Encryption with Bitlocker

Encryption with Bitlocker

To proctect your data, we recommend that you install Bitlocker. It protects your data by encrypting it. After one-time installation your local data is secured.

You need Administrator rights to install Bitlocker. Contact your local system administrator to help you install Bitlocker. In the absence of the system administrator, you can contact the DICT Helpdesk contact.

If you have a PC you have purchased yourself, but still have questions about the Bitlocker installation procedure, please keep Adminstrator password at hand when you contact your local system administrator or the DICT Helpdesk.

Bitlocker can only be installed on Windows 10.

If you want to install Bitlocker yourself, follow the procedure below.

First check whether your device already has a TPM chip

To do this, search for Device Manager and then click on Security devices (Security devices).
If your device is equipped with a TPM chip, it is listed below Security devices, e.g. "Trusted Platform Module 2.0"

If this entry is not there, proceed to the installation procedure for Bitlocker without TPM chip

Installation with TPM chip

Open Control Panel - System and Security and choose Bitlocker Drive Encryption. If Bitlocker is already turned on, you'll see "(C:) Bitlocker on".

If not, you can immediately activate Bitlocker: Turn on Bitlocker.
A check will then be carried out automatically to determine whether your device is suitable for activating Bitlocker. This may take several minutes.
Then your hard drive is being prepared for Bitlocker. This is done automatically and transparently. You will then be asked to restart.

After restart, open Bitlocker again via Control Panel.

Recovery key

The system will ask you what you want to do with the Recovery Key. You may need this recovery key, for example after updating your systems. Please do well to keep track of it and make your own choice how you wish to do this.

When asked how much you want to encrypt, always choose Encrypt Entire Drive.
For your local hard drive, it is best to choose the latest encryption method.
Perform an additional check (check Run Bitlocker system check).
The actual encryption will start after a restart. You will only notice this by clicking on the Bitlocker icon click in the taskbar. During encryption (can take several hours) you can always restart your PC, switch it off, .. Encryption will continue automatically.

Installation without TPM chip

Open Control Panel - System and Security and choose Bitlocker Drive Encryption . If Bitlocker is already turned on, you see "(C:) Bitlocker on".

If not, you can immediately activate Bitlocker: Turn on Bitlocker.
A check will then be carried out automatically to determine whether your device is suitable for activating Bitlocker. This may take several minutes.
Then your hard drive is prepared for Bitlocker. This is done automatically and transparently. You will then be asked to restart.

After restart, open Bitlocker again via Control Panel.

An additional question is now being asked for devices without a TPM chip. After all, devices without a TPM chip need an alternative to store the key securely. This can be done in two ways:

Please note, for devices without a TPM chip, you will always be asked for the security-key at start-up. If you choose a USB stick, you will always need this USB stick on your device to boot!
If you choose a password, you will always be asked for the password at start-up.

Note: Depending on your keyboard, the numbers may not be recognized! In in that case you can type numbers by using the function keys. That is, F1 = number 1, F2 = number 2, ..

Recovery key

The system will ask you what you want to do with the Recovery Key. You may need this recovery key, for example after updating your systems. Please do well to keep track of it and make your own choice how you wish to do this.

When asked how much you want to encrypt, always choose Encrypt Entire Drive.
For your local hard drive, it is best to choose the latest encryption method.

Perform an additional check (check Run Bitlocker system check).
The actual encryption will start after a restart. You will only notice this by clicking on the Bitlocker icon click in the taskbar. During encryption (can take several hours) you can always restart your PC, switch it off, .. Encryption will continue automatically.

top