phillyphotogmagee
New Member
Ok, I have a feeling that this is a larger Windows 10 issue, but I am experiencing this with the Surface Pro 4, the ideal test hardware for anything
Microsoft, right?
Here is what we are trying to accomplish:
Encrypt our Surface Pro 4's (win 10 Pro) using Hardware-Based Encryption
Why?
A) Because it is faster for the SSD to perform the encryption rather than the process, since the SSD is already encrypted
B) Better battery life (because the processor is not encrypting the volume)
C) Performing software encryption on an already encrypted volume defeats many of the internal optimizations that SSDs have built in (leading to slower performance)
How?
We have taken stock Surface Pro 4s, straight from the box. No applications or updates have been installed, we have not added to a domain. The only modification we have made is to the Local Group Policy:
Computer Configuration/Administrative Templates/Windows Components/Bitlocker Drive Encryption/Operating System Drives
*Require additional authentication at startup (Enabled, default options)
*Enable use of BitLocker Aauthentication requireing preboot keyboard input on slates (Enabled, default options)
*Configure use of hardware-based encryption for operating system drives (Enabled, default options)
What's Wrong:
When I go to enable Bitlocker, I am being provided the prompt to encrypt Used Only, or Whole Drive. From all of the literature I have read, this prompt indicates Software Encryption. When I select Full Drive, it takes a while (over 10 minutes) to encrypt. Again, from my reading, Hardware Encryption should be immediate (as everything is already encrypted).
Question:
What am I missing? Is there an issue with Hardware Encryption that I have not been able to identify on the Surface Pro 4? Is this an OS issue? Are there any other troubleshooting steps that I can take a look at? Again, these are stock units, fresh out of the box from Microsoft.
Sources (these are just some, all have been verified using additional sources that repeat the information):
Slower Performance- Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500
Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500
Steps to enable encryption- How to Enable BitLocker Hardware Encryption with SSDs
How to Enable BitLocker Hardware Encryption with SSDs • Helge Klein
Technet on Why to Hardware Encrypt - Encrypted Hard Drive
Encrypted Hard Drive
GP Settings to Enable Hardware Encryption - Enabling Hardware Acceleration of BitLocker
Enabling Hardware Acceleration of BitLocker
Microsoft, right?
Here is what we are trying to accomplish:
Encrypt our Surface Pro 4's (win 10 Pro) using Hardware-Based Encryption
Why?
A) Because it is faster for the SSD to perform the encryption rather than the process, since the SSD is already encrypted
B) Better battery life (because the processor is not encrypting the volume)
C) Performing software encryption on an already encrypted volume defeats many of the internal optimizations that SSDs have built in (leading to slower performance)
How?
We have taken stock Surface Pro 4s, straight from the box. No applications or updates have been installed, we have not added to a domain. The only modification we have made is to the Local Group Policy:
Computer Configuration/Administrative Templates/Windows Components/Bitlocker Drive Encryption/Operating System Drives
*Require additional authentication at startup (Enabled, default options)
*Enable use of BitLocker Aauthentication requireing preboot keyboard input on slates (Enabled, default options)
*Configure use of hardware-based encryption for operating system drives (Enabled, default options)
What's Wrong:
When I go to enable Bitlocker, I am being provided the prompt to encrypt Used Only, or Whole Drive. From all of the literature I have read, this prompt indicates Software Encryption. When I select Full Drive, it takes a while (over 10 minutes) to encrypt. Again, from my reading, Hardware Encryption should be immediate (as everything is already encrypted).
Question:
What am I missing? Is there an issue with Hardware Encryption that I have not been able to identify on the Surface Pro 4? Is this an OS issue? Are there any other troubleshooting steps that I can take a look at? Again, these are stock units, fresh out of the box from Microsoft.
Sources (these are just some, all have been verified using additional sources that repeat the information):
Slower Performance- Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500
Hardware Accelerated BitLocker Encryption: Microsoft Windows 8 eDrive Investigated with Crucial M500
Steps to enable encryption- How to Enable BitLocker Hardware Encryption with SSDs
How to Enable BitLocker Hardware Encryption with SSDs • Helge Klein
Technet on Why to Hardware Encrypt - Encrypted Hard Drive
Encrypted Hard Drive
GP Settings to Enable Hardware Encryption - Enabling Hardware Acceleration of BitLocker
Enabling Hardware Acceleration of BitLocker
Last edited: