BITLOCKER USER GUIDANCE This document provides guidance to users on the Bitlocker Encryption software installed on University of Wolverhampton laptops. Page 1 Further guidance and assistance can be obtained by contacting the ITS Service Desk (ext.2000). BITLOCKER ENCRYPTION PILOT 2015-16 The Bitlocker Encryption pilot will run from 1 st December 2015 15 th January 2016. This guide provides information on user device recovery options using either of the two device reset services available: o o Self-Service Portal ITS Service Desk assisted recovery. 1. BITLOCKER LOGON A university laptop with an encrypted hard drive will display the device PIN entry screen when switched on (Figure 1). Figure 1 BitLocker PIN entry screen
If you are unable to logon at this page due to a lost or forgotten PIN then you have two options: ITS Service Desk assistance Or BitLocker Self-Service Portal recovery. Page 2 2. LOST/ FORGOTTEN PIN ITS SERVICE DESK ASSISTANCE The ITS Service Desk (Ext.2000) will provide assistance for users wishing to regain access to device registered with the BitLocker Encryption service. There are four steps to recovering access to a university BitLocker Encrypted device: STEP 1 Before contacting the ITS Service Desk you will require the first 8-digits of the Recovery Key ID Figure 2 PIN Incorrect number from the Windows BitLocker Drive Encryption Recovery Key entry screen (This is the 32-digit code number on the screen Figure 3 below).
Figure 2 shows the PIN Incorrect screen for a BitLocker encrypted device, you will see this screen if you input an incorrect PIN for this device Or you have simply forgotten the PIN. From this screen press ESC. Page 3 STEP 2 The device will now go into Recovery Mode (Figure 3). Figure 3 Recovery Mode You will require the BitLocker Recovery Key ID for this device shown on this screen (Figure 3) in order to be able to request a BitLocker Recovery Key to regain access to the device. Only those users recorded as having authorised access to the device prior to the loss of the PIN will be granted access to the device, this is a system safeguard to protect confidential information stored on lost or compromised devices. In the circumstances where you are not a preauthorised user of the device prior to loss of the PIN the Recovery Key process detailed here will not be effective and you will need to contact the ITS Service Desk to request assistance with alternative data recovery procedures. STEP 3 ITS Service Desk will require the first eight digits of the BitLocker Recovery Key ID number shown on your device (Figure 3). With your university IT account user name and the existing BitLocker Recovery Key ID from your device ITS Service Desk will be able to issue a BitLocker Recovery Key. The BitLocker Recovery Key will allow you to regain access to the encrypted device.
You will need to input the recovery key into the Windows BitLocker Drive Encryption Recovery Key Entry screen (See Figure 3). Page 4 STEP 4 REMEMBER Now you have regained access to your device you now need to reset your PIN before shutting down the laptop. See Resetting My PIN, section 4 below.
3. LOST/FORGOTTEN PIN SELF-SERVICE PORTAL It is possible for university staff members to reset their BitLocker Encryption device if they have lost/ forgotten their PIN through the Self-Service Portal at https://mbladmin.unv.wlv.ac.uk/selfservice. Page 5 STEP 1 You will need to access the Self-Service Portal at the above address, this can be accessed both internally on the university campus and externally from the university campus via normal Web browser access. Input the first eight digits of the BitLocker Recovery Key (32-digit code Figure 2), select a Reason - Lost PIN/Passphrase and submit Get Key (See Figure 6 below). You will need to agree to the Web portal T&Cs (See Figure 4 below). Figure 6 BitLocker Key Recovery_2 This will create your BitLocker Recovery Key (48- digit code See Figure 7 below). Figure 4 BitLocker Self-Service portal This will take you to the BitLocker Recovery Key Web page (See Figure 5 Bitlocker Recovery Key). STEP 2 Figure 7 New BitLocker Recovery Key STEP 3 Input the BitLocker Recovery Key (Figure 7) into the device at the Windows BitLocker Drive Figure 5 BitLocker Recovery Key
Encryption Recovery Key entry screen (Figure 3 Recovery Mode). BITLOCKER ENCRYPTION USER GUIDE 2015 You have restored access to your encrypted device via the BitLocker Self-Service portal. Page 6
4. BITLOCKER PIN RESET Now you have regained access to your device you now need to reset your PIN before shutting down the laptop this is a simple reset process with only two steps required on the user encrypted device. Page 7 STEP 1 Click Start and go to Control Panel. Select System and Security, and then select BitLocker Encryption Options. Figure 8 BitLocker Encryption Options STEP 2 To change your PIN select Manage Your PIN (Figure 9). Figure 9 Manage Your PIN Type in your new PIN into both fields (PIN need to be at least 4-digits in length) and then select Reset PIN (Figure 10). Figure 10 Reset Your PIN
Read the PIN reset complete and Close (Figure 11). BITLOCKER ENCRYPTION USER GUIDE 2015 Page 8 Figure 11 PIN reset complete Your PIN is now reset and you will be prompted for this new PIN at your next reboot (See Figure 1).