26. Click Install to continue with the installation.
27. Restart the computer upon completion.
TIP You can also install this feature quickly by running the following command at the command
prompt:
ServerManagerCmd.exe -install BitLocker -restart
344 Microsoft Windows Server 2008 Administration
Initializing BitLocker
Installing BitLocker is only part of the equation. Until you initialize and enable it, it isn??™t
going to do anything for you. If you have a TPM-capable system, you will first want to
initialize the TPM by running through the TPM Initialization from the BitLocker Control
Panel applet. If you like to automate things through scripting, you??™ll be happy to learn
that TPM includes a management API that can be leveraged to initialize TPM programmatically
as well. You must have local administrator privileges to initialize BitLocker
and should always create a recovery password in the event that all other authentication
methods fail and you need to get access to the drive. Once BitLocker has been initialized,
non-administrative users can access the system as usual, with the added benefit of the
behind-the-scenes encryption protecting their data.
Figure 10-6. Add the BitLocker Drive Encryption feature.
345 Chapter 10: Windows DNS, BitLocker Drive Encryption, and Itanium Support
Hands-On Exercise: Enabling BitLocker Drive Encryption
In this exercise, we will enable BitLocker Drive Encryption and encrypt the Windows
installation volume.
Pages:
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386