BitLocker Best Practice Question Just thought I'd add to this as I have a ticket open at the moment for a related issue.
Even though there is mention above and here:
https://forum.msp360.com/discussion/360/windows-image-based-backup-keep-bitlocker about not being able to do "File Restores" I have a different experience of file restores on "Keep Bitlocker" backups of Bitlocked system drives. I have tested a "file restore" from an Image Backup (block level) and successfully restored a .png file (from my c:\temp folder) from my block level image backup created of a Bitlocked Encrypted system drive (C:) using the "Keep Bitlocker" option. Also I had AES256 turned on. It seems some clarification is needed here.
Yes it will not let you exclude any files/folders if "Keep Bitlocker" is enabled so it will back up things like c:\pagefile.sys, C:\swapfile.sys & c:\hiberfile.sys which can added up to 10+GB of space required for full image backups. This also makes block level backups much bigger.
In this thread (
https://forum.msp360.com/discussion/comment/5170) it mentions pagefile.sys and Recycle bin being excluded automatically from the backups but this is not the case if "Keep Bitlocker" is enabled - hence larger backup storage being required. I'm not sure if any of the above files are even excluded even if "Keep Bitlocker" is disabled - maybe someone else can let me know.
When I went to do the restore it asked for my AES256 encryption key (success) and then for my Bitlocker (BL) key for which I gave my BL recovery key (success).
I can imagine corruption (confusion) may occur if the source drive bitlocker key changes between backups. I've not had any problems with restores when using "Keep Bitlocker" as long as you have your BL recovery keys!
I agree with not having "Keep Bitlocker" enabled unless you have a specific reason - the only reason I can think of is if you have tonnes of storage/fast network/fast internet!
The best I can see at the moment is to have "Keep Bitlocker" disabled and to exclude c:\pagefile.sys, C:\swapfile.sys & c:\hiberfile.sys to keep backup storage requirements to a minimum for image backups.
I'm currently using version
6.3.8.12.