How to re-lock a drive with bitlockerI am using windows 7 bitlocker to encrypt a secondary hard drive. So I unlock the drive with the password successfully. Now how do I relock the drive? The only way I can see is to restart the machine. What bothers me is that even if you log off, and log in as another user the drive is still unlocked! Isnt there a menu item or option to re-lock it?<hr class="sig">-mi© 2009 Microsoft Corporation. All rights reserved.Sun, 22 Nov 2009 14:26:16 Z41607938-7452-440d-8253-67fe8657bc0fhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#41607938-7452-440d-8253-67fe8657bc0fhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#41607938-7452-440d-8253-67fe8657bc0fmi23http://social.technet.microsoft.com/Profile/en-US/?user=mi23How to re-lock a drive with bitlockerI am using windows 7 bitlocker to encrypt a secondary hard drive. So I unlock the drive with the password successfully. Now how do I relock the drive? The only way I can see is to restart the machine. What bothers me is that even if you log off, and log in as another user the drive is still unlocked! Isnt there a menu item or option to re-lock it?<hr class="sig">-miFri, 29 May 2009 15:29:44 Z2009-05-29T15:29:44Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#9db3d5db-4846-4374-8cae-7b90fed26667http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#9db3d5db-4846-4374-8cae-7b90fed26667Robinson Zhang - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Robinson%20Zhang%20-%20MSFTHow to re-lock a drive with bitlocker<p>Hi,</p> <p>I did several tests on my side, and I think this is a potential security bug. I will report it to our internal team.</p> <p>On the other hand, I do not have any workaround for this issue. Please temporarily restart the computer every time for security.</p> <p>Thank you for your understanding.</p>Mon, 01 Jun 2009 10:24:06 Z2009-06-01T10:24:06Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#94159e8c-434b-40c8-8aa9-d85e08478ae3http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#94159e8c-434b-40c8-8aa9-d85e08478ae3DeluxeWarPlayahttp://social.technet.microsoft.com/Profile/en-US/?user=DeluxeWarPlayaHow to re-lock a drive with bitlockerAny updates on this? Wed, 03 Jun 2009 15:10:51 Z2009-06-03T15:10:51Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#8c51e679-6d9c-4672-8ba4-8103717783cbhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#8c51e679-6d9c-4672-8ba4-8103717783cbsuperlativehttp://social.technet.microsoft.com/Profile/en-US/?user=superlativeHow to re-lock a drive with bitlockerI too also need an update on this!Fri, 03 Jul 2009 06:29:14 Z2009-07-03T06:29:14Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#b56ea91b-f1e9-4da2-af93-acb660f09942http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#b56ea91b-f1e9-4da2-af93-acb660f09942Ed McKinnonhttp://social.technet.microsoft.com/Profile/en-US/?user=Ed%20McKinnonHow to re-lock a drive with bitlockerAlso looking for an answer on this. <div><br/></div> <div><em>&quot;this is a potential security bug&quot;</em> - I'd say definitely a security bug!</div> <div><br/></div> <div>An automatic relock timer might be a nice feature also.</div>Tue, 07 Jul 2009 09:45:42 Z2009-07-07T09:45:42Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#592cef3e-8837-47ca-9718-832ba495add4http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#592cef3e-8837-47ca-9718-832ba495add4Robin A Marshallhttp://social.technet.microsoft.com/Profile/en-US/?user=Robin%20A%20MarshallHow to re-lock a drive with bitlockerYou can achieve this through the command line interface<br/> <br/> e.g. If P: were my private drive, I can re-lock it with the following command (run the cmd shell with Administrative rights though)<br/> <br/> <strong>To re-lock a Bitlocker drive on Windows 7</strong> :<br/> <br/> <em>   manage-bde -lock P:</em> <br/> <br/> EnjoyMon, 10 Aug 2009 13:37:18 Z2009-08-10T13:37:40Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#fc83ddcb-6b8d-40f8-977d-117a46b8a21ehttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#fc83ddcb-6b8d-40f8-977d-117a46b8a21eLoneWolf15http://social.technet.microsoft.com/Profile/en-US/?user=LoneWolf15How to re-lock a drive with bitlockerThanks for this, Robin.  At least I can add a script and pin it to the Start Menu.<br/> <br/> This is still an issue in the RTM; I'm a little disappointed it made it through to release.<br/>Sat, 22 Aug 2009 11:20:13 Z2009-08-22T11:20:13Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#5f19ca0e-c337-4127-a0cc-6fb03e6c8b34http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#5f19ca0e-c337-4127-a0cc-6fb03e6c8b34Inge Krossoeyhttp://social.technet.microsoft.com/Profile/en-US/?user=Inge%20KrossoeyHow to re-lock a drive with bitlockerI made a .cmd-file to re-lock the drives:<br/> <br/> From a cmd-prompt, type the following:<br/> <br/> C:\Windows\system32&gt;copy con lockdrive.cmd<br/> manage-bde -lock l:<br/> manage-bde -lock k:<br/> ^Z    <em> [press CTRL-Z]</em> <br/>         1 file(s) copied.<br/> <br/> Replace l: and/or k: to the corresponding drive letter on your computer.<br/> <br/> Make a shortcut to the lockdrive.cmd-file, and check the &quot;run as administrator&quot; check box.<br/> <br/> <br/> Rgs,<br/> Inge<br/> <br/>Sat, 29 Aug 2009 14:05:53 Z2009-08-29T14:05:53Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#30ed424c-d6fa-4037-bea1-cf9fcb767195http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#30ed424c-d6fa-4037-bea1-cf9fcb767195st3vhttp://social.technet.microsoft.com/Profile/en-US/?user=st3vHow to re-lock a drive with bitlocker<p>I have the same problem. By the way, I am using Windows 7 RTM 64-bit. I also through group policy increased the cipher strength to &quot;AES 256-bit with Diffuser&quot;.<br/><br/>I encrypted a couple USB hard drives with Bitlocker To Go. I noticed another security issue on top of the one already discovered:<br/><br/><strong>When a Bitlocker To Go disk is connected, initially it is locked with the volume label hidden (as it should be). When you relock the drive using &quot;manage-bde -lock drive:&quot; the volume label is still showing.<br/><br/>Edit: I have been testing this further by unlocking, relocking, and disconnecting the drive multiple times and I noticed that in &quot;Computer&quot; it eventually stopped showing a volume label for this drive when it is unlocked (until I restarted my computer). I am not sure why. But when I used the &quot;dir&quot; command it did show the proper volume label. This might be a bug in the &quot;Computer&quot; display of volume labels, it might not be re-reading the volume labels for drives properly.<br/><br/></strong>When a Bitlocker drive is relocked, it should be in the same state as if it were freshly connected. Also, logging off should automatically relock drives, or at least have an option in the Bitlocker control panel and/or group policy for that. <br/><br/>Regarding the original poster's issue: Logically, one would think right-clicking the unlocked drive and choosing &quot;Manage Bitlocker&quot; would have an option to lock the drive.</p>Sun, 30 Aug 2009 14:34:50 Z2009-08-30T15:14:06Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#a5b8e986-f42b-4668-8d47-275321d3150chttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#a5b8e986-f42b-4668-8d47-275321d3150cmi23http://social.technet.microsoft.com/Profile/en-US/?user=mi23How to re-lock a drive with bitlockerthis was the best answer ever;)<hr class="sig">-miTue, 01 Sep 2009 18:54:48 Z2009-09-01T18:54:48Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#284ea40d-666b-4ecb-9638-b39227814124http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#284ea40d-666b-4ecb-9638-b39227814124jonamafunhttp://social.technet.microsoft.com/Profile/en-US/?user=jonamafunHow to re-lock a drive with bitlockerCheck my post here on how to do the 'Lock Drive' right-click menu entry:<br/> <br/> http://jonamafun.blogspot.com/2009/11/how-to-re-lock-bitlocker-drive.htmlFri, 13 Nov 2009 12:11:07 Z2009-11-13T12:11:07Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#61b90a06-6637-4bcd-9358-4a1b4ef142d0http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#61b90a06-6637-4bcd-9358-4a1b4ef142d0stuckmotohttp://social.technet.microsoft.com/Profile/en-US/?user=stuckmotoHow to re-lock a drive with bitlocker@jonamafun - followed exactly but getting &quot;The filename,directory name, or volume label syntax is incorrect&quot;<br/> any suggestions? <br/>Mon, 16 Nov 2009 18:22:05 Z2009-11-16T18:22:05Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#b6c02d57-f593-4a76-aced-cb9f63d35a5bhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#b6c02d57-f593-4a76-aced-cb9f63d35a5bjonamafunhttp://social.technet.microsoft.com/Profile/en-US/?user=jonamafunHow to re-lock a drive with bitlockerTry running the batch file from Windows Explorer to see if it actually locks your drive first.<br/> <br/> What did you name your .bat file and where is it located? Make sure you put the full path to the file at step 6.<br/> <br/> This is what my step 6 looks like:<br/> <br/> <img src="http://img40.imageshack.us/img40/4542/step6qw.jpg" alt=""> <br/> <br/> <br/> <br/>Tue, 17 Nov 2009 12:36:53 Z2009-11-17T12:36:53Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#dd349b7e-6e2a-4e1d-94e0-86acde06a6cahttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#dd349b7e-6e2a-4e1d-94e0-86acde06a6caJajxhttp://social.technet.microsoft.com/Profile/en-US/?user=JajxHow to re-lock a drive with bitlocker<p>This could work, but batch file needs to be run as administrator, don't know how to set it yet..</p>Wed, 18 Nov 2009 10:15:22 Z2009-11-18T10:15:22Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#ac9244a7-00f3-42fe-a1af-efe832f6bb40http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#ac9244a7-00f3-42fe-a1af-efe832f6bb40Rick101chttp://social.technet.microsoft.com/Profile/en-US/?user=Rick101cHow to re-lock a drive with bitlockerI followed all the steps, but get an error popup:<br/><br/>&quot;The filename, directory name, or volume label syntax is incorrect&quot;<br/><br/>The .bat file it points to works fine.<br/><br/>my runas\command\ looks just like the screen shot.<br/><br/>Any ideas?Sun, 22 Nov 2009 10:50:25 Z2009-11-22T10:50:25Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#7527cb8c-12b7-43de-abe0-fb61899b7646http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#7527cb8c-12b7-43de-abe0-fb61899b7646Rick101chttp://social.technet.microsoft.com/Profile/en-US/?user=Rick101cHow to re-lock a drive with bitlockerI followed all the steps, but get an error popup:<br/><br/>&quot;The filename, directory name, or volume label syntax is incorrect&quot;<br/><br/>The .bat file it points to works fine.<br/><br/>my runas\command\ looks just like the screen shot.<br/><br/>Any ideas?<br/><br/>How do you add a screen shot to a post here?  I could show you what my reg keys look like.<br/><br/>I did discover that I could make a shortcut to lock.bat; and in the advanced shortcut properties it lets you set &quot;Run as Administrator&quot;.<br/><br/>So ideally, the reg key setting could point to the shortcut.<br/><br/>Thanks for any help...Sun, 22 Nov 2009 11:07:37 Z2009-11-22T11:07:37Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#8438a929-eccc-4086-a249-9c6d3ae708e7http://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#8438a929-eccc-4086-a249-9c6d3ae708e7Rick101chttp://social.technet.microsoft.com/Profile/en-US/?user=Rick101cHow to re-lock a drive with bitlockerMe, too; ever get a solution?<br/><br/>ThanksSun, 22 Nov 2009 11:09:40 Z2009-11-22T11:09:40Zhttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#c5589b23-4f10-4f63-9ea2-4277abcf150ahttp://social.technet.microsoft.com/Forums/en-US/w7itprosecurity/thread/41607938-7452-440d-8253-67fe8657bc0f#c5589b23-4f10-4f63-9ea2-4277abcf150ajonamafunhttp://social.technet.microsoft.com/Profile/en-US/?user=jonamafunHow to re-lock a drive with bitlockeri used HTML tags to embed the image here...<br/> <br/> Have you tried testing with UAC turned off? I neglected to mention that I'm running without UAC (shhh!) so that may have something to do with it.Sun, 22 Nov 2009 14:26:16 Z2009-11-22T14:26:16Z