<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>BitLocker™ Drive Encryption Team Blog</title><link>http://blogs.technet.com/b/bitlocker/</link><description>


</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Access Denied Error 0x80070005 message when initializing TPM for Bitlocker</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/access-denied-error-0x80070005-message-when-initializing-tpm-for-bitlocker.aspx</link><pubDate>Tue, 14 Sep 2010 21:14:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355478</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355478</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/access-denied-error-0x80070005-message-when-initializing-tpm-for-bitlocker.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Arial;"&gt;Hello, my name is Manoj Sehgal. I am a Senior Support Engineer in the Windows group and today&amp;rsquo;s blog will cover How to initialize TPM successfully when you enable Bitlocker in Windows 7.&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;A common problem we have seen since the release of Windows 7 has been to initialize TPM successfully so that you can successfully turn ON Bitlocker. This is most likely due to incorrect permissions for the SELF account in AD for ms-TPMOwnerInformation attribute.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;When you try to turn on Bitlocker on Windows 7 Operating System Drive, you may get the Access Denied Error message while initializing TPM.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_2.png"&gt;&lt;img height="275" width="355" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Additionally, when you open the TPM Management Console and you try to initialize TPM you get error message 0x80070005.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;b&gt;&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_4.png"&gt;&lt;img height="143" width="244" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_1.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;NOTE: If you are using SCCM to build Windows 7 machines and using Bitlocker Task Sequencer you may see the following error message(s) logged in smsts.log for OSDbitlocker.&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Lucida Console; color: #ff0000; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Lucida Console; color: #ff0000; font-size: xx-small;"&gt;pTpm-&amp;gt;TakeOwnership( sOwnerAuth ), HRESULT=80070005 e:\nts_sms_fre\sms\client\osdeployment\bitlocker\bitlocker.cpp,480)OSDBitLocker 3032 (0x0BD8) &lt;br /&gt;Failed to take ownership of TPM. Ensure that Active Directory permissions are properly configured. &lt;br /&gt;Access is denied. (Error: 80070005; Source: Windows) OSDBitLocker 3032 (0x0BD8)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Resolution:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;To set correct permissions, follow the instruction below:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;1. Open Active Directory Users and Computers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;2. Select the OU where you have all computers which will have Bitlocker turned ON.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;3. Right Click on the OU and click Delegate Control.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_6.png"&gt;&lt;img height="265" width="378" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_2.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;4. Click Next and then click Add.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_8.png"&gt;&lt;img height="270" width="385" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_3.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_10.png"&gt;&lt;img height="141" width="277" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_4.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;5. Type SELF as the Object Name.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_12.png"&gt;&lt;img height="231" width="329" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_5.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;6. Select create a custom task to delegate.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_14.png"&gt;&lt;img height="242" width="346" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_6.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;7. From the object in the folder, select Computer Objects.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_16.png"&gt;&lt;img height="242" width="345" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_7.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;8. Under show these permissions, select all 3 checkbox. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_18.png"&gt;&lt;img height="243" width="347" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_8.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;9. Scroll down in permissions and select the attribute Write msTPM-OwnerInformation.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_20.png"&gt;&lt;img height="245" width="348" src="http://blogs.technet.com/blogfiles/askcore/WindowsLiveWriter/AccessDeniedError0x80070005messagewhenin_AB40/image_thumb_9.png" alt="image" border="0" title="image" style="display: inline; border: 0px;" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;10. Click Finish.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;After you have done the above steps, you should be able to initialize TPM successfully.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;More Information:&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Backing Up BitLocker and TPM Recovery Information to AD DS&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd875529(WS.10).aspx"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;http://technet.microsoft.com/en-us/library/dd875529(WS.10).aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Author: &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Manoj Sehgal&lt;/strong&gt; &lt;br /&gt;Senior Support Engineer &lt;br /&gt;Microsoft Corporation &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355478" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/TPM/">TPM</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Secuirty/">Secuirty</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/0x80070005/">0x80070005</category></item><item><title>How to backup recovery information in AD after Bitlocker is turned ON in Windows 7</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/how-to-backup-recovery-information-in-ad-after-bitlocker-is-turned-on-in-windows-7.aspx</link><pubDate>Tue, 14 Sep 2010 21:12:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355477</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355477</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/how-to-backup-recovery-information-in-ad-after-bitlocker-is-turned-on-in-windows-7.aspx#comments</comments><description>&lt;p&gt;Hello, my name is Manoj Sehgal. I am a Senior Support Engineer in the Windows group and today&amp;rsquo;s blog will cover &amp;ldquo;How to backup recovery information in AD after Bitlocker is turned ON in Windows 7.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;A common question we are asked is how do I save the recovery information for a Windows 7 machine which has Bitlocker turned ON.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;This situation can arise when any of the following conditions are true, but is also not limited to this list:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;br /&gt;a)&amp;nbsp;&amp;nbsp;&amp;nbsp; The machine is Bitlocker&amp;rsquo;ed prior to joining the Domain. &lt;br /&gt;b)&amp;nbsp;&amp;nbsp;&amp;nbsp; The machine is not physically connected to the Network when enabling Bitlocker. &lt;br /&gt;c)&amp;nbsp;&amp;nbsp;&amp;nbsp; When the GPO for Saving Recovery Information for Bitlocker is not setup correctly.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;br /&gt;So when we open Active Directory Users and Computers portion of server manager you do not see msFVE-RecoveryInformation for the machine which was encrypted.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;In this situation we can use manage-bde command from the client machine to save the recovery information in AD, instead of decrypting and encrypting the Operating system drive again for storing recovery information in AD. &lt;br /&gt;First verify that the client machine is in the correct OU in AD where the Bitlocker group policies are applied and then follow the below steps: &lt;/p&gt;
&lt;p&gt;Open elevated command prompt on the client computer and run the below command. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note: You require local admin rights to run manage-bde commands.&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;c:&amp;gt; manage-bde -protectors -get c:&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;Example: &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;Bitlocker Drive Encryption: Configuration Tool version 6.1.7600 &lt;br /&gt;Copyright (C) Microsoft Corporation. All rights reserved. &lt;br /&gt;Volume C: [Old Win7] &lt;br /&gt;All Key Protectors &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; External Key: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID: {F12ADB2E-22D5-4420-980C-851407E9EB30} &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; External Key File Name: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; F12ADB2E-22D5-4420-980C-851407E9EB30.BEK &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Numerical Password: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID: {DFB478E6-8B3F-4DCA-9576-C1905B49C71E} &lt;br /&gt;&lt;/strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Password: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 224631-534171-438834-445973-130867-430507-680922-709896 &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; TPM And PIN: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID: {EBAFC4D6-D044-4AFB-84E3-26E435067AA5}&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;If you see results above you should see ID and Password for Numerical Password. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Now run the below command, replace id for ID of Numerical Password. &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;c:&amp;gt; manage-bde -protectors -adbackup c: -id {&lt;strong&gt;DFB478E6-8B3F-4DCA-9576-C1905B49C71E&lt;/strong&gt;}&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;Bitlocker Drive Encryption: Configuration Tool version 6.1.7600 &lt;br /&gt;Copyright (C) Microsoft Corporation. All rights reserved. &lt;br /&gt;Recovery information was successfully backed up to Active Directory. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Now if you go to AD, and check the client computer you should see &lt;span style="font-family: Consolas; font-size: x-small;"&gt;msFVE-RecoveryInformation&lt;/span&gt; for this client computer. &lt;/p&gt;
&lt;p&gt;For more information on Group Policies for Bitlocker, see my blog below. &lt;br /&gt;&lt;a href="http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx"&gt;http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Manoj Sehgal &lt;br /&gt;Senior Support Engineer &lt;br /&gt;Microsoft Enterprise Platforms Support&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355477" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Recovery+Information/">Recovery Information</category></item><item><title>Bitlocker Policies for Windows 7 on Windows Server 2003 or Windows Server 2008</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/bitlocker-policies-for-windows-7-on-windows-server-2003-or-windows-server-2008.aspx</link><pubDate>Tue, 14 Sep 2010 21:11:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355476</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355476</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/bitlocker-policies-for-windows-7-on-windows-server-2003-or-windows-server-2008.aspx#comments</comments><description>&lt;p&gt;Hello, my name is &lt;b&gt;Manoj Sehgal&lt;/b&gt;. I am a Support Escalation Engineer in the Windows group and today&amp;rsquo;s blog will cover &amp;ldquo;How to get the bitlocker policies for windows 7 for on Windows Server 2003 as domain functional level&amp;rdquo;&lt;/p&gt;
&lt;p&gt;If you open Group Policy Management Editor from a Windows Server 2008 Server you will only see policies for bitlocker for Windows Vista Only and not for Windows 7. &lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/6242.clip_5F00_image002_5F00_556F7C81.jpg"&gt;&lt;img height="276" width="628" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/2045.clip_5F00_image002_5F00_thumb_5F00_5B4A201A.jpg" alt="clip_image002" border="0" title="clip_image002" style="display: inline; border: 0px;" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Microsoft included the bitlocker admx and adml files for Windows 7 in windows server 2008 R2.&lt;/p&gt;
&lt;p&gt;Windows Server 2003 reads only adm files and not admx and adml files. So on Windows Server 2003, you cannot configure admx and adml files.&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;Resolution:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You will have to configure the bitlocker policies from Windows 7 Client machine.&lt;/p&gt;
&lt;p&gt;1. First install RSAT tools for Windows 7 on a windows 7 client machine which is already join to your domain.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=7D2F6AD7-656B-4313-A005-4E344E43997D&amp;amp;displaylang=en&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;2. Then open Group Policy Management Console and create a new policy for bitlocker.&lt;/p&gt;
&lt;p&gt;3. Edit the bitlocker policy which will open group policy management editor.&lt;/p&gt;
&lt;p&gt;4. Now you can see the Bitlocker Drive encryption Policies for Windows 7 Operating System.&lt;/p&gt;
&lt;p&gt;NOTE: Windows 7 machine would need to be used to configure the bitlocker policies for Windows Vista and Windows 7 client machines.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/1452.clip_5F00_image004_5F00_1A3BA0B6.jpg"&gt;&lt;img height="276" width="628" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/3122.clip_5F00_image004_5F00_thumb_5F00_592D2151.jpg" alt="clip_image004" border="0" title="clip_image004" style="display: inline; border: 0px;" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;5. Configure the bitlocker policies and now you can save recovery information in AD.&lt;/p&gt;
&lt;p&gt;6. If you have Windows Server 2008 and you want to have Bitlocker policies for windows 7, then you need to copy the corresponding admx and adml file for bitlocker.&lt;/p&gt;
&lt;p&gt;7. Go to c:\windows\policydefinition folder on Windows Server 2008 R2 machine and then copy the volumeencryption.admx file and corresponding volumeencryption.adml from c:\windows\policydefinition\en-US folder respectively.&lt;/p&gt;
&lt;p&gt;8. Go to Windows Server 2008 and then Copy and Replace the existing volumeencryption.admx located at c:\windows\policydefinition folder and volumeencryption.adml located at c:\windows\policydefinition\en-US folder.&lt;/p&gt;
&lt;p&gt;For more information on Group Policies for Bitlocker, see my blog below. &lt;br /&gt;&lt;a href="http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx"&gt;http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx&lt;/a&gt; &lt;br /&gt;Windows 7, Windows Server 2008 R2 and the Group Policy Central Store &lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/12/09/windows-7-windows-server-2008-r2-and-the-group-policy-central-store.aspx"&gt;http://blogs.technet.com/b/askds/archive/2009/12/09/windows-7-windows-server-2008-r2-and-the-group-policy-central-store.aspx&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Manoj Sehgal &lt;br /&gt;Support Escalation Engineer &lt;br /&gt;Microsoft Enterprise Platforms Support&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355476" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Policies/">Policies</category></item><item><title>How to use Hash of TPM from AD to reset your TPM password</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/how-to-use-hash-of-tpm-from-ad-to-reset-your-tpm-password.aspx</link><pubDate>Tue, 14 Sep 2010 21:09:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355475</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355475</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/how-to-use-hash-of-tpm-from-ad-to-reset-your-tpm-password.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Hello, my name is Manoj Sehgal. I am a Support Escalation Engineer in the Windows group and today&amp;rsquo;s blog will cover &amp;ldquo;How to use Hash of TPM from AD to reset your TPM password&amp;rdquo;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;As per Best Practices for Bitlocker we configure a Group Policy for TPM to backup information in AD DS. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Note: See links at the end to configure the Group Policy for TPM and Bitlocker.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;By design, we save hash of the TPM password in AD and not the actual TPM password.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Consider the below scenarios:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Scenario 1:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Customer rolls out machines using SCCM. SCCM creates a random password for &amp;ldquo;TPM Owner Password&amp;rdquo; as part of enabling bitlocker (MDT does this also).&amp;nbsp; &lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Scenario 2:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;If the user enabled Bitlocker and specified a &amp;ldquo;TPM Owner password&amp;rdquo;.&amp;nbsp; In this instance you could see scenario where you fired that person and need to give the laptop to his replacement. If you do not have the TPM password, you will only able to clear the TPM to factory defaults and then when you restart your computer, it will prompt you for 48 digit bitlocker recovery key.&lt;/span&gt; &lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;This password is saved in AD (msTPM-OwnerInformation) attribute as hash value.&amp;nbsp; By default only domain admins can read this attribute.&lt;/span&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;At some point the domain admin needs to make a change in TPM.MSC.&amp;nbsp; In order to do this you must supply the TPM &amp;ldquo;Owner password&amp;rdquo; otherwise the TPM chip is cleared so you would lose all data on the TPM chip.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Backing up the TPM owner information for a computer allows administrators to locally and remotely configure the TPM security hardware on that computer. As an example, an administrator might want to reset the TPM to factory defaults when decommissioning or repurposing computers.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;In order to reset the TPM Owner Password, follow the below steps:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Resolution:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;1. Open notepad and copy the below information.&lt;/span&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Consolas; font-size: x-small;"&gt;&amp;lt;ownerAuth&amp;gt;JLi2ycvjzYgYaDq5zQ094U/FxAs=&amp;lt;/ownerAuth&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;2. Get the hash information from ms-TPMOwnerInformation attribute and replace the hash information between the &amp;lt;ownerAuth&amp;gt;&amp;hellip;&amp;hellip;&amp;lt;/ownerAuth&amp;gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/8233.clip_5F00_image002_5F00_62117422.jpg"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/3125.clip_5F00_image002_5F00_39C313BE.jpg"&gt;&lt;img height="342" width="626" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/7433.clip_5F00_image002_5F00_thumb_5F00_0CCDB0E3.jpg" alt="clip_image002" border="0" title="clip_image002" style="display: inline; border: 0px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/a&gt;&lt;a&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;3. Save the file as whatevername.tpm.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;4. Open TPM Administration Console (tpm.msc) and Click on Change Owner Password.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/5684.clip_5F00_image004_5F00_3C3B4DBF.jpg"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/7357.clip_5F00_image004_5F00_4433C211.jpg"&gt;&lt;img height="310" width="575" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-59-75-metablogapi/7455.clip_5F00_image004_5F00_thumb_5F00_31129565.jpg" alt="clip_image004" border="0" title="clip_image004" style="display: inline; border: 0px;" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/a&gt;&lt;a&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;5. Select &amp;ldquo;I have the Owner Password File&amp;rdquo; and point it to .tpm file which you got in Step 2.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;6. Now you can successfully change the TPM password.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;For more information on Group Policies for Bitlocker, see my blog below. &lt;br /&gt;&lt;/span&gt;&lt;a href="http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;http://blogs.technet.com/askcore/archive/2010/02/16/cannot-save-recovery-information-for-Bitlocker-in-windows-7.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Bitlocker Policies for Windows 7 on Windows Server 2003 or Windows Server 2008&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/b/askcore/archive/2010/07/02/bitlocker-policies-for-windows-7-on-windows-server-2003-or-windows-server-2008.aspx"&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;http://blogs.technet.com/b/askcore/archive/2010/07/02/bitlocker-policies-for-windows-7-on-windows-server-2003-or-windows-server-2008.aspx&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Arial; font-size: x-small;"&gt;Manoj Sehgal &lt;br /&gt;Support Escalation Engineer &lt;br /&gt;Microsoft Enterprise Platforms Support&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355475" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Security/">Security</category></item><item><title>Issues Resulting in Bitlocker Recovery Mode and Their Resolution</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/issues-resulting-in-bitlocker-recovery-mode-and-their-resolution.aspx</link><pubDate>Tue, 14 Sep 2010 21:08:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355474</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355474</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/issues-resulting-in-bitlocker-recovery-mode-and-their-resolution.aspx#comments</comments><description>&lt;p&gt;My name is Tanner Slayton and I am a Sr. Support Escalation Engineer for Microsoft on the Windows Core Team. I am writing today to shed some light on a common Bitlocker problem that we see. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-size: 9pt;"&gt;* While you can accomplish most tasks via the Bitlocker Control Panel Applet, I am going to be using the manage-bde commands from an elevated command prompt. &lt;/span&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: 0.5in;"&gt;Specific operations or actions will cause Bitlocker to go into Recovery Mode and ask you to enter the 48-digit Recovery Key. This can be caused by several things, and a complete list can be viewed &lt;a href="http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx#BKMK_examplesosrec"&gt;here&lt;/a&gt; , but today I am going to go over the most common issues. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 1:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;When you are using a Laptop or Desktop computer and do not have the BIOS Boot order with the OS HDD listed as the first boot device. The reason for this is the boot device makes up part of the system measurement used by Bitlocker and this must remain consistent to validate the system status and unlock BitLocker. (I.e. if you have the DVD-ROM drive listed first and had a bootable media inserted, this can cause the system measurement to change.)&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Some firmware will also treat &lt;a href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/ADS/en-us/nbs_boot_policy_overview.mspx?mfr=true"&gt;PXE network boot&lt;/a&gt; as a change in boot order &amp;ndash; even when the user does not choose network boot. Changing from a wireless to wired network can trigger a recovery event.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Putting the HDD first in boot order generally eliminates these issues. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l1 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Suspend Bitlocker drive encryption by typing "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -protectors -disable c:&amp;rdquo; &lt;/b&gt;&lt;a name="_GoBack"&gt;&lt;/a&gt;from an elevated command prompt. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l1 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'MS Shell Dlg 2', 'sans-serif'; color: black; font-size: 9pt;"&gt;Go into the BIOS and change the Boot Order so the OS HDD is first in the list&lt;/span&gt;. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.75in; mso-list: l1 level2 lfo1; mso-add-space: auto;"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 9pt; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-size: 9pt;"&gt;By default from most hardware vendors, the HDD is not the first boot device. &lt;/span&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.75in; mso-list: l1 level2 lfo1; mso-add-space: auto;"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 9pt; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-size: 9pt;"&gt;If you have a laptop with a docking station, make sure that it is plugged into the docking station, in order to make sure that the external devices presented by the docking station are present in BIOS. &lt;/span&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l1 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 9pt; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Boot into the Operating System and run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -protectors -enable c:&lt;/b&gt;"&lt;span style="line-height: 115%; font-size: 9pt;"&gt; &lt;/span&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 2:&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;When you are either deploying a new system or encrypting the drive for the first time. You might pause the Bitlocker encryption process, in order to speed up the performance or while performing other tasks, so that encryption can run later or you need more than the 6 GB worth of free space to continue deploying the system.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;When you run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -pause c:&lt;/b&gt;" you are pausing the drive encryption of C:, but not the Bitlocker protectors on the system. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;You might say to yourself, if I run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -status c:&lt;/b&gt;" I see that the protection is off on that drive. The reason you see this is that the protection for the drive is not yet completed, but the clear text key still exists. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;Volume C: [] &lt;br /&gt;[OS Volume] &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Size:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;37.17 GB &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;BitLocker Version:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Windows 7 &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Conversion Status:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Encryption Paused &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Percentage Encrypted: 3% &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Encryption Method:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;AES 128 with Diffuser &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Protection Status:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Protection Off &lt;b style="mso-bidi-font-weight: normal;"&gt;&amp;lt;--- Where it shows "Protection Off" &lt;br /&gt;&lt;/b&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Lock Status:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Unlocked &lt;br /&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Identification Field: None &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l3 level1 lfo2; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;When you need to pause the encryption, whether for performance or drive space reasons, you need to run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -pause c:&lt;/b&gt;" &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l3 level1 lfo2; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;After encryption has been paused, you will want to run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -protectors -disable c:&lt;/b&gt;" &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l3 level1 lfo2; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Once you have completed your tasks and wish to start the encryption process again you can run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -resume c:&lt;/b&gt;" &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l3 level1 lfo2; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Once the encryption is complete, or if you have completed your tasks, you will then want to run "&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde -protectors -enable c:&lt;/b&gt;" &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 3:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The BIOS / TPM firmware are out of date on the systems. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution: &lt;/b&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l0 level1 lfo3; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Suspend Bitlocker drive encryption &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;disable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l0 level1 lfo3; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Update the BIOS on the system &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.75in; mso-list: l0 level2 lfo3; mso-add-space: auto;"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 9pt; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-size: 9pt;"&gt;If there is a TPM Firmware update, please follow the vendor installation instructions. &lt;/span&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l0 level1 lfo3; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Reboot the Operating System and run &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;enable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 4:&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;When you are installing additional language packs onto the system, and selecting the option to apply the language settings to all users and system accounts. This causes a locale change in the BCD (Boot Configuration Database), which Bitlocker with TPM interprets as a boot attack. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution:&lt;/b&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l4 level1 lfo4; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Suspend Bitlocker drive encryption &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;disable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l4 level1 lfo4; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Add language packs to the system and make any language settings. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l4 level1 lfo4; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Resume Bitlocker drive encryption &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;enable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 5:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;When you create or modify any of the partitions that reside on the O/S drive. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution:&lt;/b&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l2 level1 lfo5; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Suspend Bitlocker drive encryption &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;disable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l2 level1 lfo5; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Shrink, expand, or create any partitions on the drive. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l2 level1 lfo5; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Resume Bitlocker drive encryption &amp;ldquo;&lt;b style="mso-bidi-font-weight: normal;"&gt;manage-bde &amp;ndash;protectors &amp;ndash;enable c:&lt;/b&gt;&amp;rdquo; &lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Scenario # 6:&lt;/b&gt;&lt;span style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The TPM chip has been turned off in BIOS. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;Resolution:&lt;/b&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin-left: 1.25in; mso-list: l2 level1 lfo5; mso-add-space: auto;"&gt;&lt;span style="font-family: 'Courier New'; mso-fareast-font-family: 'Courier New';"&gt;&lt;span style="mso-list: ignore;"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;span style="font-family: Arial; font-size: x-small;"&gt;Go into BIOS and make sure the the TPM Security is enabled and on&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;Tanner Slayton &lt;br /&gt;Senior Support Escalation Engineer &lt;br /&gt;Microsoft Enterprise Platforms Support &lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355474" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Recovery+Mode/">Recovery Mode</category></item><item><title>BitLocker &amp; Application Compatibility</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/bitlocker-amp-application-compatibility.aspx</link><pubDate>Tue, 14 Sep 2010 20:57:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355470</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355470</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/bitlocker-amp-application-compatibility.aspx#comments</comments><description>&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;Recently I received an interesting question around BitLocker &amp;amp; Application Compatibility. In other words will an application, which works on a machine without BitLocker also work on a machine with BitLocker enabled? I believe it sounds as simple a question as important it is. &lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;Quick answer is that the BitLocker Drivers are at a very low level in the software system stack; below the file system. So BitLocker is transparent to applications and it shouldn&amp;rsquo;t cause any incompatibility for most applications that runs in normal Windows environment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;However, considering how important could this topic could be in Enterprise situations I thought of going beyond what I know or expect and finding some real world data around it. I contacted several Enterprise &amp;amp; Medium businesses who had BitLocker deployed for some time and asked their experience. Here are some facts &amp;amp; findings:&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 21pt; mso-list: l0 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: Symbol; color: #953735; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;middot;&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: #953735;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;Will an application which works on a machine without BitLocker also work on a machine with BitLocker enabled?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;For almost all case, yes. In this case, I could just say &amp;ldquo;Yes&amp;rdquo; but the reason I&amp;rsquo;m saying &amp;ldquo;almost all&amp;rdquo; is because I recommend that Enterprise Administrators evaluate which application interact with the disk via file system &amp;amp; which do not. For applications that do not use file system and interact directly with the raw data on disk, Application owners or IT administrators may want to perform a sanity check for those application with &amp;amp; without enabling BitLocker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 21pt; mso-list: l0 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: Symbol; color: #953735; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-bidi-font-size: 13.5pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;middot;&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: #953735;"&gt;Which applications are known to have incompatibilities due to BitLocker enablement?&lt;/span&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;In the study I performed, few back-up applications that operate the disk at sector level were heard to have compatibilities raised after enabling BitLocker. Similarly some system internal utilities that access the drive at the block level may have incompatibilities. Some disk partitioning tools trying to manipulate BitLocker encrypted partition may also have issues with partitions that are BitLocker encrypted &amp;ndash; however such issues were found to be intuitive to detect &amp;amp; troubleshoot. I didn&amp;rsquo;t hear any desktop application that did not work with BitLocker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 21pt; mso-list: l0 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: Symbol; color: #953735; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-bidi-font-size: 13.5pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;middot;&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: #953735;"&gt;Did we find any evidence of application compatibility issues after enabling BitLocker?&lt;/span&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;For any desktop application, so far no application compatibility issues were found.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 21pt; mso-list: l0 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: Symbol; color: #953735; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-bidi-font-size: 13.5pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;middot;&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: #953735;"&gt;On which Operating System BitLocker was enabled by these customers?&lt;/span&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;Windows Vista &amp;amp; Windows7.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 21pt; mso-list: l0 level1 lfo1; mso-add-space: auto;"&gt;&lt;span style="font-family: Symbol; color: #953735; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-bidi-font-size: 13.5pt;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;middot;&lt;/span&gt;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="color: #953735;"&gt;For how long those BitLocker deployments were in place?&lt;/span&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 21pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;From 2 to 3 years, including pilot &amp;amp; production deployments both.&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;span style="text-decoration: underline;"&gt;Other things to know&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="color: black;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;Other than the application specific &amp;nbsp;incompatibilities as you would expect, in some scenarios like patch update, OS upgrade or automated deployments you may need to suspend/pause (or in rare cases decrypt) BitLocker on one or more partitions. Best practices, scripts &amp;amp; other information on this topic is already&amp;nbsp;covered in many of the BitLocker documents e.g. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx#BKMK_examplesosrec"&gt;&lt;span&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;&lt;span style="font-size: x-small;"&gt;BitLocker FAQ&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;Hope this helps! If you had a different experience, do post a comment here or send me a message. &lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="color: #993366;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: x-small;"&gt;-Tanu Mutreja&lt;span style="font-family: 'Segoe UI', 'sans-serif'; font-size: 13.5pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 7.5pt;"&gt;&lt;span style="font-family: 'Verdana', 'sans-serif'; color: black; font-size: 7.5pt;"&gt;[This posting is provided "AS IS" with no warranties, and confers no rights.]&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 7.5pt;"&gt;&lt;span style="font-family: 'Verdana', 'sans-serif'; color: black; font-size: 7.5pt;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 7.5pt;"&gt;&lt;span style="font-family: 'Verdana', 'sans-serif'; color: black; font-size: 7.5pt;"&gt;Also found at: &lt;a href="http://blogs.technet.com/b/wincat/archive/2010/09/02/bitlocker-amp-application-compatibility.aspx"&gt;http://blogs.technet.com/b/wincat/archive/2010/09/02/bitlocker-amp-application-compatibility.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355470" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Server+Security/">Server Security</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Data+Protection/">Data Protection</category></item><item><title>Top 10 Reasons for Deploying BitLocker on Branch Office Servers</title><link>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/top-10-reasons-for-deploying-bitlocker-on-branch-office-servers.aspx</link><pubDate>Tue, 14 Sep 2010 20:55:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3355467</guid><dc:creator>Tanner S</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=3355467</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2010/09/14/top-10-reasons-for-deploying-bitlocker-on-branch-office-servers.aspx#comments</comments><description>&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Top 10 Reasons for Deploying BitLocker on Branch Office Servers&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;1.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Information Loss is Costly&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Information is the key asset of IT industry. Losing this asset or getting it in wrong hands can be equally damaging for all businesses small, medium or large. In 2004, the U.S. Department of Justice estimated that intellectual property theft cost enterprises $250 billion. Whether it&amp;rsquo;s Personal Identifiable Information (PII), individual health or financial records, employee HR records, organization&amp;rsquo;s operational data or other intellectual property, losing information can cause lot of damage to an organization. The more sensitive data your organization store the higher the risk. It can cause not only loss of revenue, loss of market credibility, competitive disadvantage but also the non-compliance penalties. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;2.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Governance &amp;amp; Regulations&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Regulations around data protection as in Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA) and European Data Protection Supervisor (EDPS) are increasing around the globe and non-compliance penalties can be significant. Irrespective of the business sizes, locales or activities regulatory conditions are getting stricter for protecting data at all stages including data at rest, data in transit, hardware transportation and safe hardware disposal. Implications of non-compliance can get severe with the sensitivity of data a business keeps.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;3.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Equipment theft or loss isn&amp;rsquo;t limited to laptops or mobile devices&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;While mobility of a device makes the device much more prone to theft or loss, mobility isn&amp;rsquo;t the only factor adding to data loss risk. There have been number of incidents reported where theft of IT equipment was committed during a physical break‐into a business premise especially for server systems. This is particularly a concern for small and medium businesses and branch office servers. In these businesses, due to the nature of business and IT infrastructure not every server and storage media is enclosed in iron walls. Think of desktops and servers around you and it won&amp;rsquo;t be hard to realize the potential vulnerabilities in case of physical break-in.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;4.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Physical protection is not enough&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Even when servers are in iron cages and there are resources physically guarding the data, data in clear text remains at risk. Studies have shown that despite the&amp;nbsp;high level of physical protection like in secure data centers, thousands of data drives leave data center on daily basis. While some drives go out for reasons like repair, return or re-provision, others are stolen or lost. In other cases data cloning (e.g. for maintenance or outsourcing) adds to the risk of data loss without the data leaving its secure physical boundary. Essentially data remains vulnerable until the data itself has a protection via encryption or other such techniques.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;5.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Safe decommissioning or re-provisioning of disks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Decommission or re-provisioning of a server or its hard drives is part of hardware lifecycle in a business. Ensuring safe decommissioning or re-provisioning is becoming a critical consideration for organizations. This requirement has led organizations to adopt a variety of mechanisms with most being cumbersome. By providing the capability to destroy Volume Encryption Keys, BitLocker provides a reliable and easy way for safe disposal of data. This simple and secure method can save multiple hours of data reclamation efforts and can significantly help in retaining and proving compliance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;6.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Safe transportation of pre-configured systems or disks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Transportation of provisioned systems or data drives is a common Branch Office and Enterprise scenario. People carrying their data drives along or sending data drives for repair aren&amp;rsquo;t uncommon either. In all such scenarios, it&amp;rsquo;s important to protect the data on the disks so an errant disk doesn&amp;rsquo;t end up in information loss or theft. BitLocker is the one reliable way to enable Branch Offices and Enterprises to reduce the risk and transport data drives around with higher confidence. With BitLocker data can be protected with a PIN at one end and can then be accessed by authorized personnel at other end.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;7.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Retain boot integrity and enable multi-factor authentication via TPM&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;BitLocker has capability to provide authentication for different needs and different security levels needed. It uses TPM (Trusted Platform Module v1.2) to validate boot integrity of the system. BitLocker can also use TPM with PIN or with startup key or with PIN and startup key both. &amp;nbsp;On the other hand, where server systems happen to be headless i.e. no keyboard, mouse and video display, or no USB port or inaccessible, TPM authentication can help avoid the requirements of manual intervention for PIN or startup key. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;8.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Smooth integration with Active Directory and policy based controls&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0.75pt 0pt 0.5in;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;BitLocker inherently integrates with Active Directory for supporting a number of scenarios like automated backup of certain BitLocker parameters like recovery password. With the use of granular Group Policies, BitLocker deployment can be highly customized for a deployment environment. Fact that Active Directory is mature and well understood technology makes BitLocker integration with Active Directory cause minimal impact to existing ecosystem and helps in reduced learning curve and faster deployments. Familiarity with Active Directory also helps BitLocker deployment professionals in exploring and leveraging information stored in AD for variety of purposes like enhanced logging and auditing.&lt;/span&gt;&lt;span style="font-family: 'Verdana', 'sans-serif'; color: black; font-size: 8pt;"&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;9.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;BitLocker is already in the Operating System &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;With Windows Server 2008 or Windows Server 2008 R2, BitLocker is available as a user-installable feature in all x64 editions. Protection of your data at rest with no additional cost is just a few mouse clicks away. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;10.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Drive encryption is a one-time task&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Enabling BitLocker on a disk volume is a one-time task. Initially when BitLocker is enabled on a disk volume, for the first time BitLocker encrypts the whole volume &amp;amp; later no specific efforts are required for keeping the data encrypted. Depending on the quality of hard-drive the initial encryption time could vary but the benefits simply outweigh this one-time effort. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Useful references: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;BitLocker Drive Encryption in Windows7 - Frequently Asked Questions&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/si_team/"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;System Integrity Blog&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; for understanding BitLocker knowhow.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Still have questions, feel free to submit here or send my way(&lt;a href="mailto:tmutrej@online.microsoft.com"&gt;tmutrej@online.microsoft.com&lt;/a&gt; - after removing online from this address).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Also found at: &lt;a href="http://blogs.technet.com/b/wincat/archive/2010/03/20/top-10-reasons-for-deploying-bitlocker-on-branch-office-servers.aspx"&gt;http://blogs.technet.com/b/wincat/archive/2010/03/20/top-10-reasons-for-deploying-bitlocker-on-branch-office-servers.aspx&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3355467" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Bitlocker/">Bitlocker</category><category domain="http://blogs.technet.com/b/bitlocker/archive/tags/Branch+Office+Servers/">Branch Office Servers</category></item><item><title>BitLocker Makeover</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/09/03/453851.aspx</link><pubDate>Mon, 04 Sep 2006 03:26:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453851</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>4</slash:comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;The Windows Vista RC1 release is quickly approaching and I know many of you are eager to hear the latest and greatest news about BitLocker.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Well, wait no more my fervent comrades!&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;Anyone who is familiar with previous builds may recall walking through separate wizards for the TPM and BitLocker functionalities – and thinking, “wait, didn’t I just do this?”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We realized this was a bit confusing, so in RC1 the TPM initialization wizard functionalities have been integrated directly into the BitLocker setup wizard (on TPM machines).&amp;nbsp; You now only need to run the single BitLocker setup wizard, although the TPM MMC snap-in can still be used separately.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;No muss, no fuss!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;But wait, there’s more!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Below you will find additional simplifications that have been made to the BitLocker wizard, which should provide for a straightforward setup experience.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So download now, and get your copy of RC1 today!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;U&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;SPAN style="TEXT-DECORATION: none"&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;STRONG&gt;&lt;FONT face=Tahoma&gt;TPM by Default&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;STRONG&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;In response to customer feedback, we have made some simplifications to the default user interface for BitLocker.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;By default, the BitLocker setup wizard will not run without a compatible TPM; and on those with a compatible TPM, the interface no longer displays the advanced options to create a startup PIN or USB startup key.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;But for those who still want these features – don’t fret!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To restore access to the advanced options in the BitLocker setup wizard, just click the following link to review the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=311f4be8-9983-4ab0-9685-f1bfec1e7d62&amp;amp;DisplayLang=en"&gt;&lt;FONT face=Tahoma color=#006629&gt;BitLocker Step-by-Step Guide for RC1.&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Note that this document will be updated concurrent to the RC1 release.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;STRONG&gt;&lt;FONT face=Tahoma&gt;System Check Option&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;STRONG&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;The purpose of the BitLocker System Check is to verify that the hardware and BIOS is compatible with BitLocker, and that access to the encryption and recovery keys is possible.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This check is now an explicit option in the setup wizard when turning on BitLocker.&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana; mso-bidi-font-family: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;To prevent a setup failure and resolve hardware issues, BitLocker can complete the system check during BitLocker setup.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Choosing this option requires a restart but ensures that encryption is only started if the computer passes the system check.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;To access the system check in the BitLocker setup wizard, follow the instructions below:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=numberedlist1 style="MARGIN: 3pt 0in 3pt 0.75in; TEXT-INDENT: -0.25in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;Click &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Start&lt;/SPAN&gt;&lt;/STRONG&gt;, click &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Control Panel&lt;/SPAN&gt;&lt;/STRONG&gt;, click &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Security&lt;/SPAN&gt;&lt;/STRONG&gt;, and then click &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;BitLocker Drive Encryption&lt;/SPAN&gt;&lt;/STRONG&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=numberedlist1 style="MARGIN: 3pt 0in 3pt 0.75in; TEXT-INDENT: -0.25in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;If the &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;User Account Control&lt;/SPAN&gt;&lt;/STRONG&gt; dialog box appears, verify that the proposed action is what you requested, and then click &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Continue&lt;/SPAN&gt;&lt;/STRONG&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=NumberedList10 style="MARGIN: 3pt 0in 3pt 0.75in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;3)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;From the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;BitLocker Drive Encryption&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt; page, click&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt; Turn On BitLocker &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;for the OS volume.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=TextinList1 style="MARGIN: 3pt 0in 3pt 0.75in"&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;&lt;FONT size=2&gt;&lt;FONT face=Tahoma&gt;If your TPM is not initialized, you will see the &lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Initialize TPM Security Hardware&lt;/SPAN&gt;&lt;/STRONG&gt; wizard. Follow the directions to turn on the TPM and restart your computer. After the restart, the BDE wizard will launch itself to continue the setup.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=NumberedList10 style="MARGIN: 3pt 0in 3pt 0.75in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;4)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;Choose the preferred recovery password storage method from the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Save the recovery password&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt; page.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;After saving the password to the desired location, click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Next&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=NumberedList10 style="MARGIN: 3pt 0in 3pt 0.75in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;5)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;From the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Encrypt the selected disk volume&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt; page, check the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Run BitLocker system check&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt; box, and click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial"&gt;Continue&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-bidi-font-weight: bold"&gt;.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=TextinList1 style="MARGIN: 3pt 0in 3pt 0.75in; TEXT-INDENT: -0.25in; mso-list: l0 level3 lfo1; tab-stops: list .75in"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=2&gt;6)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-bidi-font-weight: bold"&gt;Insert the recovery password USB flash drive (if you saved the password on a USB drive), and click &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="COLOR: gray; FONT-FAMILY: Arial; mso-bidi-font-weight: normal"&gt;Restart Now&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: Arial; mso-bidi-font-weight: bold"&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: Arial"&gt;The computer restarts and BitLocker checks to make sure that the computer is BitLocker-compatible and ready for encryption. If it is not, you will see an error message alerting you to the problem and no encryption is applied to the OS volume.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.25in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;For a related music selection:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;David Bowie – “Changes” from the album “Changesonebowie” (1976)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;FONT face=Tahoma&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 10pt 0.25in; TEXT-INDENT: -0.25in; mso-list: l2 level1 lfo3; mso-add-space: auto"&gt;&lt;FONT face=Tahoma&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:place w:st="on"&gt;&lt;st1:PlaceName w:st="on"&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: Arial"&gt;Valerie&lt;/SPAN&gt;&lt;/st1:PlaceName&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: Arial"&gt; &lt;st1:PlaceName w:st="on"&gt;Bays&lt;/st1:PlaceName&gt;&lt;/SPAN&gt;&lt;/st1:place&gt;&lt;SPAN style="FONT-SIZE: 10pt; LINE-HEIGHT: 115%; FONT-FAMILY: Arial"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=453851" width="1" height="1"&gt;</description></item><item><title>Open Sesame: BitLocker Recovery Passwords</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/08/21/448359.aspx</link><pubDate>Tue, 22 Aug 2006 02:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:448359</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>1</slash:comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Anyone who has tried enabling BitLocker will have been greeted with a friendly dialog box insisting that you create a recovery password.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I remember the first time I saw this, I found myself asking, “what is this recovery password, and what am I supposed to do with it?”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;Let’s first take a look at the BitLocker system.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;BitLocker has two major features: 1) it encrypts the hard drive to prevent offline attacks against lost or stolen laptops and, 2) it takes &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/whdc/system/platform/hwsecurity/BitLockerTechOver.mspx"&gt;&lt;FONT face=Calibri&gt;measurements of the boot process&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; to ensure the integrity of the system at start-up.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These measurements detect attacks that try to get into your system before the OS loads.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;If the measurements taken during start-up match the measurements taken when BitLocker was enabled, the system will boot into &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:place w:st="on"&gt;Vista&lt;/st1:place&gt; as expected.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If the measurements change, however, BitLocker will enter recovery mode.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There are several scenarios that can cause these measurements to change.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some scenarios are harmless, like moving a BitLocker-protected drive into a new computer, while others are malicious, like a rootkit attack.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For a more complete discussion of recovery scenarios, check out the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/whdc/system/platform/hwsecurity/BitLockerTechOver.mspx"&gt;&lt;FONT face=Calibri&gt;BitLocker Technical Overview&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;In recovery mode, encrypted data will not be unlocked unless you can present the recovery password, either by inserting a USB flash drive containing the recovery password or typing it in manually.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Start-up PINs and keys will not work in recovery mode. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;This leads to two critical points:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;If you lose the recovery password and the system goes into recovery mode, the data is irretrievable.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l1 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;If an adversary gets your recovery password, he can make changes to your system and bypass BitLocker. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;This is equivalent to a thief learning your Windows XP administrator password or mothers’ maiden name.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;So this leads to an interesting dichotomy: you want to preserve your recovery password, but not leave it accessible to an attacker.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Taping your recovery password to your laptop is a bad idea.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But what other backup options are available?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Well, we have a few ideas:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Save your recovery password on a USB drive, and put it on your key chain (or in a safe).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Print out the recovery password and hide it away in a file folder.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Burn the recovery password onto a CD (or floppy) and store that away in some safe place.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo2"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;BitLocker also supports automatic backup to Active Directory servers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This will be the recommended method for backing up recovery passwords in business scenarios.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt; mso-add-space: auto"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=ListParagraphCxSpLast style="MARGIN: 0in 0in 10pt; mso-add-space: auto"&gt;&lt;FONT face=Calibri&gt;Two things you should always remember about the BitLocker recovery password: back it up and keep it safe.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;For a related music selection:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;‘N Sync – “I Want You Back” from the album “’N Sync” (1998)&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 10pt 0.25in; TEXT-INDENT: -0.25in; mso-add-space: auto; mso-list: l2 level1 lfo3"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;Jonathan Rhodes&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=ListParagraph style="MARGIN: 0in 0in 10pt 0.25in; TEXT-INDENT: -0.25in; mso-add-space: auto; mso-list: l2 level1 lfo3"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=448359" width="1" height="1"&gt;</description></item><item><title>Keys to the Kingdom</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/08/01/bitlockerkeys.aspx</link><pubDate>Tue, 01 Aug 2006 23:36:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:444387</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=444387</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/08/01/bitlockerkeys.aspx#comments</comments><description>Every wonder about all those keys in BitLocker? Here's the scoop on the ones you need to care about....(&lt;a href="http://blogs.technet.com/b/bitlocker/archive/2006/08/01/bitlockerkeys.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=444387" width="1" height="1"&gt;</description></item><item><title>BitLocker and unallocated space</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/07/08/unallocated.aspx</link><pubDate>Sun, 09 Jul 2006 09:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:440847</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=440847</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/07/08/unallocated.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Verdana size=2&gt;I often see two questions related to free (a.k.a. “unallocated”) disk space when people talk about Windows BitLocker™ Drive Encryption on various forums:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;&lt;EM&gt;Q: What happens to unallocated space when I enable BitLocker on my volume? Does it get encrypted?&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;&lt;EM&gt;Q: I enabled BitLocker on my volume and – poof! – all my free space is gone! What’s wrong? More importantly, how do I get it back?&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;Good news: nothing is wrong and the only thing that you have to do to get it back is wait. Here’s a high level explanation (some intricate technical details have been omitted for brevity).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;In the IT world “delete” usually means “remove from plain view” rather than “obliterate out of existence”. Unallocated disk space is prone to contain interesting data: rotting skeletons of compensation spreadsheets, “deleted” text files with passwords and credit card numbers, discarded autosave copies of top secret presentations. Hence, BitLocker cannot just ignore free space when the volume is being encrypted.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;On the other hand, encrypting (or, to be exact, “reading, encrypting, and writing back”) free space is a real waste on a typical volume that is usually less than twenty percent full. As a performance optimization, BitLocker simply overwrites unallocated space with noise, thereby avoiding redundant reads. As expected, wiping free space is about two times faster than encrypting data, but it still takes considerable time on large volumes.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;Now, free space tends to be very fluid. Unallocated chunks of disk space appear and disappear all over the place, all the time. Determining whether a given sector needs to be encrypted or wiped at a particular moment of time is a considerable technical challenge. BitLocker solves this problem by creating a huge file that takes most of the available disk space (leaving 6 GB for short-term system needs) and wiping disk sectors that belong to the file. Everything else (including ~6 GB of free space not occupied by the wipe file) is encrypted. When encryption of the volume is paused or completed, the wipe file is deleted and the amount of available free space reverts to normal.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;(Note: if you have a Beta 2 build, you may have noticed that volume conversion leaves only 2 GB of free space, not 6 GB as described here. Increasing the amount of free space available during conversion from 2 GB to 6 GB was a recent change that is aimed to avoid ‘disk full’ errors in some common scenarios, such as installation of large software packages or writing a full memory dump on systems with 2+ GB of RAM.)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;When BitLocker is turned off and the volume is decrypted, the wipe file is created in a similar way, and everything except the wipe file is decrypted. There is no need to decrypt sectors that are occupied by the wipe file, since no useful data is contained therein. Wiping unallocated space is not necessary either, as the whole volume is reverted to clear text anyway. As such, sectors occupied by the wipe file are skipped during decryption; consequently, decryption of a volume is typically much faster than encryption. As in the case of encryption, the wipe file is deleted when decryption is paused or completed. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana size=2&gt;And finally, a bit of trivia: the noise that is used to overwrite free space is generated by encrypting a buffer filled with 0x57 (‘W’ in ASCII code). So, if you ever opened an encrypted volume in a disk viewer and wondered what those vast spaces filled with W’s are – that’s most probably unallocated space that has been wiped during encryption.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Tahoma"&gt;—&lt;/SPAN&gt; &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/bitlocker/articles/bulats.aspx"&gt;&lt;FONT size=2&gt;Bulat Shelepov&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=440847" width="1" height="1"&gt;</description></item><item><title>Doing our part for BitLocker™ Drive Encryption: Particular requirements around partitioning</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/06/09/partitionvistab2.aspx</link><pubDate>Fri, 09 Jun 2006 21:37:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:434570</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=434570</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/06/09/partitionvistab2.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;On May 23-25, members of the BitLocker team participated in the &lt;A title=http://www.microsoft.com/whdc/winhec/ href="http://www.microsoft.com/whdc/winhec/"&gt;Windows Hardware Engineering Conference (WinHEC)&lt;/A&gt; in Seattle. It was a successful event for us, and we even got some mentions in keynote speeches. Everyone we talked to understood the importance of encrypting the entire disk volume, and there was a great deal of excitement that this feature will be available in Windows Vista and Windows Server "Longhorn".&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Anticipation aside, we know that the true test of a product is in customers using it. Based on WinHEC and other recent feedback, we want to highlight a detour you might encounter on your way to better data protection with BitLocker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;With a newly-installed Windows Vista Beta 2 build, don’t despair if you see that you need to "reconfigure" your hard disk before you can turn on BitLocker. It’s not your fault!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The fact is, you need two partitions set up on your disk before you can turn on BitLocker.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The first partition, called the system volume, contains the boot information in an unencrypted space. This partition must be at least 1.5 GB in size and should not be used as a spare place to store files.&amp;nbsp; BitLocker requires this partition because of architectural constraints and the need to be compatible with existing technologies.&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;The second partition, called the operating system volume, contains Windows and user data and can be fully encrypted by BitLocker. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;To partition your computer, Vista Beta 2 requires that you reinstall Vista from the product DVD and set up the necessary partitioning during the installation. We, too,&amp;nbsp;quite dislike the burden &lt;A title=http://www.microsoft.com/technet/windowsvista/library/c61f2a12-8ae6-4957-b031-97b4d762cf31.mspx#BKMK_S1 href="http://www.microsoft.com/technet/windowsvista/library/c61f2a12-8ae6-4957-b031-97b4d762cf31.mspx#BKMK_S1"&gt;these steps&lt;/A&gt; place on you. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;Will you need to reinstall and run “diskpart” when Windows Vista is a finished product?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Not if we have anything to say about it. Here's what were a trying to do:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;We are working closely with computer manufacturers to have these two partitions configured by default in new computers. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;We are working with enterprise customers to make sure they can set up their Vista deployment processes appropriately (enterprise customers use automated processes that can seamlessly set up the partitioning).&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="FONT-FAMILY: 'Verdana','sans-serif'"&gt; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 3pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=disc&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;We are working on a partitioning tool that takes care of the repartitioning so you won’t have to reinstall and type the “diskpart” commands needed in the Windows Vista Beta 2 release. In effect this tool "converts" a disk to a more BitLocker-friendly state.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;For now, if you’re a beta tester for Windows Vista Ultimate edition or an employee evaluating the feature for your enterprise, we’d really appreciate it if you can step through this detour, enable BitLocker, and let us know what you think about the data protection capabilities it offers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;For more information on partitioning your computer for BitLocker:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A title=http://www.microsoft.com/technet/windowsvista/library/c61f2a12-8ae6-4957-b031-97b4d762cf31.mspx#BKMK_S1 href="http://www.microsoft.com/technet/windowsvista/library/c61f2a12-8ae6-4957-b031-97b4d762cf31.mspx#BKMK_S1"&gt;BitLocker Step by Step Guide&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;For a related music selection:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A title=http://www.pinkspage.com/ href="http://www.pinkspage.com/"&gt;P!nk&lt;/A&gt; – “Get the Party Started” from the album “M!ssundaztood” (2001)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana size=2&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Verdana','sans-serif'"&gt;- &lt;A href="http://blogs.technet.com/bitlocker/articles/xianke.aspx"&gt;Xian Ke&lt;/A&gt;, on behalf of the BitLocker team&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=434570" width="1" height="1"&gt;</description></item><item><title>Why you need to own your Trusted Platform Module (TPM)</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/06/06/owntpm.aspx</link><pubDate>Tue, 06 Jun 2006 23:43:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:433065</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=433065</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/06/06/owntpm.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;You might think that having your TPM security hardware be “owned” may not be a good thing. If you’re well-versed in &lt;A title=http://en.wikipedia.org/wiki/Owned href="http://en.wikipedia.org/wiki/Owned"&gt;slang&lt;/A&gt;, you’re excused. However, to own or “take ownership” of your computer’s TPM is actually desirable for both functionality &lt;I&gt;and &lt;/I&gt;security. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;Taking ownership of the TPM allows you to make full use of TPM capabilities and prevents any other user or software from usurping your ownership title. You are a TPM’s owner if you’re able to set the TPM owner password. Only one owner password exists per TPM, and anyone who knows that password effectively acts as the TPM owner. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;So what’s the difference in functionality between a TPM&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Verdana"&gt; which has a set owner and one which does not? Give&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;n that a TPM has an owner, what can the TPM owner do that a non-owner cannot? The first question is answered by documentation in the &lt;A title=asdfasdf href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/isowned_win32_tpm.asp"&gt;IsOwned&lt;/A&gt; method of the &lt;A title=asdfasdf href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/win32_tpm.asp"&gt;Vista TPM Windows Management Instrumentation (WMI) interface&lt;/A&gt;. This same WMI interface allows TPM owners to remotely configure a computer’s TPM. The WMI method &lt;A href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/converttoownerauth_win32_tpm.asp"&gt;ConvertToOwnerAuth&lt;/A&gt; takes as input the owner password and derives the 20-byte value that the TPM actually uses to authorize owner-restricted TPM functionality. You can then use the 20-byte owner authorization value to run WMI methods to &lt;A title=asdfasdf href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/enable_win32_tpm.asp"&gt;Enable&lt;/A&gt;, &lt;A title=asdfasdf href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/disable_win32_tpm.asp"&gt;Disable&lt;/A&gt;, and &lt;A title=asdfasdf href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secprov/security/clear_win32_tpm.asp"&gt;Clear&lt;/A&gt; a TPM. Of course, remotely configuring the TPM is not exactly the most interesting owner-only functionality that a TPM supports. Consult the “Owner Permission Settings” section of the &lt;A title=https://www.trustedcomputinggroup.org/specs/TPM href="https://www.trustedcomputinggroup.org/specs/TPM"&gt;Trusted Computing Group’s Structures of the TPM specification&lt;/A&gt; to list the TPM commands that are available only to a TPM owner. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;For more information on setting a TPM owner:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="MARGIN-TOP: 0in" type=circle&gt;
&lt;LI class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;&lt;A href="http://www.microsoft.com/technet/windowsvista/library/29201194-5e2b-46d0-9c77-d17c25c56af3.mspx"&gt;TPM Step by Step Guide&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;For a related terminology trivia: &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;“&lt;STRONG&gt;&lt;EM&gt;Initialize&lt;/EM&gt;&lt;/STRONG&gt;” – a catch-all term to indicate all the steps that must be done to use the TPM with BitLocker or other security applications, including to turn on and take ownership of the TPM.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Tahoma"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Tahoma"&gt;—&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: black; FONT-FAMILY: Tahoma"&gt; &lt;A HREF="/bitlocker/articles/xianke.aspx"&gt;Xian Ke&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=433065" width="1" height="1"&gt;</description></item><item><title>“Is anyone out there?” — Using physical presence to turn on the Trusted Platform Module (TPM)</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/05/12/428173.aspx</link><pubDate>Sat, 13 May 2006 03:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:428173</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=428173</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/05/12/428173.aspx#comments</comments><description>&lt;FONT color=#810081&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;Malicious software can lurk in the most humorous of dancing baby videos and cause havoc on your computer. To help protect against malware taking control of your computer's Trusted Platform Module (TPM) security hardware, computer manufacturers should follow recommendations from the &lt;/FONT&gt;&lt;A title=https://www.trustedcomputinggroup.org/ href="https://www.trustedcomputinggroup.org/"&gt;&lt;FONT face=Verdana size=2&gt;Trusted Computing Group (TCG)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt; to ship TPMs in the "off" state and require users to establish "physical presence" before turning on the TPM for the first time. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;So what exactly does "physical presence" mean? Before Windows Vista appeared on the scene, computer manufacturers fleshed out this ghostly requirement by considering the ability to enter and navigate pre-boot (BIOS) setup menus as proof of physical presence. This approach guards against malware since it's harder to fool us into entering a BIOS setup menu than it is to have us click on a dancing baby video. Unfortunately, finding TPM settings in the BIOS isn't intuitive and in fact, varies widely with each computer model. Not knowing how to help you with this task, Vista's TPM Initialization Wizard would need to display a dialog that says something along the lines of, "Please refer to the BIOS section of your motherboard manual to enable and activate the TPM."&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;I wanted to resolve this dilemma. I felt strongly that understanding the BIOS should not be a prerequisite for using the TPM, and just as strongly that we must have a choice to turn on the TPM or not. With the help of others on the BitLocker team, I collaborated with industry partners to specify an interoperable BIOS firmware interface that simplifies establishing physical presence. With this firmware interface, you can configure the TPM using Vista wizards without knowing about the BIOS. When an action requires physical presence, Vista will set up the BIOS to automatically ask you to confirm your requested change on the next computer restart. As a result, you can quickly use your mere presence to turn on the TPM, but dancing babies cannot (unless, of course, you permit them to do so).&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;For more information on using physical presence to turn on the TPM:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;A title=http://www.microsoft.com/technet/windowsvista/library/29201194-5e2b-46d0-9c77-d17c25c56af3.mspx href="http://www.microsoft.com/technet/windowsvista/library/29201194-5e2b-46d0-9c77-d17c25c56af3.mspx"&gt;&lt;FONT face=Verdana size=2&gt;TPM Step by Step Guide&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;For a related music selection:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;A title=http://www.level42.com/ href="http://www.level42.com/"&gt;&lt;FONT face=Verdana size=2&gt;Level 42&lt;/FONT&gt;&lt;/A&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt; – “Turn It On” from the album &lt;I&gt;&lt;SPAN style="FONT-STYLE: italic"&gt;“A Physical Presence (Live)”&lt;/SPAN&gt;&lt;/I&gt; (1985)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;&lt;SPAN style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: 'Verdana','sans-serif'; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Arial; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;—&lt;/SPAN&gt; &lt;A HREF="/bitlocker/articles/xianke.aspx "&gt;Xian Ke&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face=Verdana color=#000000 size=2&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="FONT-SIZE: 12pt"&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;FONT face=Verdana&gt;P.S. Large enterprise customers that desire no-touch deployment—and who have a controlled deployment environment—can work with their preferred computer manufacturer to purchase computers that do not require an extra touch. For example, having the TPM already on removes the need to establish physical presence during an enterprise BitLocker deployment.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=428173" width="1" height="1"&gt;</description></item><item><title>BitLocker™ Technical Overview — Now Available</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/04/28/426768.aspx</link><pubDate>Sat, 29 Apr 2006 02:58:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:426768</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=426768</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/04/28/426768.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Verdana size=2&gt;It’s been a while since WinHEC 2005, and it was time for a meaningful refresh of our BitLocker docs. In an effort to crystallize the product functionality in one relatively short, yet technical document, I have updated the BitLocker Technical Overview available on &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/windowsvista/security/bittech.mspx"&gt;&lt;FONT face=Verdana size=2&gt;http://www.microsoft.com/technet/windowsvista/security/bittech.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt;. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: blue"&gt;&lt;o:p&gt;&lt;FONT face=Verdana size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt;This document is intended for IT administrators and advanced users to help them understand the different authentication scenarios offered. The document includes the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: blue; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'"&gt;The different requirements for installing BitLocker Drive Encryption&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: blue; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'"&gt;An architectural overview&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: black; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;A section on servers&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: blue; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'"&gt;A section on data volumes&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: blue; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'"&gt;Information about the product’s lifecycle&lt;SPAN style="FONT-SIZE: 10pt; COLOR: navy; FONT-FAMILY: Verdana; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-bidi-font-family: Arial; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;—&lt;/SPAN&gt;from install to retirement&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: black; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000&gt;&lt;FONT size=2&gt;Information about the different authentication scenarios offered (what is TPM-only and what is TPM+StartupKey)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV class=MsoNormal style="MARGIN: 0in 0in 0pt; COLOR: blue; mso-list: l0 level1 lfo1; tab-stops: list .5in"&gt;&lt;FONT face=Verdana&gt;&lt;FONT color=#000000 size=2&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'"&gt;Information&lt;SPAN style="mso-spacerun: yes"&gt; &lt;/SPAN&gt;about the different recovery mechanisms available in case something goes wrong&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;FONT size=2&gt;-- &lt;/FONT&gt;&lt;A HREF="/bitlocker/articles/tureche.aspx"&gt;&lt;FONT size=2&gt;Tony Ureche&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=426768" width="1" height="1"&gt;</description></item><item><title>BitLocker™ and FIPS</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/04/14/apr14fips.aspx</link><pubDate>Sat, 15 Apr 2006 01:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:425303</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/bitlocker/rsscomments.aspx?WeblogPostID=425303</wfw:commentRss><comments>http://blogs.technet.com/b/bitlocker/archive/2006/04/14/apr14fips.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Verdana&gt;Because we have many government customers who will want to run FIPS-compliant software, Microsoft will certify BitLocker™ to the &lt;A href="http://csrc.nist.gov/cryptval/140-2.htm"&gt;FIPS 140-2&lt;/A&gt; standard. This is a long process, but if all goes well we should be in good shape within a few months after shipping.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;The process involves following &lt;A href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf"&gt;specific requirements&lt;/A&gt; to add self-tests (such as integrity checking, known-answer-tests, and so on) to our crypto modules, getting these modules validated by an independent third party, and then getting the actual certification from NIST (the &lt;A href="http://www.nist.gov/"&gt;National Institute of Standards and Technology&lt;/A&gt;) and CSE (&lt;A href="http://www.cse-cst.gc.ca/services/industrial-services/cmv-program-e.html"&gt;Communications Security Establishment&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=Verdana&gt;, NIST’s Canadian equivalent). &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;After several design drill-downs, the BitLocker team determined that we need to implement additional changes beyond self-tests, such as offering choices to opt-in and opt-out of FIPS-compliance through group policy. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;In addition to satisfying government customers’ requirements, another good thing about the validation and certification processes is that it allows an independent set of eyes to look at our crypto algorithms, not only for correct implementation and compliance with the standard, but also for potential weaknesses or avenues of attack.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;-- &lt;A HREF="/bitlocker/articles/tureche.aspx"&gt;Tony Ureche&lt;/A&gt;, Ph.D.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=425303" width="1" height="1"&gt;</description></item><item><title>Welcome</title><link>http://blogs.technet.com/b/bitlocker/archive/2006/04/14/welcome.aspx</link><pubDate>Sat, 15 Apr 2006 00:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:425299</guid><dc:creator>BitLocker Team</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;&lt;FONT face=Verdana&gt;Welcome to the BitLocker™ Drive Encryption Team blog!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;The focus of this blog is to post technical content on a range of topics, but especially how you, our customers, can use BitLocker. Posts will include things like:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;&lt;FONT face=Verdana&gt;
&lt;LI&gt;&lt;FONT face=Verdana&gt;Announcements of new documents, articles or updates&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Verdana&gt;Explanations of key BitLocker concepts&lt;/FONT&gt; 
&lt;LI&gt;BitLocker Tips and tricks&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Verdana&gt;Deployment "gotchas" and how to avoid them&lt;/FONT&gt;&lt;FONT face=Verdana&gt; 
&lt;LI&gt;&lt;FONT face=Verdana&gt;Common issues and lessons learned&lt;/FONT&gt; 
&lt;LI&gt;How-To's&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT face=Verdana&gt;And other things that you tell you'd like to see. To suggest topics, send us an E-mail at &lt;A href="mailto:bdebidea@microsoft.com"&gt;bdebidea@microsoft.com&lt;/A&gt;.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;We plan to update the blog bi-weekly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;Posts are written by team members who work on different areas of the BitLocker feature. BitLocker is part of the System Integrity group in Windows Security. Logistics are managed by &lt;A HREF="/bitlocker/articles/purnag.aspx"&gt;Purna Gathani&lt;/A&gt; and &lt;A href="/bitlocker/articles/bhynes.aspx"&gt;Byron Hynes&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=425299" width="1" height="1"&gt;</description></item></channel></rss>