Windows 10: What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?

Discus and support What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker? in Windows 10 Gaming to solve the problem; I know they now enable software encrypted Bitlocker by default. I've never had an issue with hardware based Bitlocker. I've used it for years. What's... Discussion in 'Windows 10 Gaming' started by jshoemaker21, Jul 6, 2024.

  1. What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?


    I know they now enable software encrypted Bitlocker by default. I've never had an issue with hardware based Bitlocker. I've used it for years. What's the "proper" procedure for implementation? Thanks

    :)
     
    jshoemaker21, Jul 6, 2024
    #1
  2. tekkie Win User

    BitLocker hardware encryption cannot be activated on Win10 10586/1511

    Hey,

    I'm having trouble enabling hardware encryption with BitLocker using Windows 10 build 10586 on a clean install with a Samsung 850 SSD. The encryption worked flawlessly before on build 10240.

    I've spent hours and attempted multiple solutions and made several tests.

    As mentioned, on the same machine, if clean installing build 10240 (RTM, before November update) right now, the encryption works.

    I have UEFI on with Legacy/CSM off, Fast Boot on, Secure Boot on, and a clean GPT installation after using the 'diskpart clean' command.

    As always, it's required to change a group policy to allow additional authentication at startup. I did that.

    On a clean installation of build 10586, the wizard will say 'parameter is incorrect' when attempting to start encryption.

    Microsoft did announce some BitLocker-related changes for build 10586: https://technet.microsoft.com/en-us/library/mt403325

    There are also new group policies added. I've tried all combinations. They now allow you to try and force a specific encryption cipher. Samsung uses XES-AES256. I tried forcing that (as well as all other combinations) but the same error returns.

    Now, here's where it gets interesting, and possibly why no reports about this have surfaced yet:
    If you enable the encryption on build 10240, and then upgrade to 10586, the encryption will remain and will work properly on build 10586.

    If you then attempt to 'Reset this PC', and choose the 'keep nothing' option, it will warn you that BitLocker will be disabled. Once it's done cleaning, if you attempt to enable encryption, it will again show the error.

    Even if you don't reset the PC, but simply disable BitLocker on 10586 and then attempt to re-enable it, it will no longer work.

    tl;dr: Hardware encryption via BitLocker on build 10586 cannot be enabled on a clean install. Currently-known workaround is installing 10240, encrypting it, then upgrading to 10586.

    Any solutions would be appreciated, thanks!
     
    tekkie, Jul 6, 2024
    #2
  3. Not Able to Enable Hardware Based Bitlocker Encryption On Surface Pro 4 (Windows 10 Pro)

    Ok, I have a feeling that this is a larger Windows 10 issue, but I am experiencing this with the Surface Pro 4, the ideal test hardware for anything Microsoft, right? What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker? :)

    Here is what we are trying to accomplish:

    Encrypt our Surface Pro 4's (win 10 Pro) using Hardware-Based Encryption

    Why?

    A) Because it is faster for the SSD to perform the encryption rather than the process, since the SSD is already encrypted

    B) Better battery life (because the processor is not encrypting the volume)

    C) Performing software encryption on an already encrypted volume defeats many of the internal optimizations that SSDs have built in (leading to slower performance)

    How?

    We have taken stock Surface Pro 4s, straight from the box. No applications or updates have been installed, we have not added to a domain. The only modification we have made is to the Local Group Policy:

    Computer Configuration/Administrative Templates/Windows Components/Bitlocker Drive Encryption/Operating System Drives

    *Require additional authentication at startup (Enabled, default options)

    *Enable use of BitLocker Aauthentication requireing preboot keyboard input on slates (Enabled, default options)

    *Configure use of hardware-based encryption for operating system drives (Enabled, default options)

    What's Wrong:

    When I go to enable Bitlocker, I am being provided the prompt to encrypt Used Only, or Whole Drive. From all of the literature I have read, this prompt indicates Software Encryption. When I select Full Drive, it takes a while (over 10 minutes) to encrypt.
    Again, from my reading, Hardware

    Encryption should be immediate (as everything is already encrypted).

    Question:

    What am I missing? Is there an issue with Hardware Encryption that I have not been able to identify on the Surface Pro 4? Is this an OS issue? Are there any other troubleshooting steps that I can take a look at? Again, these are stock units, fresh out of
    the box from Microsoft.

    Sources (these are just some, all have been verified using additional sources that repeat the information):

    Slower Performance- Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500

    Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500

    Steps to enable encryption- How to Enable BitLocker Hardware Encryption with SSDs

    How to Enable BitLocker Hardware Encryption with SSDs • Helge Klein

    Technet on Why to Hardware Encrypt - Encrypted Hard Drive

    Encrypted Hard Drive

    GP Settings to Enable Hardware Encryption - Enabling Hardware Acceleration of BitLocker

    http://blog.jflamb.com/enabling-hardware-acceleration-of-bitlocker/

    Tags Bitlocker, Encryption, Windows 10 Pro, Hardware Encryption, 1511
     
    PhillyPhotogMagee, Jul 6, 2024
    #3
  4. Camill_33 Win User

    What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?

    Bitlocker - Hardware encryption

    Hello,

    I trying to enable hardware encrypted disks with bitlocker. We have laptops (different models - Dell 6420, Lenovo T470, Lenovo T14 gen 1 and gen 2, Lenovo Carbon X1 gen 9) with Windows 10 Pro (21H2 witch all current updates). And different SED disks (WD SDBQNTY-256G, Samsung 850 PRO).

    I changed the settings “Configure use of hardware-based encryption for fixed data drives” to Enabled in the GPO (in Fixed Data Drives nad Operating System Drivers).

    TMP 2.0 is enabled

    UEFI is enabled.

    I tried with CSM enabled and disabled.

    But it still software encrypted.

    The only exception to each time the hardware encryption works properly is enabled "ENCRYPTED DRIVE" in Samsung Magican on the Samsung 850 PRO drive and execution Secure Erase and reinstalling Windows.

    How I can do hardware encrypted without reinstalling Windows? Let's ignore the pros and cons of hardware encryption as I am fully aware of it.
     
    Camill_33, Jul 6, 2024
    #4
Thema:

What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?

Loading...
  1. What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker? - Similar Threads - proper Microsoft Procedure

  2. What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?

    in Windows 10 Software and Apps
    What is the proper "Microsoft Procedure" to enable hardware encrypted Bitlocker?: I know they now enable software encrypted Bitlocker by default. I've never had an issue with hardware based Bitlocker. I've used it for years. What's the "proper" procedure for implementation? Thanks...
  3. Hardware Encryption with BitLocker?

    in Windows 10 Ask Insider
    Hardware Encryption with BitLocker?: Can I use Win10Pro BitLocker to enable/operate the hardware encryption of my Exos x24 16TB SED, model number ST16000NM001H. If yes, then how? submitted by /u/QuackQuackQuack2834 [link] [comments]...
  4. Can't enable bitlocker encryption.

    in Windows 10 Gaming
    Can't enable bitlocker encryption.: Hello. I have a problem. I can't enable bitlocker encryption. I have windows 11 21h2 home single language, I also recently performed a local reinstall of windows....
  5. Can't enable bitlocker encryption.

    in Windows 10 Software and Apps
    Can't enable bitlocker encryption.: Hello. I have a problem. I can't enable bitlocker encryption. I have windows 11 21h2 home single language, I also recently performed a local reinstall of windows....
  6. Bitlocker - Hardware encryption

    in Windows 10 Gaming
    Bitlocker - Hardware encryption: Hello,I trying to enable hardware encrypted disks with bitlocker. We have laptops different models - Dell 6420, Lenovo T470, Lenovo T14 gen 1 and gen 2, Lenovo Carbon X1 gen 9 with Windows 10 Pro 21H2 witch all current updates. And different SED disks WD SDBQNTY-256G, Samsung...
  7. Bitlocker - Hardware encryption

    in Windows 10 Software and Apps
    Bitlocker - Hardware encryption: Hello,I trying to enable hardware encrypted disks with bitlocker. We have laptops different models - Dell 6420, Lenovo T470, Lenovo T14 gen 1 and gen 2, Lenovo Carbon X1 gen 9 with Windows 10 Pro 21H2 witch all current updates. And different SED disks WD SDBQNTY-256G, Samsung...
  8. Bitlocker - Hardware encryption

    in Windows 10 Customization
    Bitlocker - Hardware encryption: Hello,I trying to enable hardware encrypted disks with bitlocker. We have laptops different models - Dell 6420, Lenovo T470, Lenovo T14 gen 1 and gen 2, Lenovo Carbon X1 gen 9 with Windows 10 Pro 21H2 witch all current updates. And different SED disks WD SDBQNTY-256G, Samsung...
  9. Bitlocker hardware encryption

    in Windows 10 Ask Insider
    Bitlocker hardware encryption: Im thinking to setup bitlocker but I still dont fully understand how it works. The software encryption part seems simple but how does bitlocker works with the SSD's hardware encryption? There are some articles about how bitlocker trusting the SSD's encryption that had...
  10. Bitlocker - What types of Hardware Encryption can it use?

    in AntiVirus, Firewalls and System Security
    Bitlocker - What types of Hardware Encryption can it use?: Hello Windows Support Team, When I run at powershell "manage-bde -status" I see one drive with "Encryption Method: Hardware Encryption - 1.3.111.2.1619.0.1.2" Is it eDrive, Opal 2.0, or other? How can I tell what HW encryption is being used? This is a data drive. Do you...