Information
This policy setting configures the encryption type (space only and whole) used by BitLocker Drive Encryption.
The recommended state for this setting is: Enabled: Used Space Only encryption or Enabled: Full encryption
Note: Changing the encryption type does not affect drives that are already encrypted or if encryption is in progress.
Note #2: If the option
full encryption
is selected, the entire drive be encrypted. If the option
used space only encryption
is selected, only the portion of the drive used to store data will be encrypted.
The type of encryption (used space only or full) used by BitLocker should be an organizational decision and not an end user decision.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Used Space Only encryption or Full encryption
Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives\Enforce drive encryption type on operating system drives: Select the encryption type: (Device)
Impact:
An organization will have to choose which method is used when BitLocker is enabled. The end user will not be able to choose the encryption type.
Note: This policy is ignored when shrinking or expanding a volume, and BitLocker uses the current encryption method. Example: When a drive uses
Space Only encryption
and is expanded, the new free space isn't wiped as it is for a drive that uses
Full encryption
.