Full-volume encryption built into Windows; drives used with Azure Import/Export are protected with AES-256 BitLocker.
Also called BitLocker Drive Encryption.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains BitLocker in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Import/Export
Azure Import/Export lets you ship disks so data can be loaded into or exported from Azure storage as a one-off; it is not meant for continuous ingestion.
Related terms
- Azure Disk Encryption
Due to retire on 15 September 2028, this feature encrypts VM OS and data disks from inside the guest (BitLocker or DM-Crypt), keeping keys in Key Vault. Dynamic volumes, Write Accelerator disks and ephemeral OS disks aren't supported.
- BitLocker key rotation
Generates a fresh BitLocker recovery password on a Windows device from Intune, so that one which has been handed out can't be used twice. Recovery information must be saved in Microsoft Entra ID and client-driven rotation enabled for it to work.
- Cloud Device Administrator
Entra role whose rights cover turning devices on or off in the directory, deleting them and viewing BitLocker recovery keys, with no access at all to Azure resources.
- Device Health Attestation
Reports, measured only while Windows starts up, on things like code integrity, Secure Boot and BitLocker, so that compliance policies can check a device's health.
- Enhanced Storage
A Windows Server feature that adds support for drives with built-in hardware encryption. BitLocker depends on it for such drives, yet installing BitLocker through PowerShell does not include it.
- Journal file
For every drive it prepares, the WAImportExport tool produces a .jrn file recording the BitLocker key, drive serial number and account details. You upload these files when you create the Import/Export job.
- Key package
Helps rescue data from a damaged BitLocker drive. AD can store it, though not by default.
- Network Unlock
With this BitLocker capability, domain-joined machines secured by TPM plus PIN can boot without the PIN when connected by cable inside the company. A certificate and a WDS server running Network Unlock are prerequisites.