Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » Install BitLocker on Windows Server via the Server Manager
  • How to Enable or Disable Inherited Permissions for Files and Folders in Windows
    How to Enable or Disable Inherited Permissions for Files and Folders in Windows Windows
  • IIS Installed
    Add and remove IIS Web Server on Windows Server 2019 via the Server Manager and PowerShell Web Server
  • azure app service with office 365 and yammer sharepoint saturday florence 2015 session 8 638
    WordPress site on Azure: How to create a website hosted in Azure Oracle/MSSQL/MySQL
  • LAPs on Windows Part of the OS
    How to configure Windows LAPS Windows
  • Standby Mode
    Disable modern standby on Windows 10 and 11 Windows
  • Fixing TPM Vulnerability
    How to fix a vulnerable Trusted Platform Module [TPM] Windows
  • RUST FEATURE
    How to install Rust in a Linux System Linux
  • VBR upgrade
    Upgrade Veeam Backup and Replication to version 12.2 Backup

Install BitLocker on Windows Server via the Server Manager

Posted on 13/11/202319/12/2023 Christian By Christian No Comments on Install BitLocker on Windows Server via the Server Manager
Deploy-BitLocker-on-Windows-Server-manually

BitLocker Drive Encryption enables you to protect data on lost, stolen or inappropriately decommissioned devices by encrypting the entire volume and checking the integrity of early boot components. These data can only be decrypted if all the components are successfully verified and the encrypted drive is located in the original PC. In this article, we shall learn how to Install BitLocker on Windows Server via the Server Manager. Please see How to Disable BitLocker on Windows 10, and How to Change BitLocker Password in Windows.

For all Windows Server editions, BitLocker isn’t installed by default, but it can be installed using Server Manager or Windows PowerShell cmdlets. Administrative rights are required to perform this task.

Note: Integrity checking requires a compatible TPM module for your device. You may want to see how to disable Lock Screen on Windows 10 via Registry Editor, and how to Backup existing and new BitLocker Recovery Keys to Active Directory.

Step 1: Install BitLocker on Windows Server

Open the server manager by selecting the server manager icon or running servermanager.exe. Oftentimes, this wizard opens automatically,

Select Manage from the Server Manager Navigation bar and select Add Roles and Features to start the Add Roles and Features Wizard.

Alternatively, from the Server Manager dashboard, you could select Add roles and features as shown below.

Roles-and-features

With the Add Roles and Features wizard open, select Next at the Before you Begin pane if shown.

Skip-Before-you-begin

Select Role-based or feature-based installation on the Installation type pane of the Add Roles and Features wizard and select Next to continue.

Role-or-feature-Based-Installation

Select the Select a server from the server pool option in the Server Selection pane.

Select-server-to-install-BitLocker-features
Note: Server roles and features are installed by using the same wizard in Server Manager.

Select Next on the Server Roles pane of the Add Roles and Features wizard to proceed to the Features pane. 

Select the check box next to BitLocker Drive Encryption within the Features pane of the Add Roles and Features wizard.

Drive-ecryption-features

Note: The Enhanced Storage feature is a required feature for enabling BitLocker. This feature enables support for encrypted hard drives on capable systems.

Enhanced-Stored-features

The BitLocker features and the Enhanced Storage have been selected.

BitLocker-features-installed

Before proceeding with this step, you may want to learn about Microsoft BitLocker Administration and Management (MBAM).

Install BitLocker

Select Install on the Confirmation pane of the Add Roles and Features wizard to begin the BitLocker feature installation.

If you want the server to restart automatically, check the box close to the “restart the destination server automatically if required”.

This forces a restart of the computer after installation is complete. At this time, I will not check it just to show you that it does require a RESTART of the Windows Server.

Install-BitLocaker-unto-Windows-Server

BitLocker is installing

BitLocker-feature-is-being-installed

If the Restart the destination server automatically if the required check box isn’t selected. The Results pane of the Add Roles and Features wizard displays the success or failure of the BitLocker feature installation. Please restart your server.

BitLocker-and-Enhanced-storage-installed
Please proceed and have your server restarted.
Screenshot-2023-11-13-at-20.02.57

Also, see how to fix “Cannot open Bluetooth preference pane because it is not available“, How to Create Hyper-V Virtual Switch, and How does Key Rotation work in MBAM?

To install BitLocker on Windows Server using Windows PowerShell

Windows PowerShell offers administrators an option for BitLocker feature installation. The server must be restarted to complete the installation of BitLocker. I will not be discussing these steps as the focus is on Server Manager. Here is how this BitLocker can be installed with Powershell.

Installing the BitLocker feature using Windows PowerShell does not install the Enhanced Storage feature. Administrators wishing to support Encrypted Hard Drives in their environment will need to install the Enhanced Storage feature separately

Using the DISM module to install BitLocker

With the dism.exe Windows PowerShell module uses the Enable-WindowsOptionalFeature cmdlet to install features. Learn how to install BitLocker with DISM.

Step 2: Turn on BitLocker using Windows Explorer

It is interesting to note that this option is available on client computers by default. On servers, the BitLocker feature and the Desktop-Experience feature must first be installed for this option to be available.

After the server reboots, you can use BitLocker. To enable BitLocker on Windows Server, kindly proceed with the steps below.

Windows Explorer allows you to launch the BitLocker Drive Encryption Wizard by right-clicking a volume and selecting Turn On BitLocker.

Turn-on-BitLocker-

This will check for the PC configuration. This process can take a while to complete. Sit back and relax.

Checking-PC-configuration

Proceed with the BitLocker Drive Encryption setup by clicking on Next

BitLocker-Drive-Encryption-setup

Click on Next to proceed as well.

BitLocker-encryption

The volume is shrunk as shown below.

encryption-in-progress

Encrypt the drive

Encrypt-Drive

Choose how to unlock the drive at Startup. I will select the second option as shown below.

Choose-method-of-startup-unlock

Enter a Password

Important: Removable data drives can be unlocked using a smart card. A SID protector can also be configured to unlock a drive by using user domain credentials. After encryption has started, the drive can also be automatically unlocked on a specific computer for a specific user account.

Enter-a-Password

I will select the second option to have the entire drive encrypted.

Encrypt-entire-drive

On the Ready for BitLocker Encryption? click on continue.

The "run BitLocker System Check" is selected by default. You can choose to deselect this.
Ready-for-BitLocker-Encryption-Ru-BitLocker-System-Check

You will be notified that BitLocker will start shortly after the PC is restarted.

PC-restart-to-enable-BitLocker

Unlock BitLocker Drive Encryption

To UnLock BitLocker Drive Encryption, enter the password you entered above.

UnLock-BitLocker-Drive-Encryption

Encryption has started

Volume-encrypted

Verify BitLocker Encryption

To verify the BitLocker status of a particular volume. Administrators can look at the status of the drive in the BitLocker Control Panel applet, Windows Explorer, manage-bde.exe command-line tool, or Windows PowerShell cmdlets. Each option offers different levels of detail and ease of use.

Determine the current state of a volume you can use the Get-BitLockerVolume cmdlet, which provides information on the volume type, protectors, protection status, and other details.

Check-BitLocker-Status-via-PowerShell

With manage-bde.exe you can determine the volume status on the target system

verifiy-BitLocker-Encryption-via-Command-Prompt

Process can take a while and encryption times vary depending on the type of drive that is being encrypted, the size of the drive, and the speed of the drive. If encrypting large drives, encryption may want to be scheduled during times when the drive isn’t being used.

Also, see how to check if Microsoft BitLocker Administration and Monitoring is installed on Windows, and how to Fix no BitLocker Recovery tab in Active Directory.

FAQs on Deploying BitLocker

Do I have to suspend BitLocker protection to download and install system updates and upgrades?

No user action is required for BitLocker in order to apply updates from Microsoft, including Windows quality updates and feature updates. Users need to suspend BitLocker for non-Microsoft software updates, such as UEFI/BIOS updates. Luckily, DELL has a measure in place to temporarily disable BitLocker upon these updates.

Is there a noticeable performance impact when BitLocker is enabled on a computer?

There is a small performance overhead, often in single-digit percentages, which is relative to the throughput of the storage operations on which it needs to operateCPU utilization

Can I swap hard disks on the same computer if BitLocker is enabled on the operating system drive?

Multiple hard disks can be swapped on the same computer if BitLocker is enabled, but only if the hard disks are BitLocker-protected on the same computer. The BitLocker keys are unique to the TPM and the operating system drive.

I hope you found this blog post helpful on how to Deploy BitLocker on Windows Server. If you have any questions, please let me know in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Bitlocker, Enable BitLocker, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: How to Create Hyper-V Virtual Switch
Next Post: How to correctly disable BitLocker on Windows Server

Related Posts

  • BitLocker
    Hide Default BitLocker Drive Encryption item in Windows Windows Server
  • Capture 91
    How to install IIS Web Server on Windows Server Web Server
  • screenshot 2020 04 26 at 19.14.07
    Windows 2016 Servers do not show up on the WSUS console Windows Server
  • Distributed File System DFS
    All About Distributed File System Windows
  • Expired Evaluation Configuration Manager to Full Version
    Upgrade Expired Evaluation Configuration Manager to Full Version Windows Server
  • WindowsUpdatesDISM 1
    Determine Apps UWP and remove pre-provisioned Appx in Windows Windows Server

More Related Articles

BitLocker Hide Default BitLocker Drive Encryption item in Windows Windows Server
Capture 91 How to install IIS Web Server on Windows Server Web Server
screenshot 2020 04 26 at 19.14.07 Windows 2016 Servers do not show up on the WSUS console Windows Server
Distributed File System DFS All About Distributed File System Windows
Expired Evaluation Configuration Manager to Full Version Upgrade Expired Evaluation Configuration Manager to Full Version Windows Server
WindowsUpdatesDISM 1 Determine Apps UWP and remove pre-provisioned Appx in Windows Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • How to Enable or Disable Inherited Permissions for Files and Folders in Windows
    How to Enable or Disable Inherited Permissions for Files and Folders in Windows Windows
  • IIS Installed
    Add and remove IIS Web Server on Windows Server 2019 via the Server Manager and PowerShell Web Server
  • azure app service with office 365 and yammer sharepoint saturday florence 2015 session 8 638
    WordPress site on Azure: How to create a website hosted in Azure Oracle/MSSQL/MySQL
  • LAPs on Windows Part of the OS
    How to configure Windows LAPS Windows
  • Standby Mode
    Disable modern standby on Windows 10 and 11 Windows
  • Fixing TPM Vulnerability
    How to fix a vulnerable Trusted Platform Module [TPM] Windows
  • RUST FEATURE
    How to install Rust in a Linux System Linux
  • VBR upgrade
    Upgrade Veeam Backup and Replication to version 12.2 Backup

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,834 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.