Windows Bitlocker - Two/Multiple drives with TPM












0















I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.



I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.



Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.



Thanks















share|improve this question























  • Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

    – David Schwartz
    Sep 25 '15 at 10:16











  • I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

    – KarmaEDV
    Sep 25 '15 at 10:46











  • No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

    – Ramhound
    Sep 25 '15 at 10:53











  • @KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

    – Jamie Hanrahan
    Sep 25 '15 at 11:07











  • @JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

    – KarmaEDV
    Sep 25 '15 at 11:36
















0















I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.



I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.



Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.



Thanks















share|improve this question























  • Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

    – David Schwartz
    Sep 25 '15 at 10:16











  • I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

    – KarmaEDV
    Sep 25 '15 at 10:46











  • No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

    – Ramhound
    Sep 25 '15 at 10:53











  • @KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

    – Jamie Hanrahan
    Sep 25 '15 at 11:07











  • @JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

    – KarmaEDV
    Sep 25 '15 at 11:36














0












0








0








I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.



I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.



Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.



Thanks















share|improve this question














I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.



I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.



Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.



Thanks












hard-drive ssd windows-10 encryption bitlocker






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Sep 25 '15 at 9:57









John BlackberryJohn Blackberry

12126




12126













  • Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

    – David Schwartz
    Sep 25 '15 at 10:16











  • I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

    – KarmaEDV
    Sep 25 '15 at 10:46











  • No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

    – Ramhound
    Sep 25 '15 at 10:53











  • @KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

    – Jamie Hanrahan
    Sep 25 '15 at 11:07











  • @JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

    – KarmaEDV
    Sep 25 '15 at 11:36



















  • Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

    – David Schwartz
    Sep 25 '15 at 10:16











  • I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

    – KarmaEDV
    Sep 25 '15 at 10:46











  • No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

    – Ramhound
    Sep 25 '15 at 10:53











  • @KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

    – Jamie Hanrahan
    Sep 25 '15 at 11:07











  • @JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

    – KarmaEDV
    Sep 25 '15 at 11:36

















Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

– David Schwartz
Sep 25 '15 at 10:16





Your question doesn't make sense. Aren't both drives already unlocked when you sign in?

– David Schwartz
Sep 25 '15 at 10:16













I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

– KarmaEDV
Sep 25 '15 at 10:46





I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…

– KarmaEDV
Sep 25 '15 at 10:46













No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

– Ramhound
Sep 25 '15 at 10:53





No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.

– Ramhound
Sep 25 '15 at 10:53













@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

– Jamie Hanrahan
Sep 25 '15 at 11:07





@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.

– Jamie Hanrahan
Sep 25 '15 at 11:07













@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

– KarmaEDV
Sep 25 '15 at 11:36





@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.

– KarmaEDV
Sep 25 '15 at 11:36










1 Answer
1






active

oldest

votes


















0














Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.



Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.



Use of just the USB key means you'll have to have the USB key plugged in when you boot.



Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.



The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.



See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.






share|improve this answer

























    Your Answer








    StackExchange.ready(function() {
    var channelOptions = {
    tags: "".split(" "),
    id: "3"
    };
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function() {
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled) {
    StackExchange.using("snippets", function() {
    createEditor();
    });
    }
    else {
    createEditor();
    }
    });

    function createEditor() {
    StackExchange.prepareEditor({
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader: {
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    },
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    });


    }
    });














    draft saved

    draft discarded


















    StackExchange.ready(
    function () {
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f978000%2fwindows-bitlocker-two-multiple-drives-with-tpm%23new-answer', 'question_page');
    }
    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.



    Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.



    Use of just the USB key means you'll have to have the USB key plugged in when you boot.



    Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.



    The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.



    See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.






    share|improve this answer






























      0














      Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.



      Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.



      Use of just the USB key means you'll have to have the USB key plugged in when you boot.



      Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.



      The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.



      See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.






      share|improve this answer




























        0












        0








        0







        Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.



        Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.



        Use of just the USB key means you'll have to have the USB key plugged in when you boot.



        Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.



        The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.



        See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.






        share|improve this answer















        Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.



        Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.



        Use of just the USB key means you'll have to have the USB key plugged in when you boot.



        Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.



        The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.



        See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Sep 25 '15 at 19:53

























        answered Sep 25 '15 at 11:05









        Jamie HanrahanJamie Hanrahan

        18.7k34279




        18.7k34279






























            draft saved

            draft discarded




















































            Thanks for contributing an answer to Super User!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid



            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.


            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f978000%2fwindows-bitlocker-two-multiple-drives-with-tpm%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Сан-Квентин

            8-я гвардейская общевойсковая армия

            Алькесар