Bitlocker and Macrium. A Hypothetical (at this point) question.


Mooly

Well-known member
Member
VIP
Local time
9:24 AM
Posts
374
OS
W11 Pro x64 24H2 Dev
I use Bitlocker and Macrium without issue... Bitlocker is on 24/7 and it just all works perfectly, images and restores. All is good.

What would happen if...

I tried to restore a previous clean install of W11 that was at the time made with Bitlocker running?

For example if I did a 100% clean install every 6 months and then I wanted to restore a previous image would I get locked out by Bitlocker and be asked for the 48 digit key applicable to when that image was made? and perhaps more importantly then be locked out of the current image with that also requiring the current code.
 
Windows Build/Version
23H2

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
Hard to say.

Make sure you have both keys.

Frankly, I would first turn off Bitlocker on current installation, make an image backup as a precaution, then restore older image backup.

Then restore Bitlocker
 

My Computer

System One

  • OS
    Windows 10 Pro + others in VHDs
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook 14
    CPU
    I7
    Motherboard
    Yep, Laptop has one.
    Memory
    16 GB
    Graphics Card(s)
    Integrated Intel Iris XE
    Sound Card
    Realtek built in
    Monitor(s) Displays
    N/A
    Screen Resolution
    1920x1080
    Hard Drives
    1 TB Optane NVME SSD, 1 TB NVME SSD
    PSU
    Yep, got one
    Case
    Yep, got one
    Cooling
    Stella Artois
    Keyboard
    Built in
    Mouse
    Bluetooth , wired
    Internet Speed
    72 Mb/s :-(
    Browser
    Edge mostly
    Antivirus
    Defender
    Other Info
    TPM 2.0
I use Bitlocker and Macrium without issue... Bitlocker is on 24/7 and it just all works perfectly, images and restores. All is good.

What would happen if...

I tried to restore a previous clean install of W11 that was at the time made with Bitlocker running?

For example if I did a 100% clean install every 6 months and then I wanted to restore a previous image would I get locked out by Bitlocker and be asked for the 48 digit key applicable to when that image was made? and perhaps more importantly then be locked out of the current image with that also requiring the current code.

It always restores Windows with Bitlocker disabled. You will not get any errors.
 

My Computer

System One

  • OS
    Windows 11 Pro with Debian Linux in WSL 2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Build to Order machine
    CPU
    Intel Core i7-4790 (Haswell Refresh)
    Motherboard
    MSI Z97 Gaming 7
    Memory
    32 GB
    Graphics Card(s)
    GIGABYTE NVIDIA GeForce RTX 2060 GAMING OC PRO 6G
    Monitor(s) Displays
    LG 27GN650-B IPS HDR Gaming Monitor 27" FHD
    Screen Resolution
    1080p
    Hard Drives
    2 x Samsung 860 EVO SATA SSD 1TB
    1 x Samsung 870 EVO SATA SSD 2TB
    PSU
    Corsair 1000 Watt
    Case
    Corsair Obsidian Series 750D full tower ATX case
    Cooling
    CORSAIR Hydro Series H80i v2
    Internet Speed
    1 Gbps / 1 Gbps symmetrical FTTH (GPON)
    Browser
    Microsoft Edge
Thanks for your thoughts on this, it kind of feels a bit like uncharted territory at this point. I have keys for the current set up (printed in a safe place) but not for earlier installs. That's a mistake I won't make again.
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
Thanks for your thoughts on this, it kind of feels a bit like uncharted territory at this point. I have keys for the current set up (printed in a safe place) but not for earlier installs. That's a mistake I won't make again.
I have done it many times, it always restores with Bitlocker disabled.
 

My Computer

System One

  • OS
    Windows 11 Pro with Debian Linux in WSL 2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Build to Order machine
    CPU
    Intel Core i7-4790 (Haswell Refresh)
    Motherboard
    MSI Z97 Gaming 7
    Memory
    32 GB
    Graphics Card(s)
    GIGABYTE NVIDIA GeForce RTX 2060 GAMING OC PRO 6G
    Monitor(s) Displays
    LG 27GN650-B IPS HDR Gaming Monitor 27" FHD
    Screen Resolution
    1080p
    Hard Drives
    2 x Samsung 860 EVO SATA SSD 1TB
    1 x Samsung 870 EVO SATA SSD 2TB
    PSU
    Corsair 1000 Watt
    Case
    Corsair Obsidian Series 750D full tower ATX case
    Cooling
    CORSAIR Hydro Series H80i v2
    Internet Speed
    1 Gbps / 1 Gbps symmetrical FTTH (GPON)
    Browser
    Microsoft Edge
I have done it many times, it always restores with Bitlocker disabled.

Can you explain exactly what you're doing? In particular, which partitions are you restoring, and what's your procedure for both the backup and restore? There are subtleties to the OP's question, and I would ask him the same thing. For example, I use Terabyte's Image For Windows, and if I were to follow my normal procedure to restore the OS partition, and just the OS partition, I would boot into their WinRE environment, use manage-bde to unlock the Bitlockered OS partition, and restore my unencrypted OS image to it. Bitlocker would encrypt it on the fly, and I would boot into Windows with startup and auto-unlock keys all remaining valid, and Bitlocker enabled. If I hadn't used manage-bde, I'd have to re-encrypt the OS partition when I booted into Windows and use special measures to recover from the now invalid auto-unlock keys.

I hope this makes it clear why I'm puzzled by "always restores with Bitlocker disabled". That's the one thing I want to avoid with a passion. I'd guess there's a point where my normal method would fail, and I'd have to do a full restore including the hidden System partition that contains the Bitlocker startup stuff, but I've never encountered it. If that were to happen, whether Bitlocker is enabled or not would depend on whether the image was made with the OS partition locked or not. As I make all my backups within a live Windows session, the OS is imaged in the unencrypted state, so a full restore of the drive would remove the Bitlocker protection, as would any restore that skips the manage-bde step from my first paragraph. This would be avoided if I imaged the drive outside of Windows, but then I'd be backing up encrypted data, and the imaging software couldn't compress it and would have to back up unused sectors, so that's a non-starter.
 

My Computer

System One

  • OS
    Windows 11

My Computer

System One

  • OS
    Windows 10 Pro + others in VHDs
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook 14
    CPU
    I7
    Motherboard
    Yep, Laptop has one.
    Memory
    16 GB
    Graphics Card(s)
    Integrated Intel Iris XE
    Sound Card
    Realtek built in
    Monitor(s) Displays
    N/A
    Screen Resolution
    1920x1080
    Hard Drives
    1 TB Optane NVME SSD, 1 TB NVME SSD
    PSU
    Yep, got one
    Case
    Yep, got one
    Cooling
    Stella Artois
    Keyboard
    Built in
    Mouse
    Bluetooth , wired
    Internet Speed
    72 Mb/s :-(
    Browser
    Edge mostly
    Antivirus
    Defender
    Other Info
    TPM 2.0

My Computers

System One System Two

  • OS
    Windows 11 build 10.0.26635.3566 Beta
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 14 5430
    CPU
    Intel i7-1355U
    Motherboard
    Dell 0GMW80
    Memory
    16GB
    Graphics Card(s)
    Intel Iris XE
    Sound Card
    Realtek
    Monitor(s) Displays
    Dell 14" and LG Ultrawide 26"
    Screen Resolution
    1920 x 1200 and 2560 x 1080
    Hard Drives
    Samsung 990 Pro 1TB NVME Gen 4 M.2 SSD
    PSU
    Dell
    Case
    Dell
    Cooling
    Dell
    Keyboard
    Dell KM3322W
    Mouse
    Dell Trackpad or Dell KM3322W
    Internet Speed
    900mb down / 400mb up FTTP
    Browser
    Edge 124.0.2478.67 Beta
    Antivirus
    Windows Defender
    Other Info
    Windows 365
    1TB OneDrive
    Outlook
    Visual Studio Code
    Visual Studio
    Python 3.12.2
    Macrium Reflect
    Dell Update
    MyDell
    Dell SupportAssist
    Dell TB16 Thunderbolt dock
  • Operating System
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface Pro 7
    CPU
    Core i5 - 1035G4
    Motherboard
    Microsoft
    Memory
    8GB
    Graphics card(s)
    Intel Iris Plus
    Monitor(s) Displays
    Surface touch
    Screen Resolution
    2736 x 1824
    Hard Drives
    128GB
    PSU
    Microsoft
    Case
    Microsoft Keyboard
    Cooling
    None
    Mouse
    Microsoft Arc Intellimouse
    Keyboard
    Microsoft Surface Keyboard
    Internet Speed
    900mb / 400mb FTTP
    Browser
    Edge
    Antivirus
    Windows Defender
Never had an issue with restoring from Macrium with Bitlocker on. The default settings on Macrium tells you it's going to disable Bitlocker and then just restores the image with no fuss or drama.
Never claimed there were issues - it was the statement that restores are always unencrypted that was wrong.

E.g. if you backup an encrypted partition and restore it on a different pc, without selecting option to unlock it, the new partition is still bitlocked.
 

My Computer

System One

  • OS
    Windows 10 Pro + others in VHDs
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook 14
    CPU
    I7
    Motherboard
    Yep, Laptop has one.
    Memory
    16 GB
    Graphics Card(s)
    Integrated Intel Iris XE
    Sound Card
    Realtek built in
    Monitor(s) Displays
    N/A
    Screen Resolution
    1920x1080
    Hard Drives
    1 TB Optane NVME SSD, 1 TB NVME SSD
    PSU
    Yep, got one
    Case
    Yep, got one
    Cooling
    Stella Artois
    Keyboard
    Built in
    Mouse
    Bluetooth , wired
    Internet Speed
    72 Mb/s :-(
    Browser
    Edge mostly
    Antivirus
    Defender
    Other Info
    TPM 2.0

Latest Support Threads

Back
Top Bottom