Securing our environment from
any number of potential situations is part of the responsibility of all system admits. One of the features that is
largely focused on nowadays is drive encryption because, really, the thing that we worry about the most is data. So you're a piece of hardware is just a piece of harder. It's the data that has value. So let's start about Dr Encryption and how we can
use the built in capabilities within server to manage our environment to be more secure.
First, we're gonna work with bit locker, but like her first, we'll start with our group policy environment. So let's go ahead and open up our group Policy Management Council here on our one of our domain controllers
Open up good policy management,
and then we're going to what to? In group policy management.
environment we have, but we're gonna work with, in our case, our default to many policy. That's what would have worked with is that default to be policy.
We're gonna actually right click out our default, many policy and do edit.
once we actually get in there,
we're gonna edit it and make some changes to it.
que pasa manager editor, we're going to start with the computer configuration because if you think about it, encrypted hard drive is a computer
piece of the puzzle.
So the computer configuration
we're going to be under the Policies section
and under the policy section,
we're gonna work out to our administrative templates.
So go ahead and scald out administrative templates,
and we're within our administrative templates. We want to go to Windows components.
So they had to expand out with its components.
And we get a long list of options under witness components,
bit locker drive encryption. So let's go ahead and click on
a bit like a diver. Corruption here.
And there's our bit locker drive, encryption notice. We actually have fixed data, drives operatives is to drive removable data drives as
subcategories underneath our bit locker, Dr. Environment. So,
in terms of what we want to d'oh, we're going to spend it and we're gonna
choose our fixed data drives. So we want to fix dated guys versus removable dater. I was dr
remember, the operative sister drives are a little bit difference We have to be very careful how we work with us.
So are fixed data drives. We're going to choose how bit locker it protects. The FEC stated drives
came, could be recovered. It's over here.
our environment, too.
Choose how the locker protected fixed drives can be recovered because obviously
protecting him is with a recovering of could be more important,
so we want to protect him. But if there's a issue later on
and we need to recover data from the drive for any number of reasons, including legal reasons, we might want to be able to recover it. So next we want to actually enable the
So we're gonna enable the GPS setting
and down here when we enable that we noticed we have options to work with.
The first option is to allow a data recovery agent.
in terms of what we want,
do we issue want to ensure that we could do that? How about,
uh, how about the save?
Look here, Say bit like recovery information to a T. D. S for fix data drives.
Well, I certainly makes a lot easier if it's in 80. So we want to actually
make sure that that is selected
and do not datable bit Locker to recover information is stored in a D. D s. So
if we want to make sure that we're gonna choose that,
that we would also say don't actually allow anything to be encrypted there was still basically allow it to happen until
a D. D S has the information.
So a lot of data recovery agent is there, too. We can omit recovery options from the bit locker setup wizard,
if you want. We have saved bit locker recovery information 80 s, and then we also want to do we want to
not enable bit locker recovery information,
not enable bit locker until recovery operation is stored in a. D. D s
that we could go and click out okay there because we actually have completed the process of what we need to do. So click on the okay button
and that sets the setting. Remember, how it works is once the setting is said, we don't have to save it.
And now we're going to want to work with our environment on a device that is going to be impacted by the group policy change we just made. So go ahead, switch over to one of our servers
credits. Which server one.
And here were to what?
So we're gonna open over power Shell environment?
Yes, you can use the committee, but power shells the preferred environment now. So you want to go out and you used to work with it,
and we're going to want to force an update of the group policy. So we do GP update
today's slash force.
So, an update, our good policy, we'll update it, and they will give us the results of that update.
And after it's done updating to make sure that everything is
properly encoded for our environment in terms of the bet lacquer process and the steps to go with it,
we're actually gonna want to restart that server. So
what we do is we're gonna close out of this and we will go ahead and restart the server and we will pick back up on our server manager. What's the server is restarted
now? There were rebooted. Back up it running. We need to configure the local environment. Remember, we created a group policy for our domain
for making sure that that locker was recoverable. Now, if you want to create bit, locker drive encryption
on a local machine, so on our server here, where I should go to go to our
and add rules and futures
to bring up our ad rules of features, Wizard
got next on the initial splash screen and next on the World Base or future based installation.
And next on the local server
exits are role screen, so the next thing we have to determine is where this is. Is this a roll or a feature? So if we take a quick look here and there's, there's nothing on the roll page about Bette Locker has got to move on to the future page
and now we have bit locker drive, encryption. We also have a bit locker network unlock. If we're gonna be using it
so a bit locker drive encryption. We're gonna go ahead and select the bit lack of drive encryption.
It's gonna give me a list of features that we're going to be required. So click on, Add the futures for that
kid. Then once we have that, we're gonna click on next.
We're going to do the network. Unlock here,
bed. We're going to go ahead at this time since his bit locker. We know we need to do it. We're gonna do
check the boxes. Says restart
server automatically if required. Visit restart required to service restarts automatically without addition modifications. And yes, we won't allow automatic restarts
and then we want to click on the install option here.
So go ahead and click on install,
and then we will go ahead and wait for the process to finish. And when the process finished,
the system will automatically reboot force, which is just a little bit time and effort in terms of
we don't have to remember to do it.
The aid. We don't actually manually have to do it.
When the time comes, the process will
Ed run through this process and we will then
bring it back up and running. So we will actually allow the features relation to complete here.
It says its installation to start it and run through. We can obviously close the wizard. We know that without interrupting any running task, we can also view the task prize just open the page by clicking notifications in the command bar. We have those options, and once it's stunned you unless it reboots. And when it does reboot, we're going to go ahead and paws are
according temporarily and let it finished rebooting the we'll pick our recording back up.
There is no point in watching a computer reboot. That's pretty much time and energy.
As a matter of fact, we're going to go ahead
cause now it actually finish it in a Listers in the Airs. The next time we look at the screen will be back up and running with our server manager dashboard
and moving on to the next step of the equation.
Another service fully rebooted back up a running. You notice we have our
insulation, Progress tells us, completed, and we have all the information to go associated with it. So we're going to go ahead and click on clothes here,
so close out of that.
And now we're actually going to deal with the bit locker piece of the equation.
So we're going to go to our control panel and find our bit locker option. So open up our control, panel
to find it. The easy way. Just type in bit locker up there in the search box.
That's how you spell it, right? Locker.
And why should go, too?
Have the option to click on a bit locker drive, encryption or management locker? So you want to actually
go ahead in there and and a bit like a diver Christian Window.
What is going to click out of it like a drive encryption?
And it says that locker drive encryption to help protect, pulled out your files or folders and says sees but lockers off E bit lockers off and F bit lockers off those rocks. She already called F Dr Encrypted. And that's where we're going
work with in this particular case. So we were on the after everyone actually click on expansion of it and
choose turn on bit lockers were gonna spend the drive out quick, turn a bit locker
bear in mind that this is all gonna be a D associate ID. What? We had it. So what? We do it. We need a password to unlock the drive, so
use the faster it'll lock, drive or use a smart card. Like to drive. We have a smart car, but we're gonna use a password for our environment.
And so we're going to put in
the information of the password.
So bear mind, it's just a password. It's not a user. So putting it
associated with a strong password because it's encrypted data
and we click on next, make sure that match, Of course
they don't match. You will be warned. This is how do you want to back up your recovery key? So that depends in terms of how do we get back up your recovery key? Well, typically, do is go to save it to a file because saving to use the flash drive, we could print the record freaky. That's ah, something that we could do was gonna save it to a file. So it's quiet and say that to a file,
and it says bit like a recovery key and it gives us some information, that text, and we have to choose where we're gonna put it. So we're gonna put it into our
e. Dr. Don't put it in your crypt to drive whatever you do, don't encrypt the recovery. T gonna drive where you need to get to recover key toe unencrypted.
Let's move on to our lab files and we'll go to my 10
and we're going to just leave the name as is. We could change the name of Wanted to board to believe it, as is a click on save. So that saves our key. Do you want to say the recovery key on this PC
says it's a good idea to have more than one recovered key and keep each in a safe place other than your PC. That makes sense.
because obviously, if they get lost or stolen, you want to make sure you have recovered key elsewhere
and we could be saved a file once again and put a recovery key in the second place. We're gonna click out next and says, Are you ready to encrypt this? Dr.
Obviously, we would come to this next step. We want to
click on, start encrypting
progresses Christian in progress,
and it will give us the information about it, says it. Crush it back up to recover Key Chase ***. Let's forget other features. Here
you have a backup of you recover key.
We could change password I can remove the password. I can add a smartcard, turn on auto lock and turn off that locker. So these air all of these pieces of puzzle
actually I'm running a bit locker so I could actually
go here to our environment. What's is completely encrypted
to spring up. Our power show
can actually go to our power. Shell
run certain commands that will actually let us. So we have a bit locker drive, encryption, or Bt and we actually want Look, the status of that's from a partial we can So this case will type in the
And what we're gonna manage, we're gonna manage are actually made this dash B d.
So I managed BD e mail it
and we're gonna tell it to give us a status, right? So, Josh,
else. If we spell it right
ago, spell it correctly.
gives us the results of that command. Let it tells us that
this drives could be protected. That locker, it says via me. All files dated. I was a size is 127 gigs. It's
conversion status is fully decrypted.
Their protection is off. It's a locked. It's disabled. So that's our all files After is encrypted, says
used to space on Lee encrypted. So it's only encrypting you space. So it's the sixth gate drive and it's a yes 1 28 Protection is on.
It's locked. Status is a lot. It's identity issues unknown. Automatic Elect is disabled and Kiefer protectors are password in a numerical password. And as the other ones are fully decrypted
in our Bible and that tells us the status of our drives within our environment
way because I'm that
goes out of our window, we're back to our server manager, and that is the process involved in implementing bit locker