Bitlocker on shared external drives???
Been searching for a while across the net and only come up with a couple of snippets of information, but no detailed descriptions. We're likely going to be moving to Bitlocker as a standard for all Consultants in the field. We also provide external HD's for use as backups, runind VHD's, sharing information, etc. We know our Consultants will have the need to share HD's between computers. The question is, can we protect the HD's with Bitlocker and still share them between Consultants? My understanding is that it *may* be possible, but that it would require (arguably) mounting the drive using the Bitlocker management console each and every time, due to the different TPM. Theoretically, this could extend to flash drives as well. EFS has been discussed, but some have expressed concern due to poor experiences in the past. Any thoughts?
August 8th, 2008 6:22pm

With my understanding, BitLocker protection is virtually transparent to the user in day-to-day use. And I didn't have the experience that Bitlocker preventing sharing information. Ageneral suggestion, I think you should set up a test environment before you deploying Bitlocker to all computers. Thanks.
Free Windows Admin Tool Kit Click here and download it now
August 11th, 2008 1:35pm

Thanks. We're definitely going to do our homework and test this thoroughly prior to deployment. Unfortunatley, your response doesn't completely answer my question. I'm not concerned about sharing of information, I'm interested in the idea of physically sharing a USB drive (not via windows shares). From what little inforomation I have found, which isn't much, the drive would be tied to the TPM of the computer applying BitLocker. Once moved to another computer, with a different TPM, will the user be able to see the data, or will he/she have to use the Bitlocker console to, essentially, associate the drive with the new TPM?
August 11th, 2008 10:18pm

Hi, BitLocker is designed to encrypt the entire drive, including the Windows system files necessary for startup and logon. I'm afraid it's not a good idea to use it on a USB drive that need to work on different computers. For your purpose, I think Encrypting File System (EFS) should be a better choice. Thanks.
Free Windows Admin Tool Kit Click here and download it now
August 13th, 2008 1:32pm

thx
August 13th, 2008 5:21pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics