Saturday, 19 May 2012

Refreshing a BitLocker Enabled computer

In the scenario when you have BitLocker enabled and you need to refresh the computer, meaning you want to reimage the computer without wiping the disk, you will need to disable BitLocker in the OS drive, target the Apply Operating System Image step to the correct disk and partition and then Enable bitlocker again. The BDE partition will be untouched. These are the steps I will show you in this post.

First create a Disable Bitlocker step in your Task Sequence and choose the Current operating system drive as the target.



Now in the Apply Operating System Image select Specific disk and partition as the Destination and here in my case I will select Disk 0 Partition 2 that's where the OS is installed.



You can find out what's the disk and partition the OS is installed in your environment with diskpart.

The partition numbers depends how you Enabled Bitlocked the first time. If you formatted the disk and then partitioned it to Bitlocker then the partition 1 will be the BDE partition and the partition 2 will be the OS partition otherwise if you partitioned it after installing the OS then it will be the opposite. 

In the Task Sequence example the OS is installed in partition 2 so the creation of the BitLocker partition happened before the OS was installed.

In the example below the partitioning happened after the OS was installed.




Then finaly we re-Enable BitLocker choosing the Current operating system drive. The other options are up to you requiments.



No comments:

Post a Comment