1478 Benefits of Using SD Pre-Boot BitLocker Vs Microsoft BitLocker

Prev Next

What are the advantages of using SecureDoc Pre-boot for Bitlocker versus Microsoft Bitlocker Preboot?
SecureDoc preboot for Boot Logon provides all the strength of our preboot, such as PBConnex, autoboot, PBConnex autoboot, Challenge/Response and Self-Help recovery after forgetting the password, wired and wireless network at preboot. 
 
With is the Limitations of using Microsoft Bitlocker preboot?
For example, on Win7 there's no option of a password, only TPM, TPM+PIN or TPM+PI+file on USB.
If device is shared, users don't get personal credentials (e.g. everyone has to authenticate with "at the machine level", not at the user level.  So everyone needs to know the same credentials to get into the machine.
Recovery is also problematic, in that instead of getting a unique per-incident challenge/response combination, there's a recovery key stored in the Domain that doesn't change until someone actively changes it... if that gets written down (it's about 48 bytes long) it can be used again and again, or used by an attacker to get past BL preboot
 
Advantages of using Microsoft BitLocker Preboot
Please keep in mind that if you are using the current setting which is Microsoft BitLocker Preboot, then you are utilizing what Microsoft features available to you.
Enterprises may choose to use Microsoft's BitLocker Full-Volume Encryption instead of SecureDoc encryption for various reasons such as ease of configuration, low purchase costs and better OS compatibility or you may be slowly migrating from BitLocker to SecureDoc and are looking for support in transitioning from BitLocker encryption to SecureDoc. To satisfy customers, SecureDoc supports management of devices encrypted with BitLocker as well as configuration to enable BitLocker encryption when deploying a SecureDoc package.
With the Microsoft Bitlocker Preboot, we port the recovery information to the SES server to maintain.
Windows 8 and onward allow for the use of Passwords.... I'm not sure, frankly, if that means discrete passwords (one per user) or still one per computer.
That functionality did not exist in Bitlocker for Windows 7