BitLocker Encryption for Windows Clients

BitLocker encrypts the hard drives on a Windows computer, and is an integral part of Windows.

Check Point BitLocker uses the Endpoint Security Management Server, Client Agent and the Endpoint Security UI to manage BitLocker.

BitLocker Management is implemented as a Windows service component called Check Point BitLocker Management.

It runs on the client together with the Client Agent (the Device Agent).

Check Point BitLocker Management uses APIs provided by Microsoft Windows to control and manage BitLocker.

Configuration options:

Setting Description
Initial Encryption
  • Encrypt entire drive - Recommended for computers that are in production and already have user data, such as documents and emails.
  • Encrypt used disk space only - Encrypts only the data. Recommended for fresh Windows installations.
Drives to encrypt
  • All drives - Encrypt all drives and volumes.
  • OS drive only - Encrypt only the OS drive (usually, C:\). This is the default.
Encryption algorithm
  • Windows Default - This is recommended. On Windows 10 or later, unencrypted disks are encrypted with XTS-AES-128. On encrypted disks, the encryption algorithm is not changed.
  • XTS-AES-128
  • XTS-AES-256
Note:

To take control of a BitLocker-encrypted device, the target device must have a Trusted Platform Module (TPM) module installed.

Taking Control of Unmanaged BitLocker Computers

You can do a takeover of BitLocker-encrypted computers that are not managed by SmartEndpoint, and make them centrally managed. You can do this using either BitLocker Management or Check Point Full Disk Encryption.

Taking control of unmanaged BitLocker computers using BitLocker Management

Define and install a Full Disk Encryption policy with BitLocker Management. Follow the procedure in Configuring a BitLocker Encryption Policy with these guidelines:

  • Define a Full Disk Encryption rule that Applies To either the Entire Organization or only to the entities that need BitLocker Management.

  • In the properties of the Use BitLocker Management action, select Windows Default as the Encryption algorithm.

    This is important because it leaves the existing BitLocker encryption algorithm in place. Selecting another algorithm explicitly may result in a re-encryption if the existing algorithm does not match the algorithm in the policy. It is a good idea to avoid re-encryption because it can take a long time. The time it takes depends on the disk size, disk speed and PC hardware.

Taking control of unmanaged BitLocker computers using Check Point Full Disk Encryption

  1. Follow the procedure for taking control of unmanaged BitLocker computers using BitLocker Management.

  2. After the computers are under BitLocker Management, define a rule with Check Point Full Disk Encryption that Applies To either the Entire Organization or only to the entities that need Check Point Full Disk Encryption. Follow the procedure in Configuring a BitLocker Encryption Policy.

Important:

When you change the encryption policy for clients from BitLocker Management to Check Point Full Disk Encryption, the disk on the client is decrypted and then encrypted. This causes the disk to be in an unencrypted state for some time during the process. We recommend that you do not change the encryption policy for entire organization in one operation. Make the change for one group of users at a time.