Using BitLocker for drive encryption
In this chapter, we've looked at how we can protect your servers against bad settings, missing Windows Updates, and how we can identify issues using System Monitor. But did you know we can also protect our servers against theft? Obviously, no software can stop your server from actually being stolen, but in the event that someone does steal your server, or its storage, we can render your data on that storage completely unusable. This can be done with drive encryption – when your server starts up, it unlocks the drive with a special key, known only to that server. If your disk is ever stolen, it won't be able to be unlocked as it will be missing the key. And if the entire server (with its key inside it) is stolen, if the person that stole it doesn't have an administrator password to your computer, they still won't be able to get any data off it. Microsoft calls this BitLocker.
To execute drive encryption well, your server...