BitLocker Encryption for Windows Clients
BitLocker encrypts the hard drives on a Windows computer, and is an integral part of Windows.
Check Point BitLocker uses the Endpoint Security Management Server, Client Agent and the Endpoint Security UI to manage BitLocker.
BitLocker Management is implemented as a Windows service component called Check Point BitLocker Management.
It runs on the client together with the Client Agent (the Device Agent).
Check Point BitLocker Management uses APIs provided by Microsoft Windows to control and manage BitLocker.
Configuration options:
| Setting | Description |
|---|---|
| Initial Encryption |
|
| Drives to encrypt |
|
| Encryption algorithm |
|
To take control of a BitLocker-encrypted device, the target device must have a Trusted Platform Module (TPM) module installed.
Taking Control of Unmanaged BitLocker Computers
You can do a takeover of BitLocker-encrypted computers that are not managed by SmartEndpoint, and make them centrally managed. You can do this using either BitLocker Management or Check Point Full Disk Encryption.
Taking control of unmanaged BitLocker computers using BitLocker Management
Define and install a Full Disk Encryption policy with BitLocker Management. Follow the procedure in Configuring a BitLocker Encryption Policy with these guidelines:
-
Define a Full Disk Encryption rule that Applies To either the Entire Organization or only to the entities that need BitLocker Management.
-
In the properties of the Use BitLocker Management action, select Windows Default as the Encryption algorithm.
This is important because it leaves the existing BitLocker encryption algorithm in place. Selecting another algorithm explicitly may result in a re-encryption if the existing algorithm does not match the algorithm in the policy. It is a good idea to avoid re-encryption because it can take a long time. The time it takes depends on the disk size, disk speed and PC hardware.
Taking control of unmanaged BitLocker computers using Check Point Full Disk Encryption
-
Follow the procedure for taking control of unmanaged BitLocker computers using BitLocker Management.
-
After the computers are under BitLocker Management, define a rule with Check Point Full Disk Encryption that Applies To either the Entire Organization or only to the entities that need Check Point Full Disk Encryption. Follow the procedure in Configuring a BitLocker Encryption Policy.
When you change the encryption policy for clients from BitLocker Management to Check Point Full Disk Encryption, the disk on the client is decrypted and then encrypted. This causes the disk to be in an unencrypted state for some time during the process. We recommend that you do not change the encryption policy for entire organization in one operation. Make the change for one group of users at a time.