XTS-AES 256 vS AES256

Santhosh B S 81 Reputation points
2021-03-09T17:14:28.527+00:00

Team,
we are moving from MBAM to Bitlocker MGMT policy. we have 2000 production win 10 laptops already MBAM encryption with AES 256 (GPO).
Need recommendation or best practice to move the Win10 machines to XTS-AES 256. Please help

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,760 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AliceYang-MSFT 2,081 Reputation points
    2021-03-10T03:17:39.287+00:00

    Hi,

    Changing the encryption method has no effect if the drive is already encrypted, or if encryption is in progress. So we need to decrypt laptops, change encryption method, then encrypt again.

    If BitLocker MGMT policy means using Configuration Manager to deploy BitLocker, please see Deploy BitLocker management.

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.