0% found this document useful (0 votes)
11 views2 pages

Disk Encryption with BitLocker Guide

Disk encryption secures entire partitions or disks, with Microsoft BitLocker being the primary method supported, particularly for Analytic Server. BitLocker supports both physical and virtual machine servers, but requires manual actions for virtual machines post-restart to unlock drives and start services. The document outlines various scenarios for using BitLocker with virtual machines, emphasizing the need for manual intervention and caution regarding the storage of recovery keys.

Uploaded by

Kevin Tran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views2 pages

Disk Encryption with BitLocker Guide

Disk encryption secures entire partitions or disks, with Microsoft BitLocker being the primary method supported, particularly for Analytic Server. BitLocker supports both physical and virtual machine servers, but requires manual actions for virtual machines post-restart to unlock drives and start services. The document outlines various scenarios for using BitLocker with virtual machines, emphasizing the need for manual intervention and caution regarding the storage of recovery keys.

Uploaded by

Kevin Tran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Disk Encryption

Disk encryption is an encryption method that encrypts the entire partition or disk in which the file system resides.

Disk Encryption supports the Microsoft BitLocker Encryption.

NOTE: BitLocker is only required for Analytic Server.

Microsoft BitLocker Drive Encryption


BitLocker Drive Encryption is a Microsoft security feature that used for encryption. For more information see the
Microsoft online documentation.

BitLocker Drive Encryption supports two types of servers:

Physical Machine Servers - full support with TPM.

Virtual Machine Servers - supported but not recommended. Using BitLocker on virtual machines requires manual action
after each virtual server restart, in order to unlock drives and start NICE services.

NOTE:

TPM is mandatory when using BitLocker with physical servers.

It is recommended that Audio Analysis service is the only service allowed access to the temporary audio files created in
the workflow directory.

BitLocker Usage Scenarios with Virtual Machines


The following describes possible BitLocker usage scenarios, applicable to virtual machines only.

Scenario 1:
Bitlocker is used for encrypting only the data drives that include NICE files + Media Cache (D/E/etc.).

After the server restarts, the drive is locked and becomes inaccessible until the drive is manually unlocked by typing in
the BitLocker password.

The NICE services fail to start automatically after the restart and need to be manually started after the drive is unlocked.

[Link]
Updated: Tue, 29 Apr 2025 01:04:25 GMT
Powered by
1
Scenario 2:
The Auto-Unlock option is enabled for data drives, meaning they are automatically unlocked after a restart without the
need for typing the password in manually.

In VMWare, the data disks appear on the OS level as removable data drives. With removable data drives, Auto-Unlock
is enabled per-user level and not per-machine, meaning encrypted drives are auto-unlocked only after a user with auto-
unlock configurations logs into the server.

The NICE services fail to start automatically after a restart and need to be manually started after the drive is unlocked.

Changing the NICE services startup type from Automatic to Automatic-Delayed may sometimes resolve the need to start
the services manually, if the user with auto-unlock configurations logs in right after the server restarts.

In Hyper-V, the data disks appear on the OS level as fixed data drives (by MS design). In that case, this feature requires
encryption of the OS drive as well. For further details, go to BitLocker FAQ.

Encrypting the OS drive requires manually accessing the server console after each restart and typing in the password,
as VMs don’t have a physical TPM chip like physical servers.

There is an option to configure Network Auto-Unlock for the OS drive of VM without TPM. In this case, the OS drive is
automatically unlocked after the server restarts, the D/E data drive is auto-unlocked and NICE services start
automatically.

In some case, this may be needed to change the start-up type to Automatic-Delayed.

Thus, manual intervention is usually required to either unlock drives or to start NICE services.

NOTE: When encrypting a drive with BitLocker, a recovery text file is created with GUID and a recovery key, in plain
text. It’s possible to unlock the encrypted drive with this recovery key. Therefore, it’s not recommended to keep it on the
server itself.

NICE ENGAGE PLATFORM

Further Reading

[Link]
Updated: Tue, 29 Apr 2025 01:04:25 GMT
Powered by
2

You might also like