Drive Encryption settings are managed through policies and are disabled by default to prevent unintentional encryption of endpoint drives. Update each policy to enable BitLocker encryption on Windows drives.
- In Nebula, navigate to Configure > Policies.
- Select the policy to update.
- Click Drive Encryption.
- Check the Enable automatic drive encryption checkbox.
- Turning off this setting does not decrypt drives. It only halts future automatic encryption and recovery key escrowing.
- Drives that are manually encrypted while this setting is disabled won't display their recovery key in Nebula.
- Select which drives to encrypt:
- OS drive: Primary storage device where the operating system is installed. (C:)
-
OS drive and fixed data drives: OS drives and internal storage drives used for storing applications and large amounts of data (C:, D:, E:, etc).
- Passively enables the BitLocker setting Automatically unlock this drive on this computer to prevent lockouts of fixed data drives. On highly sensitive drives, admins can require a recovery key each time the drive is accessed by manually disabling the setting. For more information, see Disable-BitLockerAutoUnlock.
- Select an encryption method. Once a drive is encrypted, the encryption method cannot be changed:
- XTS-AES-128: Strong encryption, faster performance on older hardware.
- XTS-AES-256: The strongest encryption option, ideal for regulated industries like healthcare, finance, and government.
- Select an encryption scope:
- Used space only: Encrypts sectors that currently contain data but does not protect previously deleted files. Fast on solid-state drives and best suited for new machines with no sensitive deleted data. New data continues to be encrypted in real time.
- Full disk: Encrypts every sector, including previously deleted data. Slower, but required by certain organizations and compliance regulations.
- Select whether to enable Rotate key after recovery. This is recommended to prevent reuse of potentially compromised keys.
- Click Save in the top-right.
- Navigate to the Monitor > Drive Encryption page to view each endpoint's encryption status.
Return to Drive Encryption guide.