ENABLE BITLOCKER ON WINDOWS VISTA - WITHOUT A TPM Requirements: You must be running Vista Enterprise or Vista Ultimate to enable BitLocker. Any other version of Vista is not compatible. It is recommended that you have 2 USB flash drives: one to save the recovery key, and the second to save the startup key (separate from the recovery key). The laptop MUST be plugged in to the mains during the encryption process. DO NOT attempt this procedure whilst running on battery power only. Once BitLocker encryption has been completed, the USB Flash Drive which stores the Startup Key MUST be inserted into the laptop prior to turning on. Drive Partitions In order to enable BitLocker, your hard drive must be partitioned in a particular manner. There is a tool available from Microsoft which automatically partitions the drive. To obtain the tool please use one of the following methods (depending on your version of Vista): Vista Ultimate 1. Run Windows Update from your laptop and check for any updates 2. Click on View available Extras 3. Select the BitLocker and EFS enhancements check box, then click Install. Vista Enterprise 1. x86-based Systems, download the tool from: http://www.microsoft.com/downloads/details.aspx?familyid=b9b5378e- 0851-44e3-ba33-a7df1c75c2f3 2. x64-based Systems, download the tool from: http://www.microsoft.com/downloads/details.aspx?familyid=876543bf- 2336-4324-9f67-3f351b136ded Once installed, go to Start > All Programs > Accessories > System Tools > BitLocker and double-click BitLocker Drive Preparation Tool. Accept the Agreement, then select Continue. Wait for the process to complete, then restart your laptop when prompted. This will create an additional 1.5Gb partition on your laptop to allow BitLocker to be enabled.
Allow BitLocker to be enabled without TPM The default policy for enabling BitLocker requires the presence of a TPM (Trusted Platform Module) chip on the laptop. To allow BitLocker to be used without this chip, a change to the Local Computer Policy needs to be made. Click Start, type gpedit.msc in the search box and press Enter. Under Local Computer Policy navigate to Computer Configuration \ Administrative Templates \ Windows Components \ Bit Locker Drive Encryption and double click to open the setting Control Panel Setup: Enable advance startup options.
Select the Enabled option and check the box to Allow Bitlocker without a compatible TPM Click Apply and OK Close the Group Policy editor and logoff and back on to the laptop.
Turn on BitLocker Your BIOS must be enabled for USB flash drives at startup (this will be checked during the BitLocker wizard hardware test) Ensure the USB Flash Drive(s) are plugged in Click Start, click Control Panel, click Security and select BitLocker Drive Encryption Select Turn On BitLocker for Volume C:
Select Require a Startup USB key at every startup Select the location of the flash drive you want to use to store the Startup key, and then click Save
Select Save the recovery key to a USB Flash Drive select your second USB Flash Drive as the location to save the recovery key to. Note: From this screen, you can select one or more of these options to save the Recovery key to several disks or print the key. For each option you select you will run through the wizard steps to save and\ or print the recovery key. Note: the recovery key is essential if the pin is lost or forgotten, if there is a hardware issue with laptop or data recovery of hard disk is needed. Do not change the filename generated. The data on the hard drive disk will not be accessible without the recovery key. For maximum security, store the BitLocker recovery key in a location that is not on the local machine. Once you have saved the Recovery Key to at least one location, select Next to continue.
Ensure Run BitLocker system check is ticked and click Continue Then click Restart now When you login, a message displaying Encryption in progress will appear. You can click on this to view its progress This process took typically 1-2 hours to complete on testing.
Recovering Data protected by BitLocker Drive Encryption If the USB Flash Drive which stores the Startup Key is not inserted when the laptop is turned on, you will see the message below: At this point, you can either, insert the USB Flash Drive containing the Startup Key or the USB Flash Drive containing the Recovery Key and hit the ESC key to reboot or if you have a printed copy of the Recovery Key, press Enter to access the BitLocker Recovery Screen shown below and enter the key as prompted.