Link to home
Start Free TrialLog in
Avatar of CES
CES

asked on

Remove BitLocker Startup key once OS is booted?

Hello All,

We are toying with implementing BitLocker on all workstations via GPO.  As usual, our wild is a couple of MacBooks that run Windows via BootCamp. Apple does not install a TPM chip on their systems, so if we were to encrypt these Windows installations, the users would need to have a USB drive connected at boot that contains the decryption key.

Does anyone know if this USB drive needs to remain connected at all times? or can it be removed once the operating system has loaded?
Avatar of Shaun Vermaak
Shaun Vermaak
Flag of Australia image

the users would need to have a USB drive connected at boot that contains the decryption key.
No, you can just use a startup key and backup the key file for future recovery
Avatar of CES
CES

ASKER

Right but that startup key on a non-TPM computer must be on a flash drive:

https://technet.microsoft.com/en-us/library/hh831507(v=ws.11).aspx

So does that flash drive need to remain connected after startup?  Or can i remove it once Windows is booted in order to free up the USB port?
It boots without the USB and you use it without USB. You only need key when recovery is triggered
ASKER CERTIFIED SOLUTION
Avatar of Shaun Vermaak
Shaun Vermaak
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of CES

ASKER

That's a great link.  Thanks for that!