker: Decrypts all the files on the drive. Also, decryption may take a long time to complete its process depending on the storage size, but you can still use your computer.

      How to enable (software-based) BitLocker on the operating system drive

      In the case that the computer does not have a Trusted Platform Module chip, you won't be able to configure BitLocker on Windows 10. However, you can still use encryption if you use the Local Group Policy Editor to enable additional authentication at startup. Once the feature is enabled, you will need to provide a password or USB flash drive with the recovery key to unlock the drive and continue booting into Windows 10.

      Enable policy without TPM support

      To configure BitLocker on devices without a TPM chip, use these steps.

      1. 1. Open Start.
      2. 2. Search for gpedit and click the top result to open the Local Group Policy Editor.
      3. 3. Browse the following path:

        Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives

      4. 4. On the right side, double-click the Require additional authentication at startup policy.



      1. 5. Select the Enabled option.
      2. 6. Check the "Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)" option.


      1. 7. Click the Apply button.
      2. 8. Click the OK button.

      Once you complete the steps, BitLocker can be configured on the computer to protect your data.

      Enable BitLocker

      To enable BitLocker on your device, use these steps:

      1. 1. Open Start.
      2. 2. Search for Control Panel and click the top result to open the app.
      3. 3. Click on System and Security.
      4. 4. Click on BitLocker Drive Encryption


      5. Under the "Operating system drive" section, click the Turn on BitLocker option


      6. Select the encryption to unlock method:

      • Insert a USB flash drive — requires a flash drive to unlock the device and boot into Windows 10.
      • Enter a password — requires a password before booting into Windows 10 (recommended).

      7. Create and confirm the password to unlock BitLocker and access your device.


      1. 8. Click the Next button.
      2. 9. Select the option to save the recovery key:

        • Save to your Microsoft account.
        • Save to a USB flash drive.
        • Save to a file.
        • Print the recovery.

      1. 10. Click the Next button.
      2. 11. Select how much the drive space to encrypt:

        • Encrypt used disk space only (faster and best for new PCs and drives).
        • Encrypt the entire drive (slower but best for PCs and drives already in use).

      1. 12. Choose between the two encryption options:
      • New encryption mode (best for fixed drives on this device).
      • Compatible mode (best for drives that can be moved from this device).

      1. 1. Click the Next button.
      2. 2. Check the Run BitLocker system check option.


        1. 1. Click the Continue button.
        2. Click the Restart now button.

      After you co2. mplete the steps, the computer will restart, and BitLocker will prompt you to enter your encryption password to unlock the drive.

      How to enable BitLocker on fixed data drives

      To configure BitLocker on a secondary drive, use these steps:

      1. 1. Open Start.
      2. 2. Search for Control Panel and click the top result to open the app.
      3. 3. Click on System and Security.
      4. 4. Click on BitLocker Drive Encryption.


      5. Under the "Fixed data drives" section, click the Turn on BitLocker option for the secondary drive.


      1. 6. Check the Use a password to unlock the drive option.

        Quick note: You can also use the Use my smart card to unlock the drive option, but this is uncommon.

      2. 7. Create and confirm the password to unlock BitLocker and access your device.


      1. 8. Click the Next button.
      2. 9. Select the option to save the recovery key:

        • Save to your Microsoft account.
        • Save to a USB flash drive.
        • Save to a file.
        • Print the recovery.

      1. 10. Click the Next button.
      2. 11. Select how much the drive space to encrypt:

        • Encrypt used disk space only (faster and best for new PCs and drives).
        • Encrypt the entire drive (slower but best for PCs and drives already in use).

      12. Choose between the two encryption options:

      • New encryption mode (best for fixed drives on this device).
      • Compatible mode (best for drives that can be moved from this device).

      1. 13. Click the Next button.
      2. 14. Click the Start encrypting button.



      1. 15. Click the Close button.

      Once you complete the steps, the drive will start using encryption. If the drive already had data, the process could take a long time to complete.

      How to enable BitLocker To Go on removable drives

      Alternatively, you can also use the "BitLocker To Go" feature to encrypt removable drives (such as USB flash and external drives) connected to your computer.

      To set up BitLocker To Go on a removable drive, use these steps:

      1. 1. Connect the USB drive to the device.
      2. 2. Open Start.
      3. 3. Search for Control Panel and click the top result to open the legacy app.
      4. 4. Click System and Security.
      5. 5. Click BitLocker Drive Encryption.


      1. 6. Under the "BitLocker To Go" section, select the removable drive you want to encrypt.
      2. 7. Click the Turn on BitLocker option.


      1. 8. Check the Use a password to unlock the drive option.
      2. 9. Create a password to unlock the drive.


      1. 10. Click Next to continue.
      2. 11. Select the option to save the recovery key:

        • Save to your Microsoft account.
        • Save to a file.
        • Print the recovery.

      1. 12. Click the Next button.
      2. 13. Select how much the drive space to encrypt:

        • Encrypt used disk space only (faster and best for new PCs and drives).
        • Encrypt the entire drive (slower but best for PCs and drives already in use).

      14. Choose between the two encryption options:

      • New encryption mode (best for fixed drives on this device).
      • Compatible mode (best for drives that can be moved from this device).

      1. Quick tip: In this case, the Compatibility mode is the recommended option.

      2. 15. Click the Next button.
      3. 16. Click the Start encrypting button.


      1. 17. Click the Close button.

      After you complete the steps, the encryption process will begin on the removable drive.

      When using encryption, always try to start with an empty drive to speed up the process, then the data will encrypt quickly and automatically. In addition, similar to the feature of the operating system drive, you will get the same additional options and a few more, including:

      • Add smart card: This option will allow you to configure a smart card to unlock the removable drive.
      • Turn on auto-unlock: Instead of having to type a password every time you re-connect the removable drive, you can enable auto-unlock to access your encrypted data without entering a password.

      How to disable BitLocker on Windows 10

      To remove the drive encryption, use these steps:

      1. 1. Open Start.
      2. 2. Search for Control Panel and click the top result to open the app.
      3. 3. Click on System and Security.
      4. 4. Click on BitLocker Drive Encryption.


      5. Click the Turn off BitLocker option for the drive you want to remove the encryption.



      1. 6. Click the Turn off BitLocker button.

      Once you complete the steps, the decryption process will begin, and it will take some time to complete depending on the amount of data.

      Thanks for Reading...
      Masud Rana

      How to enable and use Wake on LAN (WoL) on Windows 10

       

      How to enable & use Wake on LAN (WoL) on Windows 10

      Yes, you can wake up a computer remotely, and in this guide, we'll show you how to complete this task on Windows 10.




      On computing, Wake on LAN (WoL) is a networking standard protocol that provides the ability to configure a device to be started from a low power state using a special signal over the local network (also referred to as a magic packet). You can think of it as a remote power button to your computer.

      Usually, this feature comes in handy to maintain a connection to your computer to access files and applications while minimizing power usage since when not in use, you can put the device to sleep.

      After enabling Wake on LAN inside the Basic Input Output System (BIOS) or Unified Extensible Firmware Interface (UEFI) on supported hardware, and then in the Windows 10 network card (or USB to Ethernet adapter), you can use many third-party tools to send a magic packet over the network containing the MAC address of the remote computer to wake it up.

      In this Windows 10 guide, we will walk you through the steps to enable and use Wake on LAN to turn on remote computers in the network.

      How to enable Wake on LAN feature on Windows 10

      On Windows 10, if you want to use the WoL feature, you must enable it first on the motherboard firmware (or on the network adapter if you are using an external device) and then on the Windows settings. Also, the feature only works when the computer is in sleep mode, but some devices support waking from hibernation or powered off state, even though Windows 10 does not participate in the process.

      BIOS/UEFI configuration

      To enable Wake on LAN on the device firmware, use these steps:

      1. 1. Open Settings.
      2. 2. Click on Update & Security.
      3. 3. Click on Recovery.
      4. 4. Under the "Advanced startup" section, click the Restart now button.



      5. Click on Troubleshoot.


      6. Click on Advanced options.


      7. Click the UEFI Firmware Settings option.



      1. 8. Click the Restart button.

      While in the firmware settings, navigate to the power settings and enable the "Wake on LAN" (WoL) feature. The option may have a slightly different name since the majority of the manufacturers build their firmware differently. If this is the case, make sure to check the device documentation online for more specific details.

      Once you complete the steps, you can proceed with the instructions to configure the feature on Windows 10.

      If your device does not include support for Wake on LAN, you can always get an adapter like the USB-A 3.0 to RJ45 Gigabit Ethernet LAN Adapter from uni that provides support to wake a device from sleep at a reasonable price.

      Windows configuration

      To enable WoL on Windows 10, use these steps:

      1. 1. Open Settings.
      2. 2. Click on Network & Internet.
      3. 3. Click on Status.
      4. 4. Under the "Advanced network settings" section, click the Change adapter options button.


      5. Right-click the active network adapter and select the Properties option.


      1. 6. Click the Networking tab.
      2. 7. Click the Configure button.



      1. 8. Click the Advanced tab.
      2. 9. Select the Wake on Magic Packet option.
      3. 10. Use the "Value" drop-down menu and select the Enabled option.


      1. 11. (Optional) Select the Wake on pattern match option.
      2. 12. Use the "Value" drop-down menu and select the Enabled option.
      3. 13. (Optional) Select the WoL & Shutdown Link Speed option.
      4. 14. Use the "Value" drop-down menu and select the 10Mbps option.

        Quick note: The optional settings may be required if you use a network adapter from Realtek.

      5. 15. Click the Power Management tab.
      6. 16. Check the Allow this device to wake the computer option.
      7. 17. Check the Only allow a magic packet to wake the computer option.


      1. 18. Click the OK button.

      After you complete the steps, the computer will be ready to be started remotely with a magic packet over the network using a third-party tool.

      If you want to use the feature, you can use the same instructions outlined above to disable Wake on LAN, but on step No. 9, make sure to select the Disabled option. In addition to disabling the feature on Windows 10, you also want to turn off the WoL feature inside the device firmware using your manufacturer instructions.

      How to wake up a computer remotely on Windows 10

      Once the feature has been configured, you can turn on the computer in many different ways. For example, you can use the WoL tool built into the router. You may be able to find scripts that you can use with PowerShell. Or you can use third-party tools to send the magic packet to wake up the device.

      For this example, we are using the "WakeMeOnLan" tool from NirSoft to wake a device remotely:

      Warning: Although this application works as advertised, this is a third-party tool, and you should use it only at your own risk. You have been warned.

      1. 1. Open the NirSoft download page.
      2. 2. Click the download link to save the app on your device.


      1. 3. Extract the contents from the .zip folder with File Explorer.
      2. 4. Open the folder with the extracted files.
      3. 5. Double-click the WakeMeOnLan.exe file to launch the standalone tool.
      4. 6. Click the Play (Start Scanning) button to discover all the devices in the network.

        Quick note: The device you want to wake up remotely has to be turned on for the tool to find it. Once it is on the list, the device can be offline to use the WoL feature. You can also use the Ctrl + N keyboard shortcut to add the remote computer information (IP address, computer name, and MAC address) manually.

      5. 7. Right-click the remote computer and select the Wake Up Selected Computers option.


      1. 8. Click the Yes button.

      Once you complete the steps, the tool will send the magic packet, which should start the device immediately if the network card was still operational even when the computer was turned off.

      Confirm IP and MAC address

      If you are using another tool, you will need to determine the IP and MAC address of the device you want to wake up, which you can easily do from the Settings app. Here's how:

      1. 1. Open Settings.
      2. 2. Click on Network & Internet.
      3. 3. Click on Status.
      4. 4. Under the "Network status" section, click the Properties button for the active connection.


      5. Under the "Properties" section, confirm the IPv4 address and Physical address (MAC).



      If you are using Command Prompt, you can query the adapter addresses using the ipconfig /all command.

      Once you complete the steps, you can use the addresses with the utility of your choice to wake up a remote computer.

      How to troubleshoot Wake on LAN feature on Windows 10

      If the device does not wake up after sending the magic packet, you can do a few things to troubleshoot the problem.

      The system must support Wake on LAN at the firmware level. If the option is unavailable in the motherboard's BIOS or UEFI or the network adapter (for example, USB to Ethernet adapter), you won't be able to use the feature.

      If you use a USB to Ethernet adapter, WoL may only work when the computer is sleeping since powering off the device may also stop providing power to the USB port.

      In the case that the computer is using the fast startup feature, you can try disabling it to mitigate the problem.

      You can wake up a device only if the network card is active. If you are using an Ethernet connection, confirm the lights on the card are still blinking after the device is powered down.

      On a laptop, you have to make sure that the device is connected to a power outlet. Otherwise, it won't work.

      When using this feature, you can also come across networking problems that may prevent the device from waking up the remote computer. If you suspect a networking issue, use the ping command to confirm the source can contact the target device. Also, it is a good idea to double-check that you are using the correct MAC and IP address of the target computer. You can get this networking information using the ipconfig command (see above link to learn more).


      Microsoft office broken copy-and-paste functionality in multiple versions of Excel

       Microsoft office broken copy-and-paste functionality in multiple versions of Excel A recent Microsoft security update (KB5002914) released ...