When a hard drive is encrypted with Microsoft BitLocker, its data remains protected in case the drive is stolen or removed and connected to another computer.
Drive Encryption is a centralized BitLocker management feature that enables IT admins to silently and remotely encrypt Windows endpoints from Nebula.
Drive Encryption features
Drive Encryption gives IT administrators the ability to:
- Remotely push encryption policies to Windows endpoints across your environment
- Monitor encryption status across managed devices from a single dashboard.
- Manage recovery keys centrally, with instant lookup by machine name or BitLocker Key ID. Recovery keys for drives already encrypted with BitLocker are stored in Nebula.
- Automatically rotate recovery keys after use.
- Show auditors proof of encryption compliance.
- Log audit events when recovery keys are used or revealed.
How it works
Drive Encryption uses BitLocker with a Trusted Platform Module (TPM) protector, a physical security chip on each device. This means the encryption key is stored in the machine's TPM chip, and the machine boots normally without any user PIN. This enables silent deployment at scale.
Two encryption standards are supported:
- XTS-AES-128: Faster on older hardware and suitable for most organizations.
- XTS-AES-256: Maximum strength, used in high-security and compliance-mandated environments.
To encrypt an endpoint's drive:
- Configures a policy in Nebula to automatically encrypt drives.
- The Endpoint Agent checks that the device supports BitLocker encryption. For more information, see Requirements for Drive Encryption in Nebula.
- BitLocker's silent encryption begins automatically. No prompts are shown to the user.
- The recovery key is stored in Nebula and displayed in Nebula.
- Data residency is the same as for our endpoint protection. For more information, see https://www.threatdown.com/legal/gdpr-commitment.
Return to Drive Encryption guide.