Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form

Install BitLocker on Windows Server via the Server Manager

Posted on 13/11/202319/12/2023 IT Expert By IT Expert No Comments on Install BitLocker on Windows Server via the Server Manager
  1. Home
  2. Windows Server
  3. Install BitLocker on Windows Server via the Server Manager
Deploy-BitLocker-on-Windows-Server-manually

BitLocker Drive Encryption enables you to protect data on lost, stolen or inappropriately decommissioned devices by encrypting the entire volume and checking the integrity of early boot components. These data can only be decrypted if all the components are successfully verified and the encrypted drive is located in the original PC. In this article, we shall learn how to Install BitLocker on Windows Server via the Server Manager. Please see How to Disable BitLocker on Windows 10, and How to Change BitLocker Password in Windows.

For all Windows Server editions, BitLocker isn’t installed by default, but it can be installed using Server Manager or Windows PowerShell cmdlets. Administrative rights are required to perform this task.

Note: Integrity checking requires a compatible TPM module for your device. You may want to see how to disable Lock Screen on Windows 10 via Registry Editor, and how to Backup existing and new BitLocker Recovery Keys to Active Directory.

Step 1: Install BitLocker on Windows Server

Open the server manager by selecting the server manager icon or running servermanager.exe. Oftentimes, this wizard opens automatically,

Select Manage from the Server Manager Navigation bar and select Add Roles and Features to start the Add Roles and Features Wizard.

Alternatively, from the Server Manager dashboard, you could select Add roles and features as shown below.

Roles-and-features

With the Add Roles and Features wizard open, select Next at the Before you Begin pane if shown.

Skip-Before-you-begin

Select Role-based or feature-based installation on the Installation type pane of the Add Roles and Features wizard and select Next to continue.

Role-or-feature-Based-Installation

Select the Select a server from the server pool option in the Server Selection pane.

Select-server-to-install-BitLocker-features
Note: Server roles and features are installed by using the same wizard in Server Manager.

Select Next on the Server Roles pane of the Add Roles and Features wizard to proceed to the Features pane. 

Select the check box next to BitLocker Drive Encryption within the Features pane of the Add Roles and Features wizard.

Drive-ecryption-features

Note: The Enhanced Storage feature is a required feature for enabling BitLocker. This feature enables support for encrypted hard drives on capable systems.

Enhanced-Stored-features

The BitLocker features and the Enhanced Storage have been selected.

BitLocker-features-installed

Before proceeding with this step, you may want to learn about Microsoft BitLocker Administration and Management (MBAM).

Install BitLocker

Select Install on the Confirmation pane of the Add Roles and Features wizard to begin the BitLocker feature installation.

If you want the server to restart automatically, check the box close to the “restart the destination server automatically if required”.

This forces a restart of the computer after installation is complete. At this time, I will not check it just to show you that it does require a RESTART of the Windows Server.

Install-BitLocaker-unto-Windows-Server

BitLocker is installing

BitLocker-feature-is-being-installed

If the Restart the destination server automatically if the required check box isn’t selected. The Results pane of the Add Roles and Features wizard displays the success or failure of the BitLocker feature installation. Please restart your server.

BitLocker-and-Enhanced-storage-installed
Please proceed and have your server restarted.
Screenshot-2023-11-13-at-20.02.57

Also, see how to fix “Cannot open Bluetooth preference pane because it is not available“, How to Create Hyper-V Virtual Switch, and How does Key Rotation work in MBAM?

To install BitLocker on Windows Server using Windows PowerShell

Windows PowerShell offers administrators an option for BitLocker feature installation. The server must be restarted to complete the installation of BitLocker. I will not be discussing these steps as the focus is on Server Manager. Here is how this BitLocker can be installed with Powershell.

Installing the BitLocker feature using Windows PowerShell does not install the Enhanced Storage feature. Administrators wishing to support Encrypted Hard Drives in their environment will need to install the Enhanced Storage feature separately

Using the DISM module to install BitLocker

With the dism.exe Windows PowerShell module uses the Enable-WindowsOptionalFeature cmdlet to install features. Learn how to install BitLocker with DISM.

Step 2: Turn on BitLocker using Windows Explorer

It is interesting to note that this option is available on client computers by default. On servers, the BitLocker feature and the Desktop-Experience feature must first be installed for this option to be available.

After the server reboots, you can use BitLocker. To enable BitLocker on Windows Server, kindly proceed with the steps below.

Windows Explorer allows you to launch the BitLocker Drive Encryption Wizard by right-clicking a volume and selecting Turn On BitLocker.

Turn-on-BitLocker-

This will check for the PC configuration. This process can take a while to complete. Sit back and relax.

Checking-PC-configuration

Proceed with the BitLocker Drive Encryption setup by clicking on Next

BitLocker-Drive-Encryption-setup

Click on Next to proceed as well.

BitLocker-encryption

The volume is shrunk as shown below.

encryption-in-progress

Encrypt the drive

Encrypt-Drive

Choose how to unlock the drive at Startup. I will select the second option as shown below.

Choose-method-of-startup-unlock

Enter a Password

Important: Removable data drives can be unlocked using a smart card. A SID protector can also be configured to unlock a drive by using user domain credentials. After encryption has started, the drive can also be automatically unlocked on a specific computer for a specific user account.

Enter-a-Password

I will select the second option to have the entire drive encrypted.

Encrypt-entire-drive

On the Ready for BitLocker Encryption? click on continue.

The "run BitLocker System Check" is selected by default. You can choose to deselect this.
Ready-for-BitLocker-Encryption-Ru-BitLocker-System-Check

You will be notified that BitLocker will start shortly after the PC is restarted.

PC-restart-to-enable-BitLocker

Unlock BitLocker Drive Encryption

To UnLock BitLocker Drive Encryption, enter the password you entered above.

UnLock-BitLocker-Drive-Encryption

Encryption has started

Volume-encrypted

Verify BitLocker Encryption

To verify the BitLocker status of a particular volume. Administrators can look at the status of the drive in the BitLocker Control Panel applet, Windows Explorer, manage-bde.exe command-line tool, or Windows PowerShell cmdlets. Each option offers different levels of detail and ease of use.

Determine the current state of a volume you can use the Get-BitLockerVolume cmdlet, which provides information on the volume type, protectors, protection status, and other details.

Check-BitLocker-Status-via-PowerShell

With manage-bde.exe you can determine the volume status on the target system

verifiy-BitLocker-Encryption-via-Command-Prompt

Process can take a while and encryption times vary depending on the type of drive that is being encrypted, the size of the drive, and the speed of the drive. If encrypting large drives, encryption may want to be scheduled during times when the drive isn’t being used.

Also, see how to check if Microsoft BitLocker Administration and Monitoring is installed on Windows, and how to Fix no BitLocker Recovery tab in Active Directory.

FAQs on Deploying BitLocker

Do I have to suspend BitLocker protection to download and install system updates and upgrades?

No user action is required for BitLocker in order to apply updates from Microsoft, including Windows quality updates and feature updates. Users need to suspend BitLocker for non-Microsoft software updates, such as UEFI/BIOS updates. Luckily, DELL has a measure in place to temporarily disable BitLocker upon these updates.

Is there a noticeable performance impact when BitLocker is enabled on a computer?

There is a small performance overhead, often in single-digit percentages, which is relative to the throughput of the storage operations on which it needs to operateCPU utilization

Can I swap hard disks on the same computer if BitLocker is enabled on the operating system drive?

Multiple hard disks can be swapped on the same computer if BitLocker is enabled, but only if the hard disks are BitLocker-protected on the same computer. The BitLocker keys are unique to the TPM and the operating system drive.

I hope you found this blog post helpful on how to Deploy BitLocker on Windows Server. If you have any questions, please let me know in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Bitlocker, Enable BitLocker, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: How to Create Hyper-V Virtual Switch
Next Post: How to correctly disable BitLocker on Windows Server

Related Posts

  • Could not load file or assembly
    Unable to edit MDT XML unattended file: Could not load file Windows Server
  • image 30
    How to Fix “Insufficient System Resources Exist to Complete the Requested Service” error Windows
  • Connect to FTP Server
    Secure FTP Login Issue: NAT Router Configuration for Passive Mode and Port Forwarding Windows Server
  • Banner
    Enabling and Configuring WinRM via GPO Windows
  • maxresdefault
    How to join a computer to the Domain Windows Server
  • His May Be The Server Does Not Exist
    Fix unable to contact Server: This may be the server does not exist Windows Server

More Related Articles

Could not load file or assembly Unable to edit MDT XML unattended file: Could not load file Windows Server
image 30 How to Fix “Insufficient System Resources Exist to Complete the Requested Service” error Windows
Connect to FTP Server Secure FTP Login Issue: NAT Router Configuration for Passive Mode and Port Forwarding Windows Server
Banner Enabling and Configuring WinRM via GPO Windows
maxresdefault How to join a computer to the Domain Windows Server
His May Be The Server Does Not Exist Fix unable to contact Server: This may be the server does not exist Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • cisco asa 5505 adaptive security appliance desktop firewall 10 100 47 18790 04 56708 pekm1000x469ekm
    Administer Cisco ASA: Mastering CLI Management Network | Monitoring
  • Slide1 1
    Enable or disable Secure Boot in Windows via UEFI Firmware Settings Windows
  • a Multiple SPF Records  Issues and Examples@2x
    How to setup SPF and TXT Records in AWS AWS/Azure/OpenShift
  • Windows10 11
    Block Upgrade to Windows 11 via Group Policy or Registry Windows
  • veeam and wasabi
    Modern Backup Strategy with Veeam and Wasabi: Truly Immutable Network | Monitoring
  • Zit Error
    How to fix Domain Join Error during Windows Deployment Windows Server
  • Was ist Windows Server und wie unterscheidet er sich vom normalen Windows
    Create a certificate template for BitLocker Network Unlock Windows Server
  • Fatory Reset Or Reinatall Windows Server
    Reset or reinstall Windows Server without deleting the VM Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,801 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.