What is our primary use case?
We primarily use the solution for encryption.
What is most valuable?
You have to do a bit of reading to understand the logic; however, after that, it becomes pretty straightforward to use it.
Feature-wise we have the ability to encrypt fast. This means when you enforce the policy and when you onboard a device via the Azure AD, it comes online pretty quickly. The speed at which BitLocker engages is pretty strong. That's a significant thing. You can even control your external devices, like your USB devices. You can allow or deny, or even encrypt those devices. There are lots of useful things like that available in this product.
What needs improvement?
In terms of improvement, they should look at file encryption. When the files are being moved out or something, sometimes we need encryption in transit. Meaning when your system, your laptop you're using, the files are idle, then they are encrypted. And if you are sending the files out, let's say you're mailing the files out, that's data in transit. The encryption over there is controlled differently. It depends on what tool you're using for sending the files. However, the encryption is controlled there. The thing is, if you could have one single point of the solution, no matter if you're using Office 365 as an organization, to have just one encryption system across multiple systems, rather than having one BitLocker on the drive, then another encryption rule-set for sending an email, that would be easier.
Maybe the solution could use some more capability within the reporting system, et cetera. The reporting in Microsoft is very minimal. If you had a third-party tool, they will give you very high-level, very detailed reporting across various categories and conditions. Microsoft doesn't do that. That's a huge drawback in the system. You open the control, you get a lot of information; however, that information, you can't export.
For how long have I used the solution?
I’ve been using the solution for almost a year now.
What do I think about the stability of the solution?
The solution is absolutely stable. There are no bugs or glitches and it doesn’t crash or freeze. It’s reliable.
What do I think about the scalability of the solution?
We currently have about 150 people using the solution across every level of the organization.
Scalability doesn't really come into play since it's applicable only to the endpoint. BitLocker is applied to the laptop. You can set the policy to apply to all the drives on the laptop, and you can set the policy when the system is starting up and ask for a pin or just run it without the pin when it starts up. All that stuff is configuration-driven. There's no issue with scalability there. It just applies to all the machines, and once encrypted, all the machines will report to the central consoles.
How are customer service and support?
Technical support varies since Microsoft tech support is outsourced to other organizations partnering with Microsoft. Therefore, even though I'm raising a ticket with Microsoft, it can go anywhere across the globe. Eventually, it is a third-party organization that's representing Microsoft that will handle the ticket.
The problem is the individual's expertise will vary. Some of them are very well versed in a particular product. Some are not so well versed. Eventually what happens is if they're not so well versed, then they'll go back to the Microsoft documentation and give you details based on that, and they'll work it out with you. The important thing is they always make it a point to achieve case closure. I'm not saying that it's very brilliant, however, it does a very good job. 80-90% of the time, it actually works.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did not previously use a different solution, however, the critical thing to note is Windows 10 and 11 come with built-in encryption enabled. You have to disable that encryption. Only then will your centralized policy for BitLocker take over. Otherwise, it will throw up an error.
How was the initial setup?
The initial setup is pretty simple. You might have to do a bit of education in terms of understanding the logic, however, after that, it’s all very simple.
For the actual deployment, basically, I did it in pieces. I did the initial deployment on my laptop. I had raised queries with Microsoft Support for this. Once I got the basic settings in place, I stabilized this as my policy, and then I drove it out to all my users.
What about the implementation team?
I handled the initial setup myself. I didn’t need the help of any integrators or consultants.
What's my experience with pricing, setup cost, and licensing?
You only have to pay for it. BitLocker is already present within the operating system. It's part of the OS. When you buy your laptop or a desktop, BitLocker is already present. The important thing here is the configuration part of it. BitLocker comes on your laptop, and it's 128-bit encryption, which comes by default. It's the unmanaged variety. The managed variety can be 128 or 256 bits. As a matter of industrial practice, we will all deploy 256 versions and there's no software cost coming in.
The important thing here is the deployment tool that you have. There are lots of tools in the market. Microsoft has an app called Intune, which gives you native control of the system. If you don't use Microsoft, if you don't have Intune, then you could look at some other products which give you control over the native encryption rather than deploying their own. Many products are there in the endpoint security domain which provides you encryption. If I decide to go that route, I will disable the BitLocker on both and I will apply this encryption software. However, I’m forced to rely on that encryption tool to do that management.
What other advice do I have?
I’m using the latest edition. I started off on a trial basis for a couple of weeks, and now I've taken it to production. All my laptops are now on BitLocker.
I’d rate the solution nine out of ten.
If you want a free solution and work on Microsoft, use Windows BitLocker. That should do the job for you. Unless otherwise explicitly required for business needs, Encryption is basically a compliance requirement from an audit compliance requirement perspective. Encryption of your hard drives is a compliance requirement. However, there are businesses and industries wherein the data has to be encrypted, and it’s mandatory. This is not an issue of compliance for them. It's a work requirement. In those kinds of scenarios, then you would have to probably look at third-party solutions, which give you something beyond just the basic encryption. If you want to do basic encryption and you have your Intune, just use that. No money needs to be spent. You just need to put a little effort into creating a policy to push and apply to all the systems. End of story. However, if you have something more significant, you may have to look at other solutions.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.