\nI wasnt aware of that about Win 11 24H2, it has implications for work as well.<\/p>\n<\/blockquote>\n<\/aside>\n
Work devices in my opinion should be encrypted anyway, especially if the company deals with sensitive or copyrighted data. But any company data should be secured.<\/p>\n
Anyone in IT, my opinion is, W11 should have been used from within the first month - i understand that people like a little bedding-in, but the sooner you become familiar, the more you will love and learn about it.<\/p>\n
To note, any upgrades, in-place will not force Bitlocker on 24H2, but clean installs will. Do take this with a pinch of salt though as Microsoft do change their minds, so an KB update going forward may also enable bitlocker on upgrades.<\/p>\n
Better to start testing and using it, so the impact is low and the risk of recovery passwords being lost is also taken care of.<\/p>","upvoteCount":2,"datePublished":"2024-05-31T11:25:04.788Z","url":"https://community.spiceworks.com/t/bitlocker-local-account/1081442/8","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":"
Hi Rod<\/p>\n
All valid points, the only things encrypted at the moment are my backups and although the only data saved on the desktops is email i take your point.<\/p>\n
I am curious now, do you use encryption on your servers? \nWith them in a cabinet, in a locked room i am not sure of the benefit?<\/p>\n
I note that bitlocker is not even installed by default on servers.<\/p>\n
As for the win 11 upgrade- its been on my laptop and desktop for some time.<\/p>\n
The delay to upgrading the rest of the company desktops is due to a number of factors, but again point taken.<\/p>\n
I think for all future win 11 pcs, i will enable bitlocker from the start so that i can guarantee the key is backed up<\/p>\n
Thanks again<\/p>","upvoteCount":1,"datePublished":"2024-05-31T12:36:11.789Z","url":"https://community.spiceworks.com/t/bitlocker-local-account/1081442/9","author":{"@type":"Person","name":"trevorwilson3","url":"https://community.spiceworks.com/u/trevorwilson3"}},{"@type":"Answer","text":"\n\n
<\/div>\n
trevorwilson3:<\/div>\n
\nWith them in a cabinet, in a locked room i am not sure of the benefit?<\/p>\n<\/blockquote>\n<\/aside>\n
This is akin to a burglar alarm on a house behind locked gates - it only takes the gates to stop working or be left open to your server room to be vulnerable. It’s entirely your choice, but it’s going to come down to compliances you have to meet.<\/p>\n\n\n
<\/div>\n
trevorwilson3:<\/div>\n
\nI am curious now, do you use encryption on your servers?<\/p>\n<\/blockquote>\n<\/aside>\n
Some, yes, but the SAN is encrypted so this meets policy.<\/p>","upvoteCount":1,"datePublished":"2024-05-31T13:29:34.396Z","url":"https://community.spiceworks.com/t/bitlocker-local-account/1081442/10","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":"
hi trevor,<\/p>\n
usually if bitlocker is enabled it should have it on her Microsoft Account or if its Work Account(M365) it should be in Azure AD. Her bitlocker maybe got enabled during the setup but whats really weird here is that why was it got prompted. Did she upgrade her desktop? This would only happen if you transfer your hard drive to a different machine.<\/p>\n
just a thought.<\/p>","upvoteCount":1,"datePublished":"2024-06-03T01:40:27.557Z","url":"https://community.spiceworks.com/t/bitlocker-local-account/1081442/11","author":{"@type":"Person","name":"grapolski","url":"https://community.spiceworks.com/u/grapolski"}},{"@type":"Answer","text":"
Hi grapolski, apparently it was after a windows update.<\/p>\n
She is up and running again now, after she had reinstalled i got her to check the bitlocker status and it was already encrypted albeit ‘awaiting activation’<\/p>\n
This time she activated bitlocker and backed up the key<\/p>\n
Perhaps it was this ‘halfway house’ of encrypted but not activated that caused the issue?<\/p>","upvoteCount":0,"datePublished":"2024-06-06T22:07:27.300Z","url":"https://community.spiceworks.com/t/bitlocker-local-account/1081442/12","author":{"@type":"Person","name":"trevorwilson3","url":"https://community.spiceworks.com/u/trevorwilson3"}}]}}
Hey all
Just had my sister call me wanting help, her PC is prompting for a bitlocker recovery key. She had no idea that bitlocker was enabled and has no idea of the key.
I suggested checking in her microsoft account, which didnt help- but more confusingly she has been working with a local account.
She insists she has never used a microsoft account to log into her laptop, (although she did of course sign into office with her microsoft account when setting up office)
This has got me a bit confused, i dont understand how it would be activated with a local account?
She has her files backed up luckily, and i will reinstall for her but i dont understand how it happened?
Its a dell laptop, win 11 pro.
Thanks
Samael1
(Samael1)
May 31, 2024, 9:34am
2
She could try signing in here with her Microsoft credentials and see if there is a recovery key here. Sign in to your account (microsoftonline.com)
Some Dell utilities may have enabled bitlocker without her realising.
Hi,
Thanks, yup i sent her instructions for checking her microsoft account and there is no key uploaded.
As for dell enabling bitlocker without warning surely if that happens there would be a prompt to save the key?
I guess it is possible she did sign into a microsoft account at set up and had forgotten but she insists not, and i was under the impression that bitlocker simply does not activate unless a microsoft account is used to log in to the computer either at set up or later on?
Rod-IT
(Rod-IT)
May 31, 2024, 9:46am
4
I’m trying to find the link, but Dell machines when signed in to 365 automatically encrypts the drive.
FYI, so people are forewarned, Windows 11 24H2 will also enable bitlocker encryption by default. Signing in with a 365 account should save the key in your account
2 Spice ups
Samael1
(Samael1)
May 31, 2024, 9:49am
5
2 Spice ups
Rod-IT
(Rod-IT)
May 31, 2024, 10:02am
6
Thanks @Samael1 but the link I was looking for is a Microsoft specific one. I should have noted that.
2 Spice ups
Thanks for the link on dell, i have just read it and it does seem that even if initially set up with a local account, encryption takes place automatically. I am not sure that is a good idea?
I wasnt aware of that about Win 11 24H2, it has implications for work as well.
Our desktops are currently on win 10 pro at work, users sign into an on prem domain and are separately signed into 365 for email etc. Bitlocker is off on all desktops.
I am planning to begin the move to win 11 early next year, i have put 11 on my own machine to familiarise myself and test and find issues. Thanks for the forewarning, it is definitely something to watch out for.
Rod-IT
(Rod-IT)
May 31, 2024, 11:25am
8
Work devices in my opinion should be encrypted anyway, especially if the company deals with sensitive or copyrighted data. But any company data should be secured.
Anyone in IT, my opinion is, W11 should have been used from within the first month - i understand that people like a little bedding-in, but the sooner you become familiar, the more you will love and learn about it.
To note, any upgrades, in-place will not force Bitlocker on 24H2, but clean installs will. Do take this with a pinch of salt though as Microsoft do change their minds, so an KB update going forward may also enable bitlocker on upgrades.
Better to start testing and using it, so the impact is low and the risk of recovery passwords being lost is also taken care of.
2 Spice ups
Hi Rod
All valid points, the only things encrypted at the moment are my backups and although the only data saved on the desktops is email i take your point.
I am curious now, do you use encryption on your servers?
With them in a cabinet, in a locked room i am not sure of the benefit?
I note that bitlocker is not even installed by default on servers.
As for the win 11 upgrade- its been on my laptop and desktop for some time.
The delay to upgrading the rest of the company desktops is due to a number of factors, but again point taken.
I think for all future win 11 pcs, i will enable bitlocker from the start so that i can guarantee the key is backed up
Thanks again
1 Spice up
Rod-IT
(Rod-IT)
May 31, 2024, 1:29pm
10
This is akin to a burglar alarm on a house behind locked gates - it only takes the gates to stop working or be left open to your server room to be vulnerable. It’s entirely your choice, but it’s going to come down to compliances you have to meet.
Some, yes, but the SAN is encrypted so this meets policy.
1 Spice up
grapolski
(grapolski)
June 3, 2024, 1:40am
11
hi trevor,
usually if bitlocker is enabled it should have it on her Microsoft Account or if its Work Account(M365) it should be in Azure AD. Her bitlocker maybe got enabled during the setup but whats really weird here is that why was it got prompted. Did she upgrade her desktop? This would only happen if you transfer your hard drive to a different machine.
just a thought.
1 Spice up
Hi grapolski, apparently it was after a windows update.
She is up and running again now, after she had reinstalled i got her to check the bitlocker status and it was already encrypted albeit ‘awaiting activation’
This time she activated bitlocker and backed up the key
Perhaps it was this ‘halfway house’ of encrypted but not activated that caused the issue?