Windows Server 2016 and 2012 R2 – Setup and Manage Bitlocker (With and Without TPM) VIDEO TUTORIAL

Windows Server 2016 and 2012 R2 - Setup and Manage Bitlocker (With and Without TPM) VIDEO TUTORIAL

  Having full system and drive encryption is an important part of an organization when it comes to protecting their data and computer security. Even in some parts of the world such is a legal requirment. So, this video shows how to setup Bitlocker Drive Encryption in server 2016 and it is also valid for 2012 R2. This video shows the PowerShell way and also talks about the control panel method.

Please watch the video to see the above (to translate, click the Subtitle box in the YouTube video and then click Settings and language, as in this picture):

subtitles

 
Transcript (machine generated so it contains errors)
1. 00:00:00:50 / 00:00:07:20 - hi in this video let's have a quick look
2. 00:00:04:08 / 00:00:12:46 - at how to set up BitLocker on Windows
3. 00:00:07:20 / 00:00:16:55 - Server 2016 or in Windows Server 2012 r2
4. 00:00:12:46 / 00:00:20:51 - etc the first thing is are we doing it
5. 00:00:16:55 / 00:00:22:97 - the TPM method which is the trusted
6. 00:00:20:51 / 00:00:26:18 - platform module is a chip on your
7. 00:00:22:98 / 00:00:30:86 - motherboard that will basically store
8. 00:00:26:18 / 00:00:35:07 - passwords etc or are we doing it without
9. 00:00:30:86 / 00:00:38:85 - it so we need to check to see if we have
10. 00:00:35:07 / 00:00:43:89 - the TPM to start off with okay let's go
11. 00:00:38:85 / 00:00:46:10 - there just type in TP m dot MSC click on
12. 00:00:43:89 / 00:00:48:82 - that that brings up this ok
13. 00:00:46:10 / 00:00:54:57 - if basically this is empty and it says
14. 00:00:48:82 / 00:00:56:85 - there's no TPM fine ok if the TPM is
15. 00:00:54:57 / 00:00:59:96 - there but it has not been prepared and
16. 00:00:56:85 / 00:01:02:55 - kind of like set up click on repair TPM
17. 00:00:59:96 / 00:01:05:51 - it will restart and then ask you to kind
18. 00:01:02:54 / 00:01:07:50 - of like I'm except that the TPM will be
19. 00:01:05:51 / 00:01:10:53 - initialized and press I think it's the
20. 00:01:07:50 / 00:01:13:40 - f10 button press f10 it reboots and then
21. 00:01:10:53 / 00:01:17:43 - it comes up and then it shows this ok a
22. 00:01:13:40 / 00:01:20:39 - password is created for your TPM where
23. 00:01:17:43 / 00:01:22:79 - you can back it up ok you do get a first
24. 00:01:20:39 / 00:01:25:10 - um
25. 00:01:22:79 / 00:01:28:25 - message when you first boot up after
26. 00:01:25:10 / 00:01:32:40 - setting up the TPM and you can also
27. 00:01:28:25 / 00:01:37:61 - basically shall we say store it again
28. 00:01:32:40 / 00:01:40:86 - ok alright or change passwords etc ok
29. 00:01:37:61 / 00:01:44:93 - clear the TPM reset TPM all these things
30. 00:01:40:85 / 00:01:47:60 - can be done ok let's turn that off now
31. 00:01:44:93 / 00:01:50:06 - so we're using the TPM in this instance
32. 00:01:47:60 / 00:01:53:72 - the next thing is to basically go to
33. 00:01:50:06 / 00:01:56:87 - server manager which is right over there
34. 00:01:53:72 / 00:02:00:64 - click server manager comes up will
35. 00:01:56:87 / 00:02:08:12 - enlarge it add roles and features next
36. 00:02:00:64 / 00:02:11:58 - next next it's a feature and it's
37. 00:02:08:12 / 00:02:13:76 - BitLocker Drive Encryption ok
38. 00:02:11:58 / 00:02:17:52 - had these features you will need to
39. 00:02:13:77 / 00:02:18:99 - restart so make sure that when you're
40. 00:02:17:52 / 00:02:21:99 - doing this you're not running any
41. 00:02:18:99 / 00:02:24:84 - mission-critical applications services
42. 00:02:21:99 / 00:02:27:93 - etc in the background that need to be on
43. 00:02:24:84 / 00:02:30:84 - ok all right we're gonna click this now
44. 00:02:27:93 / 00:02:34:31 - so that it restarts at the end of this
45. 00:02:30:84 / 00:02:37:40 - very quickly it'll take a few minutes to
46. 00:02:34:31 / 00:02:40:19 - set it up and then reboot we we should
47. 00:02:37:40 / 00:02:43:56 - return to it in a few minutes
48. 00:02:40:19 / 00:02:47:15 - now we're gonna basically show you how
49. 00:02:43:56 / 00:02:50:34 - to do it basically how to can I come
50. 00:02:47:15 / 00:02:52:94 - let's turn on BitLocker we've and they
51. 00:02:50:34 / 00:02:55:28 - we've installed BitLocker okay the
52. 00:02:52:94 / 00:02:57:20 - feature now will give you the two
53. 00:02:55:28 / 00:03:01:04 - options one let's assume you don't have
54. 00:02:57:21 / 00:03:04:76 - the TPM chip okay basically you need to
55. 00:03:01:05 / 00:03:10:35 - go to group policy okay which is
56. 00:03:04:75 / 00:03:13:10 - gpedit.msc okay click on that it will
57. 00:03:10:34 / 00:03:16:65 - bring up this window and then you need
58. 00:03:13:11 / 00:03:18:81 - to go all the way to basically computer
59. 00:03:16:65 / 00:03:22:05 - configuration administrative templates
60. 00:03:18:81 / 00:03:25:17 - windows components BitLocker Drive
61. 00:03:22:05 / 00:03:27:57 - Encryption operating system drives and
62. 00:03:25:16 / 00:03:32:51 - then require additional authentication
63. 00:03:27:56 / 00:03:34:70 - at set up now when you click enabled if
64. 00:03:32:52 / 00:03:37:89 - you don't have a TPM chip make sure that
65. 00:03:34:70 / 00:03:42:93 - one is ticked okay everything else is
66. 00:03:37:88 / 00:03:47:06 - fine and then you click OK restart your
67. 00:03:42:93 / 00:03:50:52 - computer and then you need to run some
68. 00:03:47:06 / 00:03:54:23 - commands we've got a TPM chip on this so
69. 00:03:50:52 / 00:03:57:23 - we won't enable the sync group policy
70. 00:03:54:23 / 00:03:58:64 - but we will show you what needs to be
71. 00:03:57:23 / 00:04:02:25 - done okay
72. 00:03:58:63 / 00:04:06:23 - you open up Windows PowerShell okay make
73. 00:04:02:25 / 00:04:12:50 - sure it's run as admin okay and type in
74. 00:04:06:23 / 00:04:15:39 - manage - be de space - protectors - add
75. 00:04:12:50 / 00:04:18:50 - C ok so that's for the C Drive and then
76. 00:04:15:38 / 00:04:22:97 - the startup key we're saving it -
77. 00:04:18:50 / 00:04:24:31 - basically we have a USB stick ok which
78. 00:04:22:97 / 00:04:29:41 - is the
79. 00:04:24:31 / 00:04:33:63 - okay press Enter okay and then you will
80. 00:04:29:42 / 00:04:36:14 - need to restart your computer okay and
81. 00:04:33:63 / 00:04:38:93 - when it restarts is check to see that
82. 00:04:36:13 / 00:04:41:89 - the key your USB stick is installed and
83. 00:04:38:93 / 00:04:44:15 - that the key is all functional and then
84. 00:04:41:89 / 00:04:47:53 - when it boots up it'll start encrypting
85. 00:04:44:14 / 00:04:52:39 - your drive okay okay
86. 00:04:47:54 / 00:04:56:18 - now let's assume you have a TPM chip all
87. 00:04:52:39 / 00:05:00:45 - you really need to do is type in manage
88. 00:04:56:18 / 00:05:08:38 - BD and then turn it on for the C Drive
89. 00:05:00:45 / 00:05:11:47 - okay and that's that okay there we go
90. 00:05:08:38 / 00:05:15:22 - so basically it now requires a restart
91. 00:05:11:48 / 00:05:17:59 - okay and once the restart happens it
92. 00:05:15:23 / 00:05:21:86 - will check to see whether our TPM is
93. 00:05:17:58 / 00:05:24:40 - functioning with the key etc and it can
94. 00:05:21:86 / 00:05:31:49 - be used and it'll start okay so we'll
95. 00:05:24:41 / 00:05:34:93 - just click on restart now okay and when
96. 00:05:31:49 / 00:05:36:76 - it restarts you will see this little
97. 00:05:34:93 / 00:05:40:45 - thing over here which says encryption of
98. 00:05:36:76 / 00:05:48:85 - C draw Eve by BitLocker is in progress
99. 00:05:40:45 / 00:05:52:06 - if you go over there and let's just
100. 00:05:48:86 / 00:05:54:05 - click on this PC okay you will see you
101. 00:05:52:06 / 00:05:56:00 - now have this little lock there once
102. 00:05:54:05 / 00:05:59:07 - it's fully encrypted everything gets
103. 00:05:56:00 / 00:06:06:07 - locked down okay
104. 00:05:59:07 / 00:06:13:57 - and you should be able to do it in
105. 00:06:06:07 / 00:06:17:65 - control panel in 2012 r2 2016 in its
106. 00:06:13:57 / 00:06:20:00 - current version hasn't quite sorted loud
107. 00:06:17:66 / 00:06:22:82 - yet but basically what you would have
108. 00:06:20:00 / 00:06:23:80 - been able to do was hit Locker just type
109. 00:06:22:81 / 00:06:29:14 - over there
110. 00:06:23:80 / 00:06:35:81 - okay and it would have gone to a control
111. 00:06:29:14 / 00:06:39:37 - panel option okay taking us to control
112. 00:06:35:81 / 00:06:39:37 - panel there we go
113. 00:06:40:87 / 00:06:48:80 - over there all control panel items and
114. 00:06:44:86 / 00:06:52:80 - you should see somewhere over here
115. 00:06:48:80 / 00:06:56:49 - BitLocker okay it's not quite set up in
116. 00:06:52:80 / 00:06:58:31 - Windows Server 2016 yet but once it is
117. 00:06:56:49 / 00:07:00:86 - it's fairly straightforward it's a
118. 00:06:58:31 / 00:07:04:05 - window with all the drive displayed and
119. 00:07:00:86 / 00:07:09:99 - then you can turn off pause etc on the
120. 00:07:04:05 / 00:07:14:21 - drive okay so we're using PowerShell
121. 00:07:09:99 / 00:07:19:13 - which is great enough okay okay
122. 00:07:14:21 / 00:07:25:49 - and I'll just check the status so it's
123. 00:07:19:13 / 00:07:29:26 - again managed BD - status okay and this
124. 00:07:25:49 / 00:07:30:62 - is basically telling us at this point
125. 00:07:29:26 / 00:07:35:06 - okay
126. 00:07:30:62 / 00:07:39:77 - encryption is in progress is done 0.3
127. 00:07:35:06 / 00:07:42:55 - percent okay once it's all sorted out it
128. 00:07:39:77 / 00:07:46:13 - will say encrypted hundred percent
129. 00:07:42:55 / 00:07:48:44 - protection status protection is on key
130. 00:07:46:13 / 00:07:51:20 - protectors as it states over here it's
131. 00:07:48:44 / 00:07:52:74 - on the TPM if we had followed the
132. 00:07:51:20 / 00:07:54:56 - previous command
133. 00:07:52:74 / 00:07:56:96 - it would have been saved to the USB
134. 00:07:54:56 / 00:08:03:99 - stick and the key protectors would have
135. 00:07:56:96 / 00:08:09:99 - been mentioned as there okay now if we
136. 00:08:03:99 / 00:08:16:12 - want to shall we say turn it off on C
137. 00:08:09:99 / 00:08:21:68 - Drive it's as simple as this manage - PD
138. 00:08:16:12 / 00:08:23:75 - - off and C Drive click that decryption
139. 00:08:21:68 / 00:08:28:74 - is now in progress so basically it's now
140. 00:08:23:75 / 00:08:34:46 - an encrypting or decrypting my hard disk
141. 00:08:28:74 / 00:08:38:31 - ok and at the same time you can use the
142. 00:08:34:46 / 00:08:41:76 - technique to manage BD on and that if
143. 00:08:38:30 / 00:08:45:59 - you want to do it for your D Drive e
144. 00:08:41:75 / 00:08:47:48 - Drive F Drive whatever you know let's
145. 00:08:45:60 / 00:08:55:00 - look at the status
146. 00:08:47:48 / 00:08:58:22 - okay okay okay decryption in progress
147. 00:08:55:00 / 00:09:02:68 - it'll take some time once it's back
148. 00:08:58:22 / 00:09:05:87 - there everything is fine so in this
149. 00:09:02:69 / 00:09:10:49 - video we've showed you how to set up
150. 00:09:05:87 / 00:09:16:65 - your TPM okay get your TPM running we've
151. 00:09:10:49 / 00:09:20:21 - also showed you how to install the
152. 00:09:16:65 / 00:09:23:83 - BitLocker feature have the computer
153. 00:09:20:21 / 00:09:28:49 - restart okay after it's been restarted
154. 00:09:23:84 / 00:09:32:30 - um we've also shown how to basically use
155. 00:09:28:49 / 00:09:34:51 - either USB key for the protectors or use
156. 00:09:32:29 / 00:09:38:99 - your TPM chip for the protectors and
157. 00:09:34:51 / 00:09:43:78 - then how to turn on BitLocker Drive
158. 00:09:38:99 / 00:09:47:50 - Encryption and also turn it off okay if
159. 00:09:43:78 / 00:09:51:31 - at any point you have any questions or
160. 00:09:47:50 / 00:09:54:34 - queries regarding this you can just type
161. 00:09:51:32 / 00:09:57:26 - that and it gives you all the different
162. 00:09:54:34 / 00:09:58:63 - options that you can use with that
163. 00:09:57:25 / 00:10:01:39 - managed BDE
164. 00:09:58:63 / 00:10:02:53 - for example you can pause you can lock
165. 00:10:01:39 / 00:10:07:25 - okay
166. 00:10:02:53 / 00:10:09:98 - you can unlock encrypted data and you
167. 00:10:07:25 / 00:10:13:39 - can also do a lot lot more change the
168. 00:10:09:98 / 00:10:16:57 - passwords etc okay so the PowerShell
169. 00:10:13:39 / 00:10:20:32 - version is very very strong very nice
170. 00:10:16:57 / 00:10:22:76 - the GUI version in control panel is also
171. 00:10:20:33 / 00:10:27:47 - quite nice it just hasn't quite reached
172. 00:10:22:75 / 00:10:30:91 - Server 2016 yet but in 2012 it's
173. 00:10:27:47 / 00:10:34:89 - functioning fully okay hopefully this
174. 00:10:30:91 / 00:10:34:89 - video has helped thank you for watching
Visit our YouTube channel: https://www.youtube.com/channel/UCFj1BHYIUYfPWPb1Xn5qFIg