Windows Bitlocker - Two/Multiple drives with TPM
I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.
I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.
Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.
Thanks
hard-drive ssd windows-10 encryption bitlocker
|
show 2 more comments
I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.
I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.
Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.
Thanks
hard-drive ssd windows-10 encryption bitlocker
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36
|
show 2 more comments
I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.
I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.
Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.
Thanks
hard-drive ssd windows-10 encryption bitlocker
I have a Windows 10 laptop with two drives: an HDD that I use to store my data, and an SSD where the OS is stored allong with programs I use more frequently/require more performance.
I use Bitlocker to secure my data, and have both drives encrypted. My laptop has a TPM chip. What happens is that one of the drives (data drive) is automatically unlocked when I sign in, but the system asks me for a password on bootup to unlock the OS drive.
Is there any way to have both drives unlock automatically on sign in with the keys stored in the TPM chip? No options for auto-unlock appear under the OS drive in windows.
Thanks
hard-drive ssd windows-10 encryption bitlocker
hard-drive ssd windows-10 encryption bitlocker
asked Sep 25 '15 at 9:57
John BlackberryJohn Blackberry
12126
12126
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36
|
show 2 more comments
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36
|
show 2 more comments
1 Answer
1
active
oldest
votes
Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.
Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.
Use of just the USB key means you'll have to have the USB key plugged in when you boot.
Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.
The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.
See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.
add a comment |
Your Answer
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f978000%2fwindows-bitlocker-two-multiple-drives-with-tpm%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.
Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.
Use of just the USB key means you'll have to have the USB key plugged in when you boot.
Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.
The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.
See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.
add a comment |
Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.
Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.
Use of just the USB key means you'll have to have the USB key plugged in when you boot.
Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.
The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.
See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.
add a comment |
Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.
Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.
Use of just the USB key means you'll have to have the USB key plugged in when you boot.
Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.
The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.
See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.
Yes, you can have your OS drive automatically boot from a bitlocker'd drive without prompting for a passowrd. Mine works that way. But it requires either an activated TPM, or a bitlocker password on a USB key, or both.
Use of just the TPM means that if someone steals your drive, they can't read it - but if they steal your computer, and manage to log in, they can.
Use of just the USB key means you'll have to have the USB key plugged in when you boot.
Optinally you can use TPM + PIN, or TPM + USB. Like "just TPM" both of these lock the drive to the computer, and protect the boot environment from changes, via the TPM. They add either "something you know" (PIN) or "something you have" (USB key) to the need for the TPM.
The recovery key, in case you were wondering, bypasses the need to match the TPM... useful if you change the boot environment (while leaving BL enabled) or need to access the drive from another machine.
See "What is a BitLocker Drive Encryption startup key or PIN?" at microsoft.com , and "How to configure BitLocker with TPM, PIN, and USB StartupKey" at mrhorn.com for the detailed procedures.
edited Sep 25 '15 at 19:53
answered Sep 25 '15 at 11:05
Jamie HanrahanJamie Hanrahan
18.7k34279
18.7k34279
add a comment |
add a comment |
Thanks for contributing an answer to Super User!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f978000%2fwindows-bitlocker-two-multiple-drives-with-tpm%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Your question doesn't make sense. Aren't both drives already unlocked when you sign in?
– David Schwartz
Sep 25 '15 at 10:16
I have a similar setup and followed this instructions, which worked. technet.microsoft.com/en-us/library/…
– KarmaEDV
Sep 25 '15 at 10:46
No; There is no way to automatically log into your FDE system disk. The reason your other disk can be automatically mounted is because it isn't your system disk, your user profile by the way, is storing that information. What you describe would break your security. Anyone with physical access to your device now, would be unable to access either disk, likewise if t automatically enter the password they would be able to grab everything like it wasn't even encrypted in the first place.
– Ramhound
Sep 25 '15 at 10:53
@KarmaEDV, that applies to "You can configure BitLocker to automatically unlock volumes that do not host an operating system." Not to the OS volume.
– Jamie Hanrahan
Sep 25 '15 at 11:07
@JamieHanrahan Yes, but I too have a multiple BitLocker drives and never have to enter a password.
– KarmaEDV
Sep 25 '15 at 11:36