Which backup strategy for encrypted Windows?


Garlin makes a great point. The encryption routines are not at all computationally difficult for the CPU because it has built-in hardware functions for those tasks. This is very similar to the dedicated hardware for video compression and decompression (quick sync) on Intel CPUs. Because it is dedicated hardware, I find that my lowly little N100 CPU can compress video almost just as fast as my i7 CPU. Same for the BitLocker encryption / decryption.
 

My Computers My Computers

  • At a glance

    Win11 Pro 26H2 (Release Preview)Intel i7-14650HX32 GBNo GPU - Built-in Intel Graphics
    OS
    Win11 Pro 26H2 (Release Preview)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Acemagic Matrix M5
    CPU
    Intel i7-14650HX
    Memory
    32 GB
    Graphics Card(s)
    No GPU - Built-in Intel Graphics
    Sound Card
    Integrated
    Monitor(s) Displays
    Varies as machine will often be moved to locations with different monitors
    Screen Resolution
    Varies
    Hard Drives
    1 x 1TB Gen 4 NVMe SSD
    PSU
    120W Power Brick
    Keyboard
    Corsair K70 Max RGB Magnetic Keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
  • At a glance

    Win11 Pro 26H2 (Release Preview)Intel i7-1255U16 GBIntel Iris Xe Graphics
    Operating System
    Win11 Pro 26H2 (Release Preview)
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    4 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging Using an Anker 160W Charger
    Keyboard
    Backlit, spill resistant keyboard
    Mouse
    Buttonless Glass Precision Touchpad
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
May I ask why you don't perform hot backups
Byte-for-Byte comparison.

Live data changes constantly...offline is static.

If you're looking for a free solution, Hasleo is pretty popular here.
 

My Computer My Computer

At a glance

Windows 11 Pro 25H2
OS
Windows 11 Pro 25H2
Computer type
Laptop
Manufacturer/Model
Toshiba
BL adds a negligible overhead unless you changed the default encryption method to a more expensive algorithm. Data is encrypted across individual blocks as needed, and not chained across a file or volume.

If your processes are pounding the disk to death, then obviously you'll notice a performance hit.
i have slow disks so every byte/second counts. *LOL*😁 (SSD over Sata3)
 

My Computers My Computers

  • At a glance

    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...
    OS
    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
    Manufacturer/Model
    HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
    CPU
    i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
    Hard Drives
    Sata, M.2, SAS
  • At a glance

    Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core
    Operating System
    Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
    Manufacturer/Model
    Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
    CPU
    Oldest intel 8088 up to P4 dual core
    Hard Drives
    MFM, IDE, SCSI
Byte-for-Byte comparison.

Live data changes constantly...offline is static.

If you're looking for a free solution, Hasleo is pretty popular here.

If you are talking about a byte perfect replica of the entire disk including unused blocks, then yes, the only way to get a byte perfect replica of the entire disk is by performing an offline backup.

But an online backup does make a byte perfect backup of the used portion of the disk. No changes that are made while the backup is taking place are included in the backup due to the use of snapshots.

Normally, an online backup is all that is needed. The only real reason to make a byte perfect backup of the ENTIRE disk is for forensic recovery of data that was previously "deleted" but still physically present on the disk.

I'd be curious to know why you would possibly need to make a byte perfect replica of the entire disk, if that is what you are doing. Maybe I can learn something that I was not aware of although I think that extremely unlikely :-)
 

My Computers My Computers

  • At a glance

    Win11 Pro 26H2 (Release Preview)Intel i7-14650HX32 GBNo GPU - Built-in Intel Graphics
    OS
    Win11 Pro 26H2 (Release Preview)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Acemagic Matrix M5
    CPU
    Intel i7-14650HX
    Memory
    32 GB
    Graphics Card(s)
    No GPU - Built-in Intel Graphics
    Sound Card
    Integrated
    Monitor(s) Displays
    Varies as machine will often be moved to locations with different monitors
    Screen Resolution
    Varies
    Hard Drives
    1 x 1TB Gen 4 NVMe SSD
    PSU
    120W Power Brick
    Keyboard
    Corsair K70 Max RGB Magnetic Keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
  • At a glance

    Win11 Pro 26H2 (Release Preview)Intel i7-1255U16 GBIntel Iris Xe Graphics
    Operating System
    Win11 Pro 26H2 (Release Preview)
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    4 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging Using an Anker 160W Charger
    Keyboard
    Backlit, spill resistant keyboard
    Mouse
    Buttonless Glass Precision Touchpad
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
I'd be curious to know why you would possibly need to make a byte perfect replica of the entire disk, if that is what you are doing. Maybe I can learn something that I was not aware of although I think that extremely unlikely :-)
I can give you one exception of the rule. 🤓

But i would never work with whole disks or even whole partitions.. i would work with encrypted containers as it saves a bit of space.

So.. The only one i can think of is you have sensitive data and you are using a cloud provider for backups.. but you dont really trust that provider to deliver a true 100% end-to-end encryption (zero knowledge) and your data is to valuable if it ever would happen a data breach.
Then you backup the disk/partition/container in its encrypted state.. as it is encrypted even empty space will be seen as used space as it is encrypted. (or the unusual wording bit by bit)

That is the only exception to that rule i can think of. :-)
when we talk data backup only and not recovery etc.
 

My Computers My Computers

  • At a glance

    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...
    OS
    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
    Manufacturer/Model
    HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
    CPU
    i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
    Hard Drives
    Sata, M.2, SAS
  • At a glance

    Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core
    Operating System
    Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
    Manufacturer/Model
    Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
    CPU
    Oldest intel 8088 up to P4 dual core
    Hard Drives
    MFM, IDE, SCSI
Typically, BitLocker isn't disabled, but merely suspended. That means that data is still being written to the disk with encryption, but the key to access that data is "in the clear." So, applications, including backup applications, can read the data as if the drive wasn't encrypted. Later, BitLocker can be resumed (un-suspended), and the key is no longer available in the clear. There's no decryption and re-encryption of your data taking place.
That was already clear to me (I think, at least). However, I don't understand the difference between a hot backup and a cold backup regarding the matter of BitLocker suspension. What exactly happens in the hot backup compared to the cold one? I’m referring to what is written in Banjoman301’s table at post #6.


If you do image Bitlocker encrypted drives then (imo) you absolutely must copy the recovery keys to all drives or partitions and store them safely such as on paper somewhere. You can also store them in your Microsoft account with one click.
Yes, that is obvious, i fact I have already saved the BitLocker key on paper too. My doubt is whether it is better to copy the partition exactly as it is, and therefore in an already encrypted form, or whether it is better to do it by letting the image be encrypted by the backup program’s encryption.

As to the question though, using Macrium it is seamless, you are not even aware Bitlocker is in the mix. Any restore automatically applies Bitlocker settings, there is nothing you need to do.
My question concerns this scenario: the partition becomes irretrievably corrupted. I obviously have the saved BitLocker key and a system backup (this raises the previous question: is it better to have a system image or an image of the entire partition?). How do I restore the backup to return everything to exactly how it was before? How to do exactly?


If you backup offline you will need to either perform a forensic backup or suspend BitLocker on a temporary basis first.
Based on what pseymour said, BitLocker is already suspended even while the system is booted up, meaning while Windows is running. I’m confused now: what exactly does "cold backup" mean? What exactly does suspending BitLocker mean? What do I need to do manually?


Sorry for my doubts.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
That was already clear to me (I think, at least). However, I don't understand the difference between a hot backup and a cold backup regarding the matter of BitLocker suspension. What exactly happens in the hot backup compared to the cold one? I’m referring to what is written in Banjoman301’s table at post #6.



Yes, that is obvious, i fact I have already saved the BitLocker key on paper too. My doubt is whether it is better to copy the partition exactly as it is, and therefore in an already encrypted form, or whether it is better to do it by letting the image be encrypted by the backup program’s encryption.


My question concerns this scenario: the partition becomes irretrievably corrupted. I obviously have the saved BitLocker key and a system backup (this raises the previous question: is it better to have a system image or an image of the entire partition?). How do I restore the backup to return everything to exactly how it was before? How to do exactly?



Based on what pseymour said, BitLocker is already suspended even while the system is booted up, meaning while Windows is running. I’m confused now: what exactly does "cold backup" mean? What exactly does suspending BitLocker mean? What do I need to do manually?


Sorry for my doubts.
What they mean is Hot backup is you are logged in and the disk/data is decrypted, and you copy the information in a decrypted state... Cold is the disk is in encrypted mode so you cant see/get to the information in clear text and you copy information in an encrypted state.
That is how i understand their expression even i dont see that expressions commonly used.

(partition becomes irretrievably corrupted) that expression i take as you mean the disk cant be decrypted, and the information is lost.
This can happen, but is really rare. if you have "20 million sectors" on the disk and the chance of a bit-flip(bit-rot) hitting the exact sector where the key is, is really low.. its not common with bit-rot/bit-flip on disks or corrupted sectors..
But this is why you have at least 3 sets of data. On the device, external offline disk and offsite.

Note to keep in mind.. Data-recovery is almost zero chance of success on encrypted drives.
So if your data isn't sensitive, i recommend you back it up without encryption.
If you have both non-sensitive and sensitive data... then you can backup non as decrypted and the sensitive as encrypted.. or all encrypted. Just remember what i said about Data recovery on encrypted disks

There is a saying... don't make it more complicated then it's need to be. :-)
as more complexity you add, as easier it can fail
 

My Computers My Computers

  • At a glance

    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...
    OS
    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
    Manufacturer/Model
    HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
    CPU
    i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
    Hard Drives
    Sata, M.2, SAS
  • At a glance

    Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core
    Operating System
    Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
    Manufacturer/Model
    Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
    CPU
    Oldest intel 8088 up to P4 dual core
    Hard Drives
    MFM, IDE, SCSI
What they mean is Hot backup is you are logged in and the disk/data is decrypted.. Cold is the disk is in encrypted mode so you cant see/get to the information in clear text.
That is how i understand their expression even i dont see it used anywhere else.
Yes, that’s how I understood it too, but I believe that in most cases backups are performed "live" (or "hot"), and that is specifically what I am referring to. However, the table in post #6 is a bit confusing to me regarding the activation/suspension of BitLocker. If a system is powered off (offline)—and I therefore need to create a forensic image of an encrypted partition—what is the point of talking about suspending BitLocker?

(partition becomes irretrievably corrupted) that expression i take as you mean the disk cant be decrypted, and the information is lost.
This can happen, but is really rare. of you have 20 million sectors on the disk and the chance of a bit-flip(bit-rot) hitting the exact sector where the key is, is really low.. its not common with bit-tot/bit-flip on disks or corrupted sectors..
But this is why you have at least 3 sets of data. On the device, external offline disk and offsite.
This just happened to me—without the slightest idea about why—on the Linux partition after a Windows update. All the data on it is lost. Obviously, that partition will need to be reformatted and the system reinstalled. I already had important file under external backup.

Note to keep in mind.. Data-recovery is almost zero chance of success on encrypted drives.
So if your data isn't sensitive, i recommend you bach it up without encryption.
If you have both non-sensitive and sensitive data.
Certainly. But my backups always contain sensitive data: work documents, personal photos, sensitive information, and so on. Of course I don't create encrypted backups of software.

There is a saying... don't make it more complicated then it's need to be. :-)
as more complexity you add, as easier it can fail
I agree. In my case, however – keeping in mind I cannot do without encryption – I am looking for the simplest, free solution for backups.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Yes, that’s how I understood it too, but I believe that in most cases backups are performed "live" (or "hot"), and that is specifically what I am referring to. However, the table in post #6 is a bit confusing to me regarding the activation/suspension of BitLocker. If a system is powered off (offline)—and I therefore need to create a forensic image of an encrypted partition—what is the point of talking about suspending BitLocker?


This just happened to me—without the slightest idea about why—on the Linux partition after a Windows update. All the data on it is lost. Obviously, that partition will need to be reformatted and the system reinstalled. I already had important file under external backup.


Certainly. But my backups always contain sensitive data: work documents, personal photos, sensitive information, and so on. Of course I don't create encrypted backups of software.


I agree. In my case, however – keeping in mind I cannot do without encryption – I am looking for the simplest, free solution for backups.
I have never used bitlocker and i never will, even if i start using Windows as Daily driver in the future. The same for Linux, i never use LUKS
I use VeraCrypt as it is cross platform its nice to have smooth access even if i want to access the data from Linux or a Windows machine.

I dont remember if it was in this thread or another thread, where i mention i dont encrypt my system partition.. C: (windows) or, / (Linux). I never store personal data on system partitions, just in case of a complete system breakdown, then i dont have to extract data before i wipe and restore. and i also gain a bit of disk speed when the system partition isn't encrypted.

I have a lot of data that goes from, i can share it with you i dont even know, to personal things as photos, diaries, notes, up to it actually goes under stamped as secret documents so i need to keep it device isolated and work with it totally offline. So i understand the need of encryption.
But i use VeraCrypt containers for things that is sensitive instead of encrypted disks or partitions. Its easy to work with as i can easy move the data in it's encrypted state.. or i can access the data from Windows/Linux/MacOS.
So if you dualboot or have windows and Linux machines.... give it a thought of my workflow. :-)

To keep duplicates of my data i use FreeFileSync its also cross platform software.
For disk images and quick restore of my OS's partitions i use CloneZilla.... But then i dont use Disk-encryption. As far i know CloneZilla dont do bitlocker partitions unless you do a sector-by-sector cloning that is just waste of space.. as the image almost becomes as big as the partition/disk you just cloned even if the partition only had 10% data and 90% free space.
 

My Computers My Computers

  • At a glance

    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...
    OS
    Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
    Manufacturer/Model
    HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
    CPU
    i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
    Hard Drives
    Sata, M.2, SAS
  • At a glance

    Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core
    Operating System
    Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
    Manufacturer/Model
    Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
    CPU
    Oldest intel 8088 up to P4 dual core
    Hard Drives
    MFM, IDE, SCSI
Hi everyone.
As mentioned in the subject, I have a Windows 11 system encrypted with BitLocker.
What is the best software for backing up and restoring an encrypted system? Would you clone the entire system or just the partition, or could the encryption cause issues during restoration?

I've used Image for Windows ever since moving from TrueCrypt to BitLocker in May 2014, and actually a few years before that. TeraByte has a good article on the subject here:


Myself, I backup the entire system drive from live Windows, so it's backed up in the unencrypted state. (I back up to a BitLockered drive, so I don't lose security.) This allows compression and discarding unused parts of the drive and things like the pagefile and hibernation file, just like imaging a system that doesn't use BitLocker. When I restore an image, it's typically just the Windows partition itself (not the boot or WinRE or Microsoft reserved), and that has to be done from TeraByte's WinRE recovery environment, TBWinRE. Before rebooting into it, I suspend BitLocker on the Windows drive, so it shows up unencrypted in TbWinRE without having to use manage-bde to unlock it. However, BitLocker is still active, and restoring to that partition results in BitLocker encrypting it on the fly during the restore. This means that when I boot back into Windows, it's encrypted like it was before, and I don't have to re-enable BitLocker. This avoids potential data leakage, and importantly, I avoid issues with auto-unlock drives, which become invalidated and require some extra steps to fix if BitLocker has to be re-enabled once I'm back into Windows.

Terminology notes: "Suspending" BitLocker makes it so that you don't have to authenticate to access your encrypted data. It's done temporarily to remove friction across reboots and is instantaneous. The data remains encrypted, and BitLocker continues to encrypt newly written data. "Disabling" Bitlocker means removing the encryption, i.e. decrypting, which requires rewriting all the data and thus tends to take a long time.

That's for system images. For file-based data backups, I use SyncBackPro.
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Back
Top Bottom