Are You Sure Your Devices Are Fully Encrypted with BitLocker?

BitLocker has long been the standard when it comes to disk encryption for your devices running Microsoft Windows operating systems—particularly on workstations and laptops. It’s designed to protect data by encrypting the entire disk drive on which the OS and user data are stored. This encryption ensures that even if someone physically steals or accesses your computer, they won’t be able to get to the data on the encrypted drive without the appropriate decryption key.

It is commonplace these days for MSPs and IT Admins to monitor BitLocker status on devices. While you may be sitting there confident your devices are fully encrypted, did you know most BitLocker status monitoring is done by using the Get-BitLockerVolume PowerShell command?

What’s wrong with the Get-BitLockerVolume PowerShell command?

The issue here is that this command can sometimes return a false positive when a drive is not fully encrypted. With newer devices, Microsoft starts the encryption process as part of the system setup on first boot. If you sign in with a Microsoft account, it will kick off a wizard to guide you through the process, and of course it will want you to store the keys in that account. If you don’t do this, BitLocker pauses and waits for the Microsoft account to move forward. Because of this, the Get-BitLockerVolume PowerShell cmd is going to show the device as encrypted, even though the process was not fully completed.

Related Product

N‑sight RMM

Comece a operar rapidamente, contando com o RMM, projetado para MSPs e departamentos de TI de pequeno porte.

How can you be sure the BitLocker disk encryption process has completed successfully?

One way to verify that the device has been encrypted is if there is a recovery key present.

To ensure you can confidently answer yes to the question “Are Your Devices Fully Encrypted with BitLocker?”, I’ve taken the Bitlocker Status AMP—widely used by our N‑able partners—and updated it. Now, not only does it tell you if BitLocker is turned on, but it also automatically checks what the system drive is. On top of this, it will retrieve the system drive recovery key so that you can confidently say the device is fully encrypted.

With the new BitLocker Status v2 monitoring, it will show as failed if any of the following scenarios are true:

  • BitLocker is not enabled on the device
  • BitLocker is available but is “off” on at least one drive
  • If the drive is partially encrypted but no recovery key is present. 
Related Product

N‑central

Manage large networks or scale IT operations with RMM made for growing service providers.

Where can I find BitLocker Status v2?

For many of you, it will come as no surprise to hear that BitLocker Status v2 is available in the Automation Cookbook.

For those of you who are unfamiliar with the Automation Cookbook, boy are you in for a treat: with over 800 scripts (and growing), the Automation Cookbook contains automation policies, custom monitoring, and pre-built scripts to help you boost your efficiency. These scripts are written in-house or by other MSPs who are using automation capabilities, so you know you are getting scripts that work, and work well.

Make sure you check out the Automation Cookbook here: https://me.n-able.com/s/global-search/%40uri#t=AutomationCookbook&sort=relevancy

In most cases I’m sure you’ll find that BitLocker has actually fully encrypted your devices, but as Murphy’s Law would dictate, if something can go wrong it will. So why run the risk of not taking any action? Roll out Bitlocker Status v2 across your devices and if you have questions join me on my N‑central office hours, alternatively you can contact me directly by the methods below.

Paul Kelly is the Head Nerd at N‑able. You can follow him on Twitter at @HeadNerdPaulLinkedIn and Reddit at u/Paul _Kelly. Alternatively you can email me direct.

 

© N‑able Solutions ULC e N‑able Technologies Ltd. Todos os direitos reservados.

Este documento é fornecido apenas para fins informativos e não deve servir de base para aconselhamento jurídico. A N‑able não oferece nenhuma garantia, expressa ou implícita, nem assume qualquer responsabilidade legal ou responsabilidade pela precisão, integralidade ou utilidade de qualquer informação nele contido.

As marcas N-ABLE, N-CENTRAL e outras marcas registradas e logotipos N‑able são de propriedade exclusiva da N‑able Solutions ULC e da N‑able Technologies Ltd e podem ser marcas legais comuns, registradas ou de registro pendente com o Escritório de Marcas e Patentes dos EUA e com outros países. Todas as outras marcas comerciais mencionadas neste documento são usadas apenas para fins de identificação e são marcas comerciais (e poderão ser marcas registradas) de suas respectivas empresas.