BitLocker Drive Encryption is an integral new security feature in both Windows Server 2008 and Windows Vista to protect servers at locations such as branch offices and mobile computers for roaming users.
BitLocker provides considerable offline data and operating system protection by ensuring that data stored on the computer is not revealed if the machine is tampered with when the installed operating system is offline. It optionally uses a Trusted Platform Module, or TPM, to provide enhanced protection for your data and to assure early boot component integrity. This helps protect your data from theft or unauthorized viewing by encrypting the entire Windows volume. BitLocker Drive Encryption is designed to offer the most transparent end-user experience with systems that have a compatible TPM microchip and BIOS.
The TPM interacts with BitLocker Drive Encryption to help provide protection at system start-up. BitLocker Drive Encryption can also be used on computers without a compatible TPM. Using BitLocker in this way provides the volume encryption capabilities but not the added security of early boot-file integrity validation. Instead, a USB flash drive validates the user’s identity at startup.
BitLocker is configurable through Group Policy. What this means is, with Windows Server…