ATI2021 and interaction with Bitlocker
I have a laptop (HP Probook 450 G6) on which I have enabled Bitlocker.
I want to know exactly how I can go about using ATI2021 to restore a system image in case disaster should strike.
I have read various knowledge base articles relating to Bitlocker which, to be honest, do not really explain things very well (at least not to me).
I would like the following questions answered if possible:
- When taking a system image backup of the Bitlocker protected drive does Bitlocker protection need to be Suspended? If it does, why and similarlily, if not why not?
- I believe that I cannot recover the system image from within the Windows based program but must use ATI Bootable Media. Does the bootable media created from within ATI Windows include any tools to enable Bitlocker recovery to take place if these are needed?
- Do I need to save a copy of the Bitlocker Recovery Key to the ATI Bootable Media for the restoration to the same drive to work? If not, will I need to have the Recovery Key to hand during the recovery so I can manually enter this?
- The laptop in question has a TPM and Bitlocker has been enabled so that it utilises this TPM alongside a PIN. Does any of this alter the way in which the recovery of a system image to that drive would be performed?
- I believe that if I wanted to clone the OS drive to a larger drive then I would be well advised to decrypt the OS drive before cloning it and then turn Bitlocker on again once the clone process had taken place. Is that correct? Would tuning off Bitlocker also disable the TPM and PIN protection mentioned above or would I need to reset this in Group Policy Editor before/after turning off Bitlocker protection.


- Se connecter pour poster des commentaires

Thank you Steve for the detailed response which I will digest and then try and put into practice.
Can you please confirm whether the fact that I have BL enabled with both the use of the TPM and a PIN makes any difference to your advice.
Also, when you mention using the Password do you mean the BL Recovery Key or the BL PIN, which are different.
Robert
- Se connecter pour poster des commentaires

Robert, I would suggest taking a read through webpage: A beginner's guide to BitLocker, Windows' built-in encryption tool - to see if this will help answer some of your questions.
I don't use BitLocker other than for occasional testing purposes and don't have TPM etc.
You should use / read the help available for BitLocker as shown below:
PS D:\powershell> manage-bde -unlock /? BitLocker Drive Encryption: Configuration Tool version 10.0.19041 Copyright (C) 2013 Microsoft Corporation. All rights reserved. manage-bde -unlock Volume {[{-RecoveryPassword| -rp} NumericalPassword] | [{-RecoveryKey|-rk} PathToExternalKeyFile]} [{-Certificate|-cert} {-cf PathToCertificateFile| -ct CertificateThumbprint} {-pin}] [{-Password|-pw}] [{-ADAccountOrGroup|-sid} [{SID|domain\user|domain\group}] [{-ComputerName|-cn} ComputerName] [{-?|/?}] [{-Help|-h}] Description: Allows access to BitLocker-encrypted data with a recovery password, recovery key, certificate, or password. Parameter List: Volume A drive letter followed by a colon, a volume GUID path or a mounted volume. Example: "C:", \\?\Volume{26a21bda-a627-11d7-9931-806e6f6e6963}\ or "C:\MountVolume" -RecoveryPassword or -rp Provide a recovery password to unlock the volume. -RecoveryKey or -rk Provide an external key file to unlock the volume. -Certificate or -cert Query the local user certificate store for a BitLocker certificate to unlock the volume. -Password or -pw Prompt for a password to unlock the volume. -ADAccountOrGroup or -sid Attempt to unlock the volume using a SID-based Identity protector. -ComputerName or -cn Runs on another computer. Examples: "ComputerX", "127.0.0.1" -? or /? Displays brief help. Example: "-ParameterSet -?" -Help or -h Displays complete help. Example: "-ParameterSet -h" Examples: manage-bde -unlock -? manage-bde -unlock e: -RecoveryPassword ... manage-bde -unlock e: -RecoveryKey "f:\File Folder\Filename" manage-bde -unlock e: -Certificate -cf "c:\File Folder\Filename.cer" manage-bde -unlock e: -pw manage-bde -unlock e: -sid PS D:\powershell>
- Se connecter pour poster des commentaires

I face a lot of issue with BL and decided to decrypt my system. ATI2021 is not able to support BL imho.
- Se connecter pour poster des commentaires

Dietmar P wrote:I face a lot of issue with BL and decided to decrypt my system. ATI2021 is not able to support BL imho.
Hello Dietmar,
Acronis True Image is compatible with BitLocker with certain limitations that depend on the current status of BitLocker protection of the disk. Disks that are encrypted by BitLocker and are in locked state are not available for any operation by Acronis True Image, except for being overwritten when recovering an Entire PC, disk or partition backup in disk/partition mode using Acronis Bootable Media. Here we have the detailed information on the BitLocker support https://kb.acronis.com/content/56619
62662: Acronis True Image and BitLocker FAQ might also be helpful.
- Se connecter pour poster des commentaires

I have found that if I want to restore an ATI backup onto a Bitlocker encrypted drive then the best way to do this is to unlock Bitlocker and then decrypt it through Command Prompt after booting with the bootable media.
This seems logical but I wonder whether this is necessary or whether there is a way of getting ATI to restore to the drive without doing this.
Comments welcomed.
- Se connecter pour poster des commentaires

Hi RF,
It's only necessary to unlock the drive using the command prompt from the rescue media. You don't need to decrypt it.
- Se connecter pour poster des commentaires

Thank you Mustang.
I have tried merely unlocking the drive as described above by Steve and then restarting ATI and carrying out a restore.
Unfortunately, just as the restore process is about to start the system requires a reboot. This results, at least in my case, in restoration process failing as I suspect the reboot locks the drive again and so ATI cannot write to it.
I assume that this does not occur when you restore your system image to a Bitlocker encrypted drive. Please confirm.
Totally decrypting the drive is slower but not the end of the world.
I just was interested to know whether the program is designed to work when the OS drive has been unlocked but not decrypted.
- Se connecter pour poster des commentaires