How to Enable BitLocker and FileVault and store their keys
How to enable FileVault on a MAC:
Open system settings (looks like a gear) and scroll down to “Privacy and Security” on the left-hand side. On the right-hand side, scroll to the bottom and select “FileVault” to turn it on. Click on the “Turn on” button. Choose “Create a recovery key and do not use my iCloud account”. It will present you with a recovery key that is like the one below.
EXAMPLE KEY: 3KMT-VL5N-2JPA-R3KN-OOMY-68HA
Capture this in a pic from a phone or a screenshot utility and place it in the SharePoint directory we have set up. Name it in the same format as seen below.
firstname lastname FileVault-mmddyyyy
How to recover a FileVault key on a MAC:
If FileVault has already been enabled and we do not have a key stored, open terminal (MAC version of command line) and type “sudo fdesetup changerecovery -personal” and hit enter. Enter the local admin password (likely the EU’s local MAC password) and hit enter. You will then enter the username (again likely the EU’s MAC username) and hit enter. Re-enter the local admin password and hit enter. This will present you with a recovery key like the one above in the first section. Capture this in a pic from a phone or a screenshot utility and place it in the SharePoint directory we have set up. Name it in the same format as seen below.
firstname lastname FileVault-mmddyyyy
How to enable BitLocker on a PC:
Open Control Panel and click on “System and Security”. Click on “BitLocker Drive Encryption” and “turn on BitLocker”. You will be prompted to choose how to unlock your drive at startup. Choose “Let BitLocker automatically unlock my drive”. Next, choose how you want to back up your recovery key. Choose the option to “print the recovery key” and print it to a PDF. Transfer that info to the SharePoint directory by uploading it to SharePoint.
** Capture the BitLocker key and name it in the same format as seen below.
firstname lastname (leave BitLocker key info in place here)-mmddyyyy
How to recover a BitLocker key on a PC:
If BitLocker has already been enabled and we do not have a key stored, Open Control Panel and click on “System and Security”. Click on “BitLocker Drive Encryption”. Choose “Back up your recovery key”. Choose the option to “print the recovery key” and print it to a PDF. Transfer that info to the SharePoint directory by uploading it to SharePoint.
** Capture the BitLocker key and name it in the same format as seen below.
firstname lastname (leave BitLocker key info in place here)-mmddyyyy