Welcome to TechNet Blogs Sign in | Join | Help

Secure Your Laptops, Protect Your Data – with Windows Vista BitLocker Drive Encryption.

Hi,

Due to the level of public scrutiny of securing customer data at the moment in Ireland I wanted to reach out and share with you a an easy way to best secure all of your data on Laptops and PCs.

Simon McCourt, our local Security Technology Specialist has written a short article (below) on Windows Vista BitLocker  - which is our out of the box full drive encryption solution that is “best practice” in preventing data falling into the wrong hands, in the event of a computer being lost or stolen. You get BitLocker as a feature of both Windows Vista Enterprise and Windows Vista Ultimate editions.

As ever, if you’ve any further questions or would like additional assistance on this important topic, just drop me an email.

Enjoy the article!

Colm Torris


Secure Your Laptops, Protect Your Data – with Windows Vista BitLocker Drive Encryption

By Simon McCourt

While most organisations will be concerned about the loss of sensitive information, such as intellectual property, company financial data etc., perhaps the greatest concern is the risk to customers’ personal information, which is subject to legal protection under the Data Protection Acts 1988 & 2003. Not only should organisations be acutely mindful of their responsibilities to their customers with respect to personal data, but they should also be keenly aware of the risk to their bottom line; any person suffering damage through the mishandling of their personal information is entitled to claim compensation through the Courts, as outlined in Section 7 of the Data Protection Acts, 1988 and 2003.

In a nutshell, BitLocker is a fully Active Directory-integrated technology that encrypts the entire hard drive, protecting data on lost or stolen machines. It’s even effective in 'offline' attacks, whereby an attacker tries to boot the machine using a non-Windows operating system in an attempt to bypass Windows security. With effective full drive encryption in place, it’s simply not possible to access data without proper authorisation. All that is lost when a computer goes missing is the cost of the hardware itself and the time it takes to get the user in question back up and running. (Assuming an effective data backup/restore process is in place, user impact can be greatly minimised.)

A recent case that achieved high visibility was that of the Northern Ireland Civil Service (NICS).  In response to a number of security incidents in the UK government involving lost and stolen laptops, NICS made a decision to roll out Windows Vista with BitLocker. Microsoft is currently rolling out 4,500 of NICS’ laptops over a three-month project duration, testament to the fact that Windows Vista with BitLocker can be deployed very quickly.

Public references below:

Read the NICS news story

Read the UK government news story

While there are other vendors who have drive encryption offerings, it’s important to highlight the fact that implementing these 'bolt-on' solutions can be a very expensive approach – software costs can be high, not to mention there is significant ongoing management overhead associated with solutions that have to be layered on to Windows. As BitLocker is fully Active Directory-integrated, it is far easier to manage and can be rolled out using Microsoft zero touch deployment technologies, such as System Centre Configuration Manager.

See below for a quick overview of BitLocker. You can also check out a 35 minute video here.


BitLocker Drive Encryption

BitLocker Drive Encryption is an integral security feature of Windows Vista that provides considerable offline protection for data and the operating system. BitLocker helps ensure that data stored on a computer running Windows Vista is not revealed if the computer is tampered with when the installed operating system is offline. It optionally uses a Trusted Platform Module (TPM) to provide enhanced protection for data and to help ensure the integrity of early startup components. This can help protect data from theft or unauthorised viewing by encrypting the entire Windows volume.

Overview of BitLocker Drive Encryption Functionality

BitLocker offers a seamless end-user experience with systems that have a compatible TPM microchip and basic input/output system (BIOS). A compatible TPM is defined as a version 1.2 TPM with the appropriate BIOS required to support the Static Root of Trust Measurement, as defined by the Trusted Computing Group (https://www.trustedcomputinggroup.org). The TPM interacts with BitLocker to help provide seamless protection at system startup.

BitLocker also offers the option to lock the normal startup process until the user supplies a personal identification number (PIN) or inserts a universal serial bus (USB) flash drive that contains a startup key. These additional security measures provide multifactor authentication and higher assurance that the computer will not start or resume from hibernation until the user presents the correct PIN or USB flash drive.

Figure 1 shows a summary of the BitLocker components.

clip_image001[2]

Figure 1. Summary of components in BitLocker

BitLocker enhances data protection by bringing together two major functions: full drive encryption and the integrity checking of early startup components.

Full Drive Encryption

Drive encryption helps mitigate unauthorised data access by unauthorised users from breaking the Windows Vista file and system protection on lost or stolen computers. This protection is achieved through the encryption of the entire Windows Vista volume and any additional volumes on the hard drive. With BitLocker, all user and system files are encrypted, including the system memory paging and hibernation files.

Integrity Check of Early Startup

An offline attack is a scenario in which an attacker starts an alternative operating system to gain control of a computer system. Integrity checking the early startup components helps to ensure that data decryption is performed only if those components appear unmodified and that the encrypted drive is located in the original computer. BitLocker stores measurements of core startup components in the TPM chip. Every time the computer is started, Windows Vista verifies that the startup components have not been modified. If the files have been modified, Windows Vista alerts the user and refuses to release the key required to access the Windows partition. The system then goes into a recovery mode, prompting the user to provide a recovery key to allow access to the startup volume.

The system also uses recovery mode if a disk drive is transferred to another system. Recovery mode requires a recovery key that is generated when BitLocker is enabled, and that key is specific to one computer. As a result, BitLocker is intended for enterprises with a management infrastructure in place to store the recovery keys, such as Active Directory. Otherwise, the potential exists for data loss if a computer enters recovery mode and the recovery key is unavailable.

BitLocker can also be used on computers without a compatible TPM. Using BitLocker in this way provides the volume encryption capabilities but not the added security of integrity validation on early startup files. Instead, a USB flash drive provides the encryption key at startup.

Posted by ieitpro | 0 Comments
Filed under:

Last places on WS08 Powershell Event Dublin April 1-3

Automating Windows Server 2008 Administration with Microsoft Windows PowerShell

 

This three-day instructor-led course provides students with the knowledge and skills to utilize Windows PowerShell for administering and automating administration of Windows Server 2008. The course focuses on cmdlets, script structure and flow control, language syntax, and implementation details of scripting administrative tasks using COM, WMI, and .NET foundations.

 

City

Date

Registration

Location

Cost

Dublin

1 – 3 April 2008

Register Now

Global Knowledge, Millennium Walkway, Dublin 1

€475 per person

 

 

With Microsoft invested subsidies the cost per attendee for this is course is €475 (euro)

Posted by ieitpro | 0 Comments
Filed under: ,

IMTC speaker GROKtalks

Very cool....

 

·         Dave McMahon, who was voted one of the top speakers in TechEd 07 in Barcelona.

·         Gary Short speaking about his favourite patterns and other topics.

·         A snipped from Martin Woodward’s maiden session at TechEd 07 in Barcelona

Posted by ieitpro | 0 Comments
Filed under: ,

Are you in Ireland? IMTC & DDD are coming

Community Events

We are happy to recommend two excellent community events coming up in April and May where you can hear expert speakers on the three launch products and many more Microsoft technologies:

  • The Irish Microsoft Technology Conference 2008 (April 3rd,4th - Dublin) - Now in its third year, the multi-day, multi-track IMTC 2008 features over 40 technolgy-packed sessions for developers and IT Pros. Register online now to experience a host of technical experts including world-renouned speakers from Microsoft developer groups, MVPs and certified partners. The IMTC is one of the largest tech conferences in Ireland and this year each delegate will receive a free DVD containing all the sessions - one not to miss! Fee: 189 euros.
  • Developer Developer Developer Ireland (May 3rd - Galway)  for the first time, the UK's popular day-long DDD event is coming to Ireland. DDD is  focused on .NET development, with many TechEd and DevWeek regulars included in the speaker line-up. This is your chance to get hands-on with the technologies in Galway! This is a free event.

 

 

Posted by ieitpro | 0 Comments

Still undecided on Vista? Virtual Roundtable Event with Mark Russinovitch

 

Still undecided on Windows Vista? View the replay of the recent Springboard Live! Virtual Roundtable at http://technet.microsoft.com/en-us/windowsvista/cc307852.aspx with Mark Russinovich (http://blogs.technet.com/markrussinovich/) - Technical Fellow and desktop guru. The video features Mark and a panel of independent experts in an interactive discussion on adopting Windows Vista into a desktop infrastructure, and what Windows Vista SP1 means for you. Hear about challenges, solutions, workarounds, and tips & tricks from subject-matter experts and IT pros from around the world who have tackled Windows Vista adoption and deployment.

For access to guidance, resources, tools, and straight-talk articles today, visit the Springboard Series (http://www.microsoft.com/technet/springboard) for Windows Vista.

Posted by ieitpro | 0 Comments

Free and easy way to get your users up to speed with Office 2007

 I'll have to admit when I first started using Office 2007 I did find it difficult  to deal with the new ribbon task bars and find the functionality that I had downpat with Office 2003. If you've just deployed Office 2007 and you're getting some resistance from your internal customers to the changes - help is at hand. If you follow the links below, you'll find free of charge plug-ins that create Getting Started Tabs that show end users how to get the best out of the applications using multi-media training, show-me video instruction and an Interactive guide. These are some of the best plug-ins I've seen - try them for yourself.

Word: http://www.microsoft.com/downloads/details.aspx?FamilyId=F587370C-FDAE-4EDE-B528-AC58031A5DFF&displaylang=en

Excel - http://www.microsoft.com/downloads/details.aspx?FamilyId=8A5AF9D7-08A7-41BA-8844-76BB94228957&displaylang=en

Power Point- http://www.microsoft.com/downloads/details.aspx?FamilyId=831F0AE9-FC50-4074-96D3-D02FD98CB041&displaylang=en

 

 

 

 

 

Posted by ieitpro | 0 Comments

Windows Server Launch Event Feedback

Now the dust is settling over the Tripod in Dublin I'd love to hear some verbatims from anyone who attended the event. We had over 2000 through the doors in three sessions - there was a lot of activity in all the sessions. What did you like or didn't like about the event? Did you register for one of the hands-on lab sessions? What did you do with your free server software?

Let me know

Hands on Windows Server 2008

As part of the local Windows Server launch campaign we're going to offer free, full-day instructor lead training sessions on Windows Server. The sessions will take place in Dublin, Belfast and Cork during April. They'll be in the form of hands-on labs so you need to know your way around the technology to get the most out of them. They'll cover

  • Server Management: Windows PowerShell, Server Manager, and Server Core
  • Centralized Application Access: Terminal Services Gateway and Remote Programs
  • Security & Policy Enforcement: Network Access Protection and AD Rights Management Services
  • Web & Applications Platform: IIS 7.0, .NET 3.0, and Windows System Resource Manager

Places are really limited - the sessions are worth a few hundred quid per person! We're doing first come - first serve from the Server Launch event on Tuesday - so if you want to get ahead of the crowd, come to the launch.

Posted by ieitpro | 0 Comments

Green IT?

One of our colleagues Mike Hughes attended an IT@cork event on Green IT this morning to talk about what Microsoft is doing for environmental sustainability both as a company and as a software developer producing products that are safe and energy efficient. There were also presentations from Tom Raftery on how the Cork Internet eXchange (CIX) has been designed to reduce power consumption by as much as possible and James Governor, Industry analyst from Redmonk on what role software can have in environmental sustainability. Attendance was very high and there were a lot of ideas and discussion on how industries could adopt green initiatives ranging from printing on both sides of the page  to sugestions as to how Microsoft might change it's packaging! Presentations from the event will be posted here: http://www.itcork.ie/index.cfm?page=events&eventId=110

To find out what Microsoft is doing on the green front, you can read the brief paper here:  http://www.microsoft.com/About/CorporateCitizenship/US/ResponsibleLeadership/EnvironmentalSustainability.mspx

Co-incidentally, Steve Balmer opened CeBit yesterday with keynote on green IT which is a theme for the show this year....

"Software will make our homes and buildings more intelligent, so we use only the energy we need for lighting, heating, and cooling. It'll enable businesses to redesign products and processes to use less energy and fewer natural resources. High-performance computing will help researchers understand the effects of climate change and mitigate its impacts."

Posted by ieitpro | 0 Comments
Filed under:

Last few remaining places in the Dublin Windows Server 2008, SQL 2008 and VS 2008 launch event

Two of the three sessions are now full - register quickly to claim a place in the last remaining session.

Date: Tuesday, 11th March 2008

Venue: Tripod, Harcourt Street, Dublin 2

Time: There are three sessions to choose from:

12.00-14.00 NOW FULL
15.00-17.00 Register Now!
18.00-20.00 NOW FULL

At the event you will be brought through a 2 hour experience which includes an introduction of the three
products and a tour where you can observe demos and gather information on your specific areas of interest.
The venue will be divided up into various areas covering a broad range of topics across the three products.

Best of all, you will leave with a promotional kit that includes product licences for Windows Server 2008,
Microsoft SQL Server 2008 and Microsoft Visual Studio 2008 .

Visit www.microsoft.ie/launch2008 for further information on community events, new products, local stories on launch and the Launch Experience 2008 – also watch this space for information on launch event in Belfast on
April 8th.

Posted by ieitpro | 0 Comments
Filed under: ,

Quest Active Directory Seminars

Join the Quest field experts in Dublin on 13 March to find out how Quest Active Directory solutions are helping customers from small businesses to enterprises of over 400K users across all sectors secure, automate and manage their AD better than ever before.

With over 7,000 organisations using Quest AD solutions software to protect and manage over 45 million Active Directory accounts, Quest Software is the leader in Active Directory Management worldwide as cited by Forrester Research, Inc.

  • User Management Provisioning and Roles
  • Group Policy Management
  • Password Management & User Self Service
  • Troubleshooting & Recovery
  • Auditing & Reporting
  • Extending AD to non-windows platforms such as Unix and Linux
  • Security enhancement through two-factor methods

To register - visit:-

http://www.quest.com/events/listdetails.aspx?contentid=6796&technology=&prod=&prodfamily=&loc

Posted by ieitpro | 1 Comments
Filed under: ,

TechNet Radio

Stuck in traffic on your commute everyday? I spend a full day on the M50 every week going nowhere fast. There's only so much radio you can listen to! I've tried learning chinese - I've even listened to Wikinomics on audio book. I had a great idea then that if only we could produce technical audio casts that you could listen when you were stuck in traffic - you could keep up to date and get the most out of the commute deadtime! Great idea that unfortunately someone at MS already had before me (forget about the early retirement plans!).

TechNet Radio is a series of audio casts that you can download from the Technet Site -  unlike the audio streams of webcasts, they're designed to be listened to and not viewed so there are no references to PowerPoint slides that you can't see.  In fact most of them take the form of an interview with an expert on whatever the topic is: currently they're running a series on mobility. We're planning to do one or two of these locally so if anyone has any topics they'd like to hear - let me know.

You can check it out for yourself at:-

http://technet.microsoft.com/en-ie/bb510143(en-us).aspx 

Posted by ieitpro | 0 Comments
Filed under:

SQL Server 2008 February CTP Now Released

The feature complete February CTP for SQL Server 2008 is now available for download. This is the first CTP to deliver all the key functionality thta's planned for the final release. Three key areas that we've made big enhancements on are:-

  • Data Compression, which reduces the storage and manageability cost of your database and provides significant performance improvements for workloads such as data warehousing.
  • Enhancements to Policy Based Management, including policy violation alerts, policy import, the ability to run and evaluate multiple simultaneous policies, view the facets and evaluate policies when Object Explorer is connected to Analysis Services and Reporting Services, and more.
  • Integrated Full Text Search, which makes the transition between Full-Text Search and relational data seamless while enabling the use of full-text indexes to perform high-speed text searches on large text columns.

More than 100,000 users have already registered for the community technology programme so if you'd like to join in and try it for yourself visit the link below.

 

http://www.microsoft.com/sql/2008/prodinfo/download.mspx

Posted by ieitpro | 0 Comments
Filed under:

Windows Vista SP1 Now Released for Technet Subscribers

The upcoming Vista SP1 brings enhancements in security, performance and reliability. Since Vista launch, enhancements have been delivered over Windows Update and by the partner community. Today, 10-times more applications have ‘certified’ or ‘works with’ Windows Vista Logos than at launch and there is support for an additional 700K devices – making it the most supported OS ever. Read the WhitePaper and download SP1 update (technet subscribers).

Posted by ieitpro | 0 Comments
Filed under:
More Posts Next page »
 
Page view tracker