Cloning drive with BitLocker unlocked on a new drive


hexaae

Crazy bug-hunter
Member
VIP
Local time
11:47 AM
Posts
115
Location
Italy
OS
Windows 11 Home
I have C: on my source NVMe drive I want to replace, which is BitLocker enabled but UNLOCKED (grey icon).

1733925408374.webp

Can I clone this drive to the new NVMe (Macrium Reflect 8 says it will be copied without BitLocker) and just boot from the new drive? Do I need to enable BitLocker again on the cloned drive and then unlock it again before I swap the old -> new drive?

Macrium web page is not that clear about this topic in the "BitLocker Removal Restore/Clone" section saying: "Outcome: The entire file system is restored in the clear and BitLocker must be manually re-enabled on the restored/cloned file system."; "must" = "if you want BitLocker again"?
The simple question is: will the new one boot, just swapping the drive? Or I "MUST" re-enable first BitLocker on the new cloned drive for C: partition?

Windows 11 24H2, NVMe drives, Macrium Reflect 8 (Registered).
 
Windows Build/Version
24H2

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller
Seems pretty explicit:
Outcome: The entire file system is restored in the clear.


Why would you want to enable BitLocker prior to cloning if you do not have it enabled now?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & IGB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 13 (Trixie)
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
So the new drive will be just without BitLocker... but this new drive should boot up and work fine (without BitLocker), right?
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller
I would make 100% sure you have the original BitLocker keys accurately written down, then there are no surprises if you find the cloned drive locked when you don't expect it to be. Write the keys down for all drives concerned.

Is 'unlocked' the same as 'off' is what I'm thinking.
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
I would make 100% sure you have the original BitLocker keys accurately written down, then there are no surprises if you find the cloned drive locked when you don't expect it to be. Write the keys down for all drives concerned.

Is 'unlocked' the same as 'off' is what I'm thinking.
Yep... people often says BitLocker Off but it's never clear if they mean BitLocker enabled but unlocked (grey icon), or without BitLocker.
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller
So the new drive will be just without BitLocker... but this new drive should boot up and work fine (without BitLocker), right?
Why wouldn'it?
Unless the image is corrupted.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & IGB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 13 (Trixie)
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
No it's ok if the new cloned drive will be without BitLocker. Just wanted to be sure not to be locked out and avoid problems, and be able to boot right away from the new drive without BitLocker issues... ;-)
That "you must manually re-enable BitLocker" in Macrium docs can be confusing.

(Of course I've written down my BitLocker keys from Sign in to your account just to be safe)
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller
No it's ok if the new cloned drive will be without BitLocker. Just wanted to be sure not to be locked out and avoid problems, and be able to boot right away from the new drive without BitLocker issues... ;-)
That "you must manually re-enable BitLocker" in Macrium docs can be confusing.
All it means is this:
If you leave your front door unlocked after leaving the house, make sure you lock it again behind you when you return in order to secure your home.:wink:
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & IGB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 13 (Trixie)
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
Ok, sorry but it's first time (24H2 forced it!) I have to clone a BitLocker enabled but unlocked drive and wanted to be 100% sure.

All my concerns came from the fact that BitLocker enabled but unlocked (grey icon) means the drive is accessible but still encrypted... while without icon at all = not even encrypted, and wanted to be sure it can't be a problem when swapping to the new cloned drive (with no BitLocker at all and no icon).
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller
Ok, sorry but it's first time (24H2 forced it!) I have to clone a BitLocker enabled but unlocked drive and wanted to be 100% sure.

All my concerns came from the fact that BitLocker enabled but unlocked (grey icon) means the drive is accessible but still encrypted... while without icon at all = not even encrypted, and wanted to be sure it can't be a problem when swapping to the new cloned drive (with no BitLocker at all and no icon).
There is only one way to find out.
Besides you will still have the old drive to fall back on in case of an issue.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & IGB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 13 (Trixie)
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
Have a read at post #68 here. I remembered this from a few months back:

POST #68
 

My Computer

System One

  • OS
    W11 Pro x64 24H2 Dev
    Computer type
    Laptop
    Manufacturer/Model
    Dell 7760 Mobile Precision 17"
    CPU
    Intel i5
    Motherboard
    Unknown
    Memory
    8Gb
    Graphics Card(s)
    Intel HD Graphics
    Sound Card
    Realtek
    Monitor(s) Displays
    Internal
    Hard Drives
    2 x 256Gb SSD
    PSU
    Dell 240 watt
    Mouse
    Dell Premier Bluetooth
    Internet Speed
    50Mbps
    Browser
    Edge
    Antivirus
    Default Microsoft Security
...To sum up, reading from various sources, this is the situation (more advanced users on this argument, please correct me if I'm wrong):

1733949914807.webp
What do these hard drive icons mean? - The Old New Thing (icons are Win10 style in this pic, still very similar to Win11's though)

So... if you clone an old drive with C: partition with BL (BitLocker) enabled and unlocked (grey icon, "Unlocked padlock"): BL working, encryption enabled, but auto-unlocked on boot to access the drive) --> new drive with cloned C: without BitLocker (no BL icon at all, "System drive" from pic above) you will have no problems wherever you mount the unit. TPM 2.x chip on your PC will still retain the old BL key for C: from the old drive, so you can even re-mount the old drive with BL enabled and it will be auto-unlocked (grey icon) on boot, just like it was before cloning. To be short, you can actually interchange drives: old with BL enabled, or new without BL.
BUT... at this point if you enabled BL (and auto-unlock to access the drive on boot) on the new cloned drive, a new BL key will be generated and stored in TPM (and added to your device in your MS online account) replacing old C: BL key for current boot drive (which is the new one with new BL key). This means that from now on, to access your old drive where BL was enabled (in the same PC port or in an external enclosure), you'll have to recover and enter your old BL key associated with that drive/partition to unlock it (will appear with yellow "Locked padlock" icon 'till you unlock it)!
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    Laptop
    Manufacturer/Model
    ASUS ROG SCAR 18
    CPU
    Intel i9-13980HX
    Memory
    32GB DDR5 5600MHz
    Graphics Card(s)
    NVidia GTX 4090 Laptop 256bit 16GB 175W
    Sound Card
    Realtek ALC285 + Dolby Atmos
    Monitor(s) Displays
    G-Sync NE180QDM-NZ2 18" 16:10, FreeSync Premium XiaoMi Mi 34" 21:9
    Screen Resolution
    2560x1600@240Hz (internal), 3440x1440@144Hz (external)
    Hard Drives
    NVMe Lexar NM790 1TB 6GB/s, NVMe Lexar NM790 4TB 6GB/s
    PSU
    330W (laptop PSU)
    Mouse
    ROG Strix Carry Wireless-BT mouse
    Other Info
    4K UHD USB Archgon Star Blu-Ray 4K UHD,
    8BitDo Arcade Stick,
    Vader 4 Pro controller

Latest Support Threads

Back
Top Bottom