EFS was not a foolproof option. BitLocker is.
However, a little beforehand research is in order.
One needs to have at least two (2) volumes created before installing Windows Vista.
At least that is how it reads until about the middle of the Help article where it states that if you only have one volume, you can use the BitLocker Drive Preparation Tool to "help get your system ready for BitLocker by creating the required second partition".
From the Windows Vista Help for BitLocker:
Set up your hard disk for BitLocker Drive EncryptionFrom the above mentioned Knowledge base article:
Before you can turn on BitLocker Drive Encryption you need to make sure that your computer's hard disk has the following:
At least two volumes. If you create a new volume after you have already installed Windows, you will have to reinstall Windows before turning on BitLocker [emphasis ours].
One volume is for the operating system drive (typically drive C) that BitLocker will encrypt, and one is for the active volume, which must remain unencrypted to start the computer. The size of the active volume must be at least 1.5 gigabytes (GB). Both partitions must be formatted with the NTFS file system.
The terms partition and volume are often used interchangeably. On most computers, they are the same: one partition equals one volume. On larger computer systems, however, it is possible to have a single volume span several partitions. BitLocker installs on a simple volume, where one volume equals one partition.
If you do not already have two partitions, you can use the BitLocker Drive Preparation Tool to help get your system ready for BitLocker by creating the required second partition [emphasis ours].
If you are using Windows Vista Ultimate, you can download and install the BitLocker drive preparation tool from Ultimate Extras. Download and install the Ultimate extra called BitLocker and EFS enhancements. After you have installed this tool, type BitLocker into the Start menu search box, and then double-click BitLocker Drive Preparation Tool to run the tool. After the tool runs, you must restart your computer before turning on BitLocker.
If you are using Windows Vista Enterprise, you can get the BitLocker drive preparation tool through these standard support channels:
Microsoft Volume Licensing Services
Microsoft Services Premier Support
Additional information about the BitLocker drive preparation tool is available in Knowledge base article KB# 930063.
If your computer meets these requirements, you can turn on BitLocker.
To turn on BitLocker
Click to open BitLocker. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
Click Turn on BitLocker.
Follow the instructions in the BitLocker Setup wizard.
How to obtain the BitLocker Drive Preparation ToolWe don't have a free system with a TPM at the moment. So, we won't be able to run through the setup procedure to figure out just what is up.
Windows Vista Ultimate
If you are using Windows Vista Ultimate, follow these steps to obtain the tool:
- Click Start, type Windows Update in the Start Search box, and then press ENTER.
- Click Check for updates.
- Click View available Extras.
- Click to select the BitLocker and EFS enhancements check box, and then click Install.
To the Windows Vista team that wrote this particular Help item, please clarify whether we need to have two partitions/volumes before we install the OS or not. The above Help article certainly, at least in our opinion, doesn't make things clear.
Microsoft Small Business Specialists
*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.