Solved

Hyper-V VM encryption


Userlevel 1

Hello, 

is it supported to have Hyper-v VM with bitlocker enabled inside the guest for encrypting the data disk ?

 

icon

Best answer by MicoolPaul 20 May 2024, 18:27

View original

6 comments

Userlevel 7
Badge +19

Hi @Sc2111 - it appears you can back them up but you can't restore those VMs or browse the guest. See limitations below

https://helpcenter.veeam.com/docs/backup/hyperv/guest_restore_before_you_begin.html?zoom_highlight=Bitlocker&ver=120

Userlevel 7
Badge +22

Hi @coolsport00 slight correction on that, you can still restore the disks etc, you just can’t restore individual files because Veeam can’t decrypt the encrypted data. But it can certainly still restore the entire disk for the VM to use its Bitlocker key to read the data. This isn’t a Veeam specific limitation btw @Sc2111 

Userlevel 7
Badge +19

Hi @coolsport00 slight correction on that, you can still restore the disks etc, you just can’t restore individual files because Veeam can’t decrypt the encrypted data. But it can certainly still restore the entire disk for the VM to use its Bitlocker key to read the data. This isn’t a Veeam specific limitation btw @Sc2111 

Good catch Michael!

Guess it doesn't make sense to back them up & not be able to restore 😂

Userlevel 1

Hi @coolsport00 slight correction on that, you can still restore the disks etc, you just can’t restore individual files because Veeam can’t decrypt the encrypted data. But it can certainly still restore the entire disk for the VM to use its Bitlocker key to read the data. This isn’t a Veeam specific limitation btw @Sc2111 

So in case of restore needed what could be the steps ?

Restore the entire virtual disk attached to the same server, I suppose that attaching to another won’t work?

thanks

 

Userlevel 7
Badge +19

Hi @Sc2111 -

There’s nothing specific to recovery of Bitlocker Volumes in the Guide, but I did find an older post in the Forums which discusses Volume recovery:

https://forums.veeam.com/microsoft-hyper-v-f25/bitlocker-protected-vhd-attached-to-guest-available-to-veea-t25031.html

You could restore your disk to another VM, but you’d need the Bitlocker key to unlock it which makes total sense.

Userlevel 7
Badge +19

Hey @Sc2111 - I found this more recent Forum post on how PMs would go about doing restores. Pretty good IMO. So, you have some options there. You’d just need to test what works best for you:

https://forums.veeam.com/veeam-backup-replication-f2/file-level-restore-for-bitlocker-encrypted-volumes-t64847.html

Comment