Microsoft BitLocker Room for Improvement

SK
Vice President at Sysnet Global Technologies

The migration itself is a nightmare. Microsoft should give more use cases for service providers to work on. Since our client is a bank, our users do not comply with our time windows, so we should be able to block some of their access. Those features are not available. Secondly, calendaring and scheduling are done on Teams, but some users don't use Teams. From an environmental standpoint, Microsoft has everything, but when executing, none of them really work. That is where the project fails to meet its timelines.

Likewise, the availability of features can be improved.

From a migration perspective, they should make it more integrative for the admins working on it and better integration with Intune. There are also high failure rates for policy deployment.

Moreover, some policies can't be remotely enabled. One has to physically talk to the user and get the DPM and security code done. That is something that can be improved.

View full review »
Anthony Jenkins - PeerSpot reviewer
Retired at a government with 10,001+ employees

I cannot think of any downsides to the solution at the time since it's very easy to recover my password if I forget my BitLocker password.

It would be great if there were levels of security where the basic level locks the whole computer but has a level where I could give access to an individual who could open read-only files. The solution lacks the ability to allow its user to provide limited access to someone. This is one feature that needs to be added to the solution.

View full review »
Jeison Bonilla - PeerSpot reviewer
Cyber ​​Security Administrator at BAC Credomatic

Technical support has not been very good. 

We'd like automatic self-service in future releases. 

View full review »
Buyer's Guide
Microsoft BitLocker
April 2024
Learn what your peers think about Microsoft BitLocker. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.
Hassan Moussafir - PeerSpot reviewer
Information Security Senior Expert at Wafaassurance

The only improvement needed is a module that can centralize the keys better. It needs a management console. 

View full review »
PM
EUT Analyst at Absa Group Ltd

In future releases, I would like to see a feature where I can have a view of each device that has BitLocker to see if these machines are encrypted or not. So, I just want a view or a dashboard that can tell us so that I can remediate and add BitLocker to those systems or devices.

So, it should have the ability to view which devices are using Microsoft BitLocker.

View full review »
BF
Desk Top Operation Manager at a government with 10,001+ employees

I think there is some room for improvement for end users and technical staff. They are the ones required to support the computers, learn how the solution functions and to troubleshoot. For now, they have to wing it most of the time and it could be better. 

For additional features, I'd like to see something more manageable by our agency. We had a portal where we could manage these. I know there are products out there that have portals where you can actually manage the BitLocker and that would be much better. If we lose a computer now it's unclear whether Absolute Computrace can find it if it's been encrypted. 
We have some issues with Microsoft about that. 

View full review »
ManojNair2 - PeerSpot reviewer
Founder/Director at Augesys Solutions Pvt Ltd

In terms of improvement, they should look at file encryption. When the files are being moved out or something, sometimes we need encryption in transit. Meaning when your system, your laptop you're using, the files are idle, then they are encrypted. And if you are sending the files out, let's say you're mailing the files out, that's data in transit. The encryption over there is controlled differently. It depends on what tool you're using for sending the files. However, the encryption is controlled there. The thing is, if you could have one single point of the solution, no matter if you're using Office 365 as an organization, to have just one encryption system across multiple systems, rather than having one BitLocker on the drive, then another encryption rule-set for sending an email, that would be easier.

Maybe the solution could use some more capability within the reporting system, et cetera. The reporting in Microsoft is very minimal. If you had a third-party tool, they will give you very high-level, very detailed reporting across various categories and conditions. Microsoft doesn't do that. That's a huge drawback in the system. You open the control, you get a lot of information; however, that information, you can't export.

View full review »
AI
Head of IT department at Monetars

BitLocker could have a more user-friendly interface at a lower price. There are no regular updates for it. If they introduce new features, the new version might offer improvements or enhancements in the future.

View full review »
TS
Senior Presales Engineer at CenterTools Software GmbH

The primary aspect for improvement lies in expanding our developer base, which would accelerate the development process and bring these enhancements to fruition. For the upcoming release, I'm interested in seeing additional features, particularly the ability to synchronize usernames and passwords into a pre-boot authentication system.

View full review »
NM
Founding Partner at 2Five1

The only thing that could be slightly improved is the occasional stability issue.

View full review »
Claudio Dosio - PeerSpot reviewer
ICT Manager at a construction company with 11-50 employees

We recently found some stability issues with Microsoft BitLocker. We found that quite a few users on the web are complaining about the solution's stability, especially after the Microsoft update. One user's laptop did not boot because of such an issue.

View full review »
Matt Hardy - PeerSpot reviewer
Infrastructure Manager/Deployment Manager at Hivedome Consultancy Services

BitLocker should be available on standard Windows. We need to spend money on a Pro license to get BitLocker because it's essential to protect our customers' data. We don't want that to fall into the wrong hands.

View full review »
CO
Senior Network Associate at AMCON, Inc.

For improvement, as it is now, I do not have any support from anyone. There should be a web interface to manage BitLocker. But for now, all I do is just install a new product on the user's machine and create it. 

I would like to be able to see everything that is happening, even if it is just through a web interface. I would also like to be able to see how many users are provisioned, which users are using BitLocker, and how to disable or enable it.  That's what I would like to see.

View full review »
EO
Information Security Management Individual Contributor at First Bank of Nigeria Ltd.

Some non-enterprise security solutions offer more comprehensive tracking capabilities for stolen devices beyond device protection. They enable location tracking of the device once it connects to the internet. Additionally, they provide enhanced stability, addressing instances where encryption fails to complete and rollback attempts become problematic.

View full review »
LA
Team Manager at JJ soluciones

The product must improve the centralization of keys. BitLocker is not perfect. Sometimes, we have problems when Windows tries to start. It shows that the key is not available.

View full review »
Naren Malepati - PeerSpot reviewer
Assistant Manager at Vodafone

The solution’s user interface could be improved.

View full review »
DC
Operator at Halliburton

There are options which could be implemented to make it a little more like PGP Whole Disk Encryption, but given the fact BitLocker is readily available, and has no known conflicts, I think it is a great product to secure against unauthorized access.

View full review »
Urs Schuerch - PeerSpot reviewer
Information Technology Engineer at Ingenias AG

The deployment process regarding prerequisites and automation could be easy to understand. It could be more transparent. Documentation should be more accessible and simplified, particularly directed towards small organizations, making it understandable for smaller setups.

A centralized management console with a web interface or dashboard for an implementation overview could exist.

View full review »
JS
Information Security Manager at a renewables & environment company with 501-1,000 employees

Their interoperability with our tools, which are the Microsoft tool, can be improved. It needs to be geared towards more of the wraparound of the zero trust. There are solutions we're looking at that do encryption plus X, Y, and Z. So, we're looking at the ability to wrap around the product with other features.

The biggest one for us is revoking access. So, even though someone downloads something to a device, we want the ability to cloak that device or data and bring it back or make that data unusable for that person. Currently, BitLocker doesn't give us that ability. It basically encrypts it. We're seeing if identity management or IAM allows us to do that. We're kind of looking at third-party software that does that for us.

Usually, Microsoft sees what other third-party companies do and then either adopts it or buys the third-party company, and that's kind of what we're looking into. That's our need. It'd be a lot better if it was all under one mirror or one window, instead of having a couple of different vendors working on it. So, if Microsoft could solve that, it would be awesome. They should look at the third-party enhancements that people are doing, and then take the encryption a step further by adding those features to BitLocker. Microsoft has different components. They have identity management, but is it tied to encryption? BitLocker is mostly tied to devices, but it would be best for me if I get a piece of data and I am able to encrypt it all the way through using BitLocker. Currently, BitLocker is basically tied at the device level instead of the data level.

I would just like them to look at what other people are doing in terms of encryption as a whole and offer the encryption not only tied to the device, but also to the file level. They should add features on that in terms of access control and reporting. We should be able to see who has access to it and who has touched a file. So, we're going towards the zero trust model and the zero trust reporting. It is a "We don't trust anybody" type of deal. So, it is not just the device, it is the data. They should try to wrap it around the data at the file level and not at the device level.

View full review »
AS
System and network security engineer at Central Bank of Nigeria

They could improve cloud integration regarding attribute and encryption key management.

View full review »
KW
Project Engineer (Engineer II) at Sarawak Energy Berhad

I would like to see improvement in the solution's central management of passwords. Currently, we install it separately. 

View full review »
KD
I.T. Director & CISO at Maple Reinders

The pricing should be improved.

View full review »
Atal Upadhyay - PeerSpot reviewer
AVP at MIDDAY INFOMEDIA LIMITED

There is room for improvement in stability. 

View full review »
DL
Director IM/IT at Sustainable Development Technology Canada

In the next generation, it could have a higher level of encryption.

I would like to be able to encrypt our cloud tenancy.

I would like to have the ability to encrypt a cloud-based server with BitLocker.

View full review »
ZG
Head of IT at a financial services firm with 11-50 employees

The management of the product could be made a little easier.

View full review »
TAYIM Henri - PeerSpot reviewer
System Administrator at a transportation company with 10,001+ employees

The solution could improve by having a centralized GUI for management.

View full review »
AP
Director, Cryptographic Engineering at a financial services firm with 10,001+ employees

Right now, the problem for us is, if a laptop is stolen, how they address it with the hard drive if it is already protected in BitLocker? We cannot protect anything until we have a centralized server feed where w can get all the information from all the laptop and the device if it does get stolen. Currently, to solve this, we are using a solution called Unbound.

I'm a hardcore developer. I don't know whether the solution has any source files. That said, I don't see anything that's really lacking, feature-wise. 

It's possible that the time it takes to pull items in to BitLocker could be reduced a bit. It can take a long time - sometimes up to 90 minutes.

View full review »
it_user757422 - PeerSpot reviewer
Microsoft (Active Directory) Consultant at a logistics company with 5,001-10,000 employees

Microsoft Bitlocker Administration and Monitoring (MBAM) is one of the best solution available in the marekt to protect corporate data

View full review »
SK
Associate at a consultancy with 201-500 employees

The solution could be improved if it was more user friendly. 

View full review »
Milan Turinic - PeerSpot reviewer
IT manager at Milan Turinič


They can improve the security of the application and include an encryption disk in the next feature.
View full review »
Ibrahin Gamal - PeerSpot reviewer
IT Specialist at ITE Corp

The product could be improved by simplifying the implementation process and the integration between Active Directory and BitLocker could be better.

View full review »
JK
Information Technology Specialist at Calculus System Sarl

It takes a very long time to encrypt a disk, so I think that speed is something that can be improved. It can take more than two hours to encrypt a disk with one terabyte of data. When my clients are working, they don't really like having to look at a progress bar to tell them that the disk is in the process of being encrypted. If the encryption was faster then it would make the experience more pleasant.

I would like to be able to secure the hard drives of virtual machines.

Securing data transfer such as email and the more general internet connection would be very good.

They should improve the hybrid-cloud security and protect the network instead of just securing the computers.

View full review »
Loyiso Gura - PeerSpot reviewer
Microsoft SureStep Ambassador at 4Sight Dynamics Africa

Microsoft BitLocker needs to be an all-inclusive solution. For example, a Trusted Platform Module (TPM) cryptoprocessor is required to use Bitlocker with your computer which keeps Bitlocker from adoption beyond Windows.

View full review »
LC
Network engineer at Techmcc

The customizations could be more flexible. 

View full review »
AS
System Administration Specialist at Alatau Innovations

We need to increase the data disc a bit, not all of it, as we tried to test some special software views. We had a problem with the disc. The disc may be damaged. We can lose information. This has just happened once. It’s not standard.

The initial setup is complex.

I want them to include the encryption of the data disc.

View full review »
SW
Manager - ICT at a insurance company with 51-200 employees

I was looking for a better solution. It's my understanding that if you're just to generate that endpoint encryption and you just run it normally, it may not give you the actual protection you need as you don't have a centralized server.

At the end of it all, we are looking for something that can be easier to manage. Everything that you need to do manually can end up being an issue. If it's a product that can be automated, I would be happier with it. Right now, with the way it is arranged, it's a bit manual as it isn't centralized.

View full review »
TS
Technical Associate at Intimesolutions

They should offer better login capabilities that are more secure. Right now, they only offer SSO. They need to offer multi-factor authentication. 

The support could be a bit faster. 

View full review »
VM
Product Manager at Axoft Ukraine

Some of the technical internal functions, such as encryption protocols or something similar, could be improved. But it makes no difference in terms of functionality for us or users.

View full review »
JM
Manager, Information Technology Operations & Security at a government with 11-50 employees

User profiles can be improved so that people can create their own passwords. It has one password per machine, which is a problem. We would prefer each user to have his or her own boot password. Each user can have a username and password or biometrics, such as fingerprints and iris scanner, integrated into the boot process, but I really can't see that coming anytime soon, if ever.

View full review »
SB
Technical support engineer at 64 Network security pvt ltd

The solution needs to have better protection and improve its pricing. 

View full review »
RS
AnalystAssistant General Manager - Corporate Strategy, Growth and Transformation Office at a manufacturing company with 501-1,000 employees

My overall experience is based solely on one point: the gateway to the admin site. Even though my password is correct, I often have to make multiple attempts to log in. Microsoft BitLocker can help streamline the login process so that it works on the first attempt.

I would like the next release to include a fingerprint unlock feature, as I am currently required to use the PIN provided by my organization.

View full review »
Usman Rasool - PeerSpot reviewer
VP - Head Enterprise Technology Infrastructure at MCB Islamic Bank Ltd.

The price of this solution should be more competitive.

The first level of technical support needs to be improved.

View full review »
it_user1011 - PeerSpot reviewer
Manager of Data Center at a insurance company with 51-200 employees
1. Although, drive encryption could be running in the background, it took a long time to encrypt a drive. 2. Bitlocker is available to Windows Ultimate / Enterprise edition only. Other edition of Windows should enjoy this facility My job functions involve writing scripts that I mostly apply to client’s computers both standalone and networked. I store most of these scripts in a flash drive to reduce the task of writing it at the client end. My major challenge was in securing the flash drive. In the past I had a case where a staff member wiped most of his important files, by unknowingly clicking on one of the scripts in the flash drive he collected from me. This incident almost caused me to lose my job. View full review »
YB
Senior System Manager at Teganalytics

The following areas need improvement:

  • The encryption takes a long time to complete, and our system runs very slowly while it is encrypting.
  • If you lose the data, or it becomes corrupted, then there is no backup for it. There is no way of recovering it.
  • There are no clear guidelines for using this product.
  • Technical support for this solution is poor.
View full review »
SK
IT Manager at a tech services company with 10,001+ employees

The console GUI could be better.

The initial setup could be simplified.

View full review »
KC
Director at Pathfinder

The visualization could be better. I don't have any complaints about the usability of the stability of it and he licensing is quite reasonable actually.

View full review »
it_user1122 - PeerSpot reviewer
Infrastructure Expert at a tech services company with 1,001-5,000 employees
Any software encryption will take up additional space on your hard drive or storage device, and Bitlocker is no exception. Also, Bitlocker is only available on Windows 7 Ultimate and Enterprise editions, not Professional which most small and medium business users use. View full review »
JH
Chief Information Security Officer at a healthcare company with 1,001-5,000 employees

It is not good for cross-compatibility, so our Mac users are not able to use it.

The support for Linux and Macs is really the only thing that we are missing.

View full review »
RM
IT Infrastructure Analyst at a tech services company with 501-1,000 employees

The implementation of BitLocker is not simple. There are many prerequisites and hours of study and testing. We have had some communication problems between Windows 10 and TMP and, in some cases, the computer does not work and we need to generate a new key in MBAM.

View full review »
it_user1035 - PeerSpot reviewer
Developer at a tech vendor with 51-200 employees
1. It is available for Microsoft Windows Ultimate and Enterprise editions only. 2. It takes a long time to encrypt and decrypt a drive.Bitlocker is a very user friendly tool, which can encrypt our data within a few clicks. There is no hard work to do. Because of that, I prefer to use it. It has no big steps and is also a very light tool. A major thing is that it is a free tool that comes with Microsoft Windows. View full review »
it_user1287888 - PeerSpot reviewer
IT Security Specialist at a tech services company with 201-500 employees

For our company's needs, the solution works very well.

From a retail standpoint, in terms of Microsoft licensing, you need to purchase an enterprise-level version of the licensing tool to get the level of manageability that's needed. However, this is only offered to very large enterprises.

The solution should offer encryption for other items such as shared folders, removable media, etc.

The solution should recreate the key when Windows is upgraded to a newer version.

View full review »
it_user355887 - PeerSpot reviewer
Infrastructure Specialist at a healthcare company with 1,001-5,000 employees

Remote management (e.g., enable/disable, reset, etc.) of PIN codes and recovery keys would be a nice feature.

View full review »
SP
Head of Operations (India) at a tech vendor with 51-200 employees

More customization options would have been nice, such as password selection, actions when the screen is locked, etc.

View full review »
Buyer's Guide
Microsoft BitLocker
April 2024
Learn what your peers think about Microsoft BitLocker. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,578 professionals have used our research since 2012.