Disabling Bitlocker: Difference between revisions

From RHLUG Wiki
Jump to navigation Jump to search
added more instructions
Improve formatting
 
Line 1: Line 1:
In order to dual-boot Linux on a RHIT laptop, it is recommended to disable BitLocker (and Secure Boot). To do so on a RHIT Laptop, perform the following steps.
In order to dual-boot Linux on a RHIT laptop, it is recommended to disable BitLocker (and Secure Boot). To do so on a RHIT Laptop, perform the following steps.


1. Get your BitLocker recovery key in case any issues arise. To do so, go to [https://aka.ms/aadrecoverykey](https://aka.ms/aadrecoverykey)
== Getting your recovery key ==
[[File:MyAccountPage.png|thumb|365x365px|Picture of my account page]]
Get your BitLocker recovery key in case any issues arise. To do so, go to [https://aka.ms/aadrecoverykey](https://aka.ms/aadrecoverykey)


![https://rhit-lug-bucket.s3.us-east-005.backblazeb2.com/Screenshot+2024-10-14+194806.png](Picture of my account page)
Click Devices -> <click your device> -> View BitLocker Keys, copy this onto a mobile device or somewhere NOT on your RHIT computer. This will be required if something goes wrong when disabling BitLocker.


Click Devices -> <click your device> -> View BitLocker Keys, copy this onto a mobile device or somewhere NOT on your RHIT computer. This will be required if something goes wrong when disabling BitLocker.
== Disabling Bitlocker ==


2. Search for "Manage BitLocker" in the search bar and click the "Manage BitLocker" Control Panel entry. Then click "Turn off BitLocker" and follow the prompts provided. Wait for the BitLocker drive encryption to be disabled. Note that you are not done after this due to the Rose-Hulman MDM configuration.
# Search for "Manage BitLocker" in the search bar and click the "Manage BitLocker" Control Panel entry.  
3. Next, go to the search bar, and type "services.msc". Find "BitLocker Drive Encryption Service". Right-click this entry and click Properties, then set Startup Type to Disabled.
# Click "Turn off BitLocker" and follow the prompts provided.  
4. Search for "Group Policy Editor" and click "edit group policy", and navigate to Computer Configuration > Administrative Templates > Windows Components > Bitlocker drive encryption. In fixed data drives, OS drives, and probably also removable drives just to be safe, disable "Enforce drive encryption type", "configure use of hardware based encryption", and other ones that are directly related to the configuration and enabling of bitlocker
# Wait for the BitLocker drive encryption to be disabled. Note that you are '''not''' done after this due to the Rose-Hulman MDM configuration. Follow the rest of these steps to prevent it from turning back on each time you reboot
# Go to the search bar, and type "services.msc".
# Find "BitLocker Drive Encryption Service".
# Right-click this entry and click Properties, then set Startup Type to Disabled.
# Search for "Group Policy Editor" and click "edit group policy", and navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker drive encryption.  
# In fixed data drives, OS drives, and probably also removable drives just to be safe, disable "Enforce drive encryption type", "configure use of hardware based encryption", and other ones that are directly related to the configuration and enabling of BitLocker
# At this point, you should be good to go! Reboot and verify that BitLocker is still disabled.

Latest revision as of 19:48, 16 March 2025

In order to dual-boot Linux on a RHIT laptop, it is recommended to disable BitLocker (and Secure Boot). To do so on a RHIT Laptop, perform the following steps.

Getting your recovery key[edit | edit source]

Picture of my account page

Get your BitLocker recovery key in case any issues arise. To do so, go to [1](https://aka.ms/aadrecoverykey)

Click Devices -> <click your device> -> View BitLocker Keys, copy this onto a mobile device or somewhere NOT on your RHIT computer. This will be required if something goes wrong when disabling BitLocker.

Disabling Bitlocker[edit | edit source]

  1. Search for "Manage BitLocker" in the search bar and click the "Manage BitLocker" Control Panel entry.
  2. Click "Turn off BitLocker" and follow the prompts provided.
  3. Wait for the BitLocker drive encryption to be disabled. Note that you are not done after this due to the Rose-Hulman MDM configuration. Follow the rest of these steps to prevent it from turning back on each time you reboot
  4. Go to the search bar, and type "services.msc".
  5. Find "BitLocker Drive Encryption Service".
  6. Right-click this entry and click Properties, then set Startup Type to Disabled.
  7. Search for "Group Policy Editor" and click "edit group policy", and navigate to Computer Configuration > Administrative Templates > Windows Components > BitLocker drive encryption.
  8. In fixed data drives, OS drives, and probably also removable drives just to be safe, disable "Enforce drive encryption type", "configure use of hardware based encryption", and other ones that are directly related to the configuration and enabling of BitLocker
  9. At this point, you should be good to go! Reboot and verify that BitLocker is still disabled.