-
hi everyone frank westfall here in this
-
video i will show you how to enable and
-
use bitlocker disk encryption with or
-
without a tpm chip and how to use
-
bitlocker to go
-
with windows 10 or windows 11.
-
bitlocker is an application that is
-
built into all microsoft operating
-
systems since windows 7
-
and it allows you to encrypt the
-
contents of your system disk or your
-
system disk and another disk and also
-
encrypt the contents of removable disks
-
like usb flash thumb drives this means
-
that if those disks are ever lost or
-
stolen or the computer itself is ever
-
lost or stolen anyone who has those
-
disks won't be able to read any of the
-
data on it unless they have the
-
encryption key as well and as long as
-
your encryption key isn't with the
-
computer when it's lost or stolen
-
there's no way they can have the
-
encryption key
-
so what that means is that if i lose
-
this laptop or it gets stolen and i have
-
bitlocker disk encryption enabled even
-
if someone pulls the disk out
-
and puts it in another computer
-
they will not be able to read the
-
contents on this disk it is encrypted
-
and if a person doesn't have bitlocker
-
just encryption or some other type of
-
disk encryption enabled and they lose
-
their computer
-
and i happen to find it or anyone who's
-
relatively savvy with computers
-
we'll be able to pull the disc out
-
put it in another computer and instantly
-
access all the data on it anything
-
that's unencrypted is just there for the
-
taking
-
so i highly recommend that if you have
-
sensitive data on a laptop
-
or a removable thumb drive
-
that you encrypt the contents of it
-
the worst thing that can happen is you
-
have sensitive data and then you're not
-
thinking about whether or not the device
-
gets lost or stolen and then it gets
-
lost or stolen and you don't care about
-
the actual laptop you care about the
-
data well with bitlocker disk encryption
-
if that happens you don't have to worry
-
because your data is protected it's not
-
going to be red it's not going to be
-
able to be used you might be out the
-
device you might have lost the laptop or
-
you might have lost a thumb drive but
-
you didn't lose your data for this video
-
you will need any pc computer or laptop
-
a flash thumb drive and it doesn't have
-
to have much storage four gigs or above
-
would be fine and if you're wondering
-
how i'm running windows 11 without a tpm
-
chip because i'm going to show you
-
bitlocker without a tpm chip and with a
-
tpm chip i show how to bypass the new
-
tpm requirements for windows 11
-
in my other video called your pc does
-
not meet minimum requirements how to
-
bypass tpm 2.0 and run windows 11 on
-
older pc
-
the link for that video will be in the
-
description below okay here we go first
-
i'm going to show you how to use
-
bitlocker without a tpm than with a tpm
-
and then also show you how to use
-
bitlocker to go for usb flash drives
-
i'll show you that there's no tpm
-
enabled
-
this computer actually has a tpm chip
-
but i have it disabled in the bios to
-
check your tpm status you can type in
-
tpm.msc
-
in the search run bar
-
and you can see that this computer
-
doesn't think it has a tpm chip because
-
when it's turned off in the bios it
-
doesn't even get powered on it's like
-
the chip doesn't even exist when you
-
turn it off in the bios
-
so we don't have a tpm chip but we're
-
still going to use bitlocker just fine
-
the next thing we want to do is in the
-
search run box type in gp
-
edit
-
dot msc
-
and we want to go to local computer
-
policy
-
administrative templates
-
expand that go to windows components
-
expand that
-
and then go to bitlocker drive
-
encryption and expand that
-
and then operating system drives
-
and then if we slide this over over here
-
require additional authentication at
-
startup double click that
-
turn it to enabled and then check this
-
box if it isn't already checked allow
-
bitlocker without a compatible tpm
-
requires a password or startup key on a
-
usb flash drive
-
we're going to hit ok
-
so now we can use bitlocker without a
-
tpm
-
and we can go to
-
control panel
-
and then
-
bitlocker drive encryption and then we
-
just want to turn on bitlocker
-
and this is where you want to insert
-
your usb drive we're going to need it in
-
a second
-
you can choose
-
to use a usb drive
-
to decrypt the disk
-
before operating system login
-
or you can choose to use a password and
-
i'll show you what it looks like with a
-
password login in a second when we're
-
done with this i'm going to use a
-
password to decrypt the system drive
-
i recommend using a complex password for
-
this
-
and then
-
we're going to save
-
the recovery key
-
onto the flash drive
-
i've already named this one win11
-
bitlock
-
and then hit next
-
and you can choose the first option
-
if you want to do your whole disk it
-
does take longer but that just encrypts
-
the entire disk regardless of whether or
-
not there's data on the disk for the
-
purpose of speed i'm going to do
-
the top option here
-
and i'm going to use the new encryption
-
mode
-
here you want to uncheck this
-
and then hit start encrypting
-
and then you get this notification
-
encryption is in progress encryption of
-
c by bitlocker drive encryption has
-
started when bitlocker disk encryption
-
is running even before it's finished
-
encrypting the entire disk
-
you can shut down and restart the
-
computer it picks up wherever
-
it left off when you shut down the
-
computer if it hasn't finished its
-
encryption process the encryption
-
process is a one-time thing and then
-
after that it's just encrypted this is
-
what logging in looks like
-
after you've enabled bitlocker without a
-
tpm chip you're first asked for a
-
password to decrypt the system disk and
-
then you enter the password to log in
-
and those can be two separate passwords
-
or they could be the same i recommend
-
that they're different so first i'm just
-
going to enter the bitlocker password
-
now the system disk is decrypted
-
and the operating system can load
-
and now i can log into the operating
-
system
-
and i'm in that's what logging in looks
-
like when you use bitlocker without a
-
tpm chip if you use bitlocker with a tpm
-
chip it looks exactly like normal login
-
because the tpm delivers the decryption
-
password as the computer starting up
-
automatically without you even knowing
-
that's happening okay so i've turned my
-
tpm chip on in the system bios and if
-
you're not sure if you have a tpm chip
-
you can go into your bios
-
and go under security
-
and then if you have tpm you'll see tpm
-
security as an option i'm going to turn
-
on my tpm chip now and then show you
-
bitlocker with tpm
-
hit apply
-
and then when you hit apply you get
-
these options
-
i'm going to do
-
tpm acpi support
-
and then you have to hit activate as
-
well and now the tpm chip can be used by
-
the motherboard and by the operating
-
system
-
hit apply and exit that's how you turn
-
tpm on in your bios now i'm going to
-
turn on bitlocker again but this time
-
with the tpm chip first i'm just going
-
to do the tpm.msc
-
command in the search run bar
-
to show the tpm status so here it shows
-
that there is a tpm chip
-
and you can actually also check the
-
firmware version of your tpm chip right
-
here specification version 1.2 this is a
-
tpm chip that is running tpm firmware
-
1.2 can exit out of that
-
and then i'm just going to also show you
-
that
-
the group policy modification
-
has been undone as well
-
so if i go back to that same spot
-
you can see that i've reverted this to
-
not configured then go to control panel
-
and bitlocker drive encryption again
-
turn on bitlocker
-
and we want to
-
save
-
the recovery key
-
to
-
this disk this is the usb disk that i
-
have
-
say yes
-
your recovery key has been saved and
-
it's really important that you save your
-
recovery key and then actually keep it
-
because if you get locked out of your
-
disk and you need to get back in you
-
have to have that encryption key or you
-
will not be able to get that data
-
i've actually had to use my recovery key
-
to get into an encrypted disk before so
-
just keep it in a safe place and then
-
hit next
-
and we're going to use the top option
-
again
-
and then new encryption mode yes
-
and then for this one we can actually do
-
the run bit locker system check what
-
it's going to do is look for a tpm chip
-
and it says okay everything looks good
-
restart now and then the encryption will
-
start okay i've restarted and i'm going
-
to check the status of the bitlocker
-
encryption
-
uh control panel bitlocker drive
-
encryption and you can see that the
-
encryption is in progress right now
-
you'll notice that you're able to shut
-
down and restart the computer and it
-
does not disrupt the process of the
-
encryption you can also turn off
-
bitlocker here very simply by hitting
-
turn off bitlocker
-
and then this will decrypt the disk the
-
disk has been decrypted and now we're
-
back to where we started the last thing
-
i'm going to show you is how to use
-
bitlocker to go which is for use with
-
usb flash thumb drives
-
so maybe you don't want to encrypt your
-
entire system disk inside the computer
-
itself but you want to have
-
some sensitive data encrypted in a flash
-
thumb drive you can use this to do that
-
so i'm going to encrypt this flash thumb
-
drive
-
just turn on bitlocker
-
we're going to use a password to unlock
-
it
-
and then i'm going to save the bitlocker
-
encryption key i'm going to actually
-
just put it on the desktop of this
-
computer i recommend actually putting it
-
on a separate usb drive but for the
-
purpose of this demonstration i'm going
-
to put it just on the desktop of this
-
computer
-
the recovery key has been saved that
-
step is really important you want to
-
make sure that you see your recovery key
-
has been saved
-
and hit next and then we're going to use
-
the top option again
-
and compatible mode has to be used for
-
drives that can be moved from the device
-
hit next and yes we are ready to start
-
encrypting this usb drive
-
now i'm going to remove this drive and
-
then plug it back in so you can see what
-
it looks like when you plug the drive in
-
so go to eject media
-
safe to remove
-
pull it out
-
and then put it back in
-
bitlocker drive encryption unlock drive
-
d the drive is bitlocker protected
-
enter the password
-
and now the drive has been unlocked
-
and
-
we can access the data on it
-
there isn't any data on this it's just
-
the recovery keys from the
-
testing of bitlocker that i did before
-
the video and then also the recovery
-
keys that we created during this video
-
and i also want to show you real quick
-
what it looks like if you have the usb
-
disk in and you haven't entered the
-
bitlocker decryption key so this is what
-
it would be like for someone that found
-
your usb disk but they don't have the
-
bitlocker password to decrypt the drive
-
they plug it in their computer they go
-
to access it and
-
they're not getting in
-
even if they loaded this up on a linux
-
system or some other type of computer
-
and then they can actually open it
-
the actual data in it is encrypted so
-
it's just a bunch of gibberish it
-
doesn't make any sense you can also
-
decrypt the usb drive the same way that
-
you decrypted the system drive
-
i just did a decryption of the usb drive
-
so it's just back to a normal usb drive
-
all you have to do is hit the turn off
-
bitlocker under
-
bitlocker to go and then select the
-
drive and then hit turn off bitlocker
-
all right that's it i hope this
-
information was helpful please subscribe
-
to my channel for more computer
-
tutorials videos and please check out
-
the ones i already have i'm building a
-
large library of computer tutorial
-
videos thank you for watching bye