Skip to main content

Recovery and Bitlocker

Thread needs solution

While this forum may not be the right place for this inquiry, and no replies expected, I thought I'd try here first.

I read the knowledge base information (1734: Acronis Backup: Compatibility with Windows BitLocker) and found it missing a key element.

I understand the pitfalls of an OS encrypted drive, and a restore should it be necessary.

The missing element though was discussion of impacts to a system with a TPM module installed, and in use for the Win 10 Bitlocker incrypted OS drive.

What is the impact for a Win 10 OS encrypted drive with TPM active during a restore operation?

This setup is important so that not only my personal environment is understood fully, those that I consult for are able to make the proper business decisions with the right information.

My system is a platform for understanding and experimentation so my clients can understand the impacts of various decisions.

Thank you for your time and consideration.

Jim

0 Users found this helpful

I haven't personally tried, but it should work just fine.  Primarily, the reason being tha Acronis backups on a bitlockered drive are taken while the machine is in a decrypted state (when Windows OS is booted).  You cannot backup the drive while it's encrypted (you can try a sector-by-sector backup and hope for the best, but most likely is a useless backup).  This is why Acronis states to run your backups from Windows on an ecnrypted system (while it's decrypted).

As a result, an restores would be done with unencrypted data (well, other than the encryption my may have set on the backup .tib file as part of the backup process from within Acronis).  This should give you an unencrypted system after the restore and then you would need to apply bilocker encryption again. 

Worse case, you could disable TPM and remove the associated security keys in the bios before restoring an image and once the image is restored, enable TPM an d create the TPM keys again and then proceed to bilocker encrypt the drive after that.  These scenarios should apply to just about any backup product out there though and not be specific to Acronis.