# Self-Encrypting Drive vs BitLocker for Company Laptops

> Self-encrypting drive or BitLocker for company laptops? Windows defaults, pre-boot login, hardware-accelerated BitLocker and when an SED is worth it.

**Canonical HTML page:** https://www.protechnology.ae/self-encrypting-drive-vs-bitlocker
**Source:** PRO TECHnology Co. L.L.C., Dubai, United Arab Emirates

---
Enterprise IT · System drive encryption

# Self-encrypting drive or BitLocker? Encrypting the system drive on company laptops and desktops

Published 8 October 2026 · PRO TECHnology Enterprise IT

For most company Windows laptops and desktops, the usual answer for the system drive is BitLocker: the Trusted Platform Module (TPM) alone is Microsoft’s baseline, with a startup PIN added where devices hold highly sensitive data or could face a skilled attacker with lengthy physical access. Since September 2019, BitLocker has encrypted newly protected self-encrypting drives in software unless Group Policy says otherwise. A self-encrypting drive (SED) earns its place where you need a pre-boot lock that does not depend on Windows, on Linux workstations whose policy asks for one, for a tender that names an SED, or for a quick key change before a drive is reissued. This guide covers the drive inside the computer; USB and portable drives are a separate decision.

- **BitLocker on an SED** Newly encrypted drives use software unless Group Policy enables hardware encryption

- **New in 2025-26** Hardware-accelerated BitLocker on laptops with crypto-offload chips

- **What an SED adds** A pre-boot lock that works without Windows

- **Checked** Microsoft, NIST and Kanguru sources, October 2026

A Kanguru Defender SED30 M.2 NVMe self-encrypting SSD, serial and PSID numbers blurred (image: Kanguru)

## Key takeaways

- Since Microsoft’s September 2019 Windows 10 updates (KB4516071 for version 1709, for example), BitLocker has encrypted newly protected self-encrypting drives in software unless Group Policy says otherwise; Microsoft lists no configuration service provider (CSP) for that policy, so Intune’s BitLocker settings cannot set it.
- For most Windows fleets the usual answer is BitLocker with recovery keys backed up centrally: TPM-only is Microsoft’s baseline, and a startup PIN, with hibernate or shutdown rather than sleep when a laptop leaves its user’s control, is what Microsoft recommends for devices with highly sensitive data or at risk from a skilled attacker with lengthy physical access.
- Hardware-accelerated BitLocker moves bulk encryption to a dedicated crypto engine on new laptops with supported chips (Microsoft named Intel vPro devices with Core Ultra Series 3 processors first, in December 2025), which narrows the speed argument for a self-encrypting drive on those machines; laptops already in service without such a chip stay on software BitLocker.
- A self-encrypting drive earns its place for a pre-boot lock that does not depend on Windows, Linux workstations whose policy asks for one, tenders that name an SED, desktops taking replacement drives, and drives that must be re-keyed at reissue.
- If a tender names FIPS 140, check the NIST certificate for the exact part number: the Kanguru SED300’s FIPS 140-2 certificates are on NIST’s historical list, and the SED30 has none.

## Four ways to encrypt a laptop’s system drive, side by side

This guide is about the drive inside a company laptop or desktop, the one the computer starts from. USB sticks and portable drives are a different decision, because the drive travels between computers, must protect itself on computers you do not manage and enforces its own wrong-password limit. For that side, see [our comparison of hardware-encrypted USB drives with BitLocker To Go](https://www.protechnology.ae/kanguru#hardware-encryption).

For the system drive of a Windows PC there are four realistic set-ups: three kinds of BitLocker, and a self-encrypting drive that locks itself behind its own login before any operating system starts.

- **Pre-boot authentication (PBA)** A login that must succeed before the system drive can be read. BitLocker’s version is a TPM plus PIN or startup key; an SED’s version is a small environment stored on the drive.

- **Windows encrypted hard drive (eDrive)** Microsoft’s name for a self-encrypting drive that also meets specific TCG protocols and IEEE 1667, so that BitLocker can manage its hardware encryption.

- **PSID** A code printed on an Opal drive’s label that can reset the drive to factory settings. The reset erases the data; it does not unlock it.

*System-drive encryption options compared (Microsoft and Kanguru documentation, checked October 2026)*

| Question | Software BitLocker | Hardware-accelerated BitLocker | BitLocker on a Windows encrypted hard drive (eDrive) | Self-encrypting drive with its own pre-boot login |
|---|---|---|---|---|
| Where encryption runs | On the laptop’s main processor | On a dedicated crypto engine in the system on chip | In the drive’s controller, under BitLocker’s control | In the drive’s controller, under the drive vendor’s software |
| Where the bulk key is held | In memory once unlocked; the TPM protects the intermediate keys | Wrapped by the chip where supported, so less exposed to CPU and memory vulnerabilities | Generated by the drive and, Microsoft says, never exposed outside it | Generated and kept inside the drive |
| Who unlocks it before the operating system starts | The TPM alone by default; optionally TPM with a PIN, a startup key, or both | As for software BitLocker | BitLocker’s protectors; Microsoft notes a PIN also counters key capture on an exposed eDrive bus | The drive’s own pre-boot authenticator, usually a password |
| Windows edition | Pro, Enterprise, Pro Education/SE or Education; device encryption elsewhere on qualifying hardware | As for BitLocker, on Windows 11 24H2 (September 2025 update) or 25H2 | Pro, Enterprise, Pro Education/SE or Education | Not tied to Windows |
| Central management and recovery | Group Policy, Intune or another MDM; recovery keys backed up to Microsoft Entra ID or Active Directory | As for software BitLocker | Needs a Group Policy setting; BitLocker’s usual recovery-key backup | The vendor’s tool; Kanguru documents an administrator password and a reset that erases the drive |
| Linux | No | No | No | Where the vendor supports it; Kanguru’s Opal Commander has Ubuntu 22.04 and RHEL installers |
| How to check it | Encryption Method in **manage-bde -status** shows an algorithm such as XTS-AES 128, not Hardware Encryption or Hardware accelerated | Encryption Method reads Hardware accelerated | Encryption Method reads Hardware Encryption | In the vendor’s tool, which shows lock status |

Microsoft warns that a self-encrypting drive is not automatically a Windows encrypted hard drive, which must also comply with specific TCG protocols and IEEE 1667. Confirm the device type before you plan on the third column.

## What a self-encrypting drive actually does

A self-encrypting drive encrypts everything written to it inside its own controller and decrypts it as it is read, using a media encryption key that the drive generates itself. That definition comes from the [joint white paper by the Trusted Computing Group and NVM Express](https://nvmexpress.org/wp-content/uploads/TCGandNVMe_Joint_White_Paper-TCG_Storage_Opal_and_NVMe_FINAL.pdf) on TCG Opal, the TCG specification aimed at corporate client drives. Opal adds a management interface for locking, a small pre-boot authentication environment stored on the drive (MBR shadowing) so that the operating system can be unlocked before it boots, and a cryptographic erase for repurposing a drive or ending its life.

Three limits matter when you set an SED against BitLocker:

- **It protects a drive that has lost power.** The white paper describes Opal protecting data at rest when or after the drive has been power cycled. Once unlocked, [Kanguru’s self-encrypting drive page](https://www.kanguru.com/pages/self-encrypting-internal-secure-ssds-opal-sed-hardware-based-solid-state-drives) says its drive “behaves like a normal SSD”. Sleep and resume behaviour depends on the platform and the vendor’s software, so test it.
- **It protects nothing until it is set up.** The drive encrypts all the time, but under Opal the data is locked only once an authentication credential has been set, and Kanguru’s key-renewal instructions say a reset drive can be used as a normal unencrypted drive.
- **It does not stop an attacker on a running system.** Malware, or anyone signed in, reads files exactly as the user does.

Some business laptops already ship with Opal drives: for example, [Lenovo’s PSREF sheet for the ThinkPad T14 Gen 5 (Intel)](https://psref.lenovo.com/syspool/Sys/PDF/ThinkPad/ThinkPad_T14_Gen_5_Intel/ThinkPad_T14_Gen_5_Intel_Spec.pdf), dated 6 May 2026, lists Opal 2.0 under security for its M.2 SSD options. That does not mean the laptop uses the drive’s encryption. BitLocker hands encryption to a drive only when it is a Windows encrypted hard drive and Group Policy allows it; otherwise the drive still encrypts internally, but its Opal locking sits idle unless a pre-boot authenticator or management tool switches it on.

## Why BitLocker stopped using SSD hardware encryption by default

Carlo Meijer and Bernard van Gastel of Radboud University and the Open University of the Netherlands reverse-engineered the firmware of SSDs from three manufacturers, produced between 2014 and 2018: internal SATA and NVMe models and external USB models. Their findings were made public on 5 November 2018 and published in [their paper for the IEEE Symposium on Security and Privacy 2019](https://www.ieee-security.org/TC/SP2019/papers/310.pdf). For many of those models, they report, the weaknesses allowed complete recovery of the data without the password, and BitLocker at the time relied entirely on the drive’s encryption whenever an SSD advertised it. Their advice was not to rely solely on hardware encryption offered by SSDs. The paper says nothing either way about drives it did not test.

Microsoft answered with [security advisory ADV180028](https://msrc.microsoft.com/update-guide/vulnerability/ADV180028) on 6 November 2018, telling concerned customers to consider BitLocker’s software-only encryption, enforced through Group Policy, and warning that a drive already encrypted in hardware must be decrypted and encrypted again to switch. Microsoft then changed the default: the release notes for [KB4516071, the 24 September 2019 update for Windows 10 version 1709](https://support.microsoft.com/en-us/help/4516071) (the same note appears in that day’s updates for versions 1607, 1703 and 1803), say newly encrypted self-encrypting drives get software encryption, while drives already encrypted keep their type.

### Where the policy stands in October 2026

- Microsoft’s [Configure BitLocker reference](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure) (updated 29 July 2025) says of the setting *Configure use of hardware-based encryption for operating system drives*: if you do not configure it, BitLocker will use software-based encryption, irrespective of hardware-based encryption availability.
- Microsoft lists no CSP for that setting, so it cannot be set from Intune’s BitLocker settings; it is a Group Policy setting under Windows Components, BitLocker Drive Encryption, Operating System Drives.
- With the policy enabled, the startup drive must still be a [Windows encrypted hard drive](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/encrypted-hard-drive) in an uninitialised state, on a UEFI 2.3.1 PC booting natively from UEFI with the compatibility support module disabled, on a non-RAID controller.
- Hardware encryption is still documented, and [Microsoft’s list of deprecated Windows features](https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features), updated 23 September 2026, does not include it.

## BitLocker in 2026: TPM, PIN and hardware acceleration

By default BitLocker unlocks the system drive with the TPM alone, so the user sees an ordinary sign-in. Microsoft’s [BitLocker planning guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide) calls TPM-only the most transparent option for organisations that need a baseline level of data protection, and recommends adding a second factor, such as a PIN, on devices with highly sensitive data. [Microsoft’s countermeasures guidance](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/countermeasures) treats TPM-only as enough against an attacker without much skill or with limited physical access. Against an attacker with skill and lengthy physical access, it recommends a TPM with a PIN protector, ideally an enhanced alphanumeric PIN, together with disabling standby and shutting down or hibernating the device before it leaves the control of an authorised user.

Sleep matters as much as the PIN: Microsoft notes that a device resuming from sleep does not ask for the PIN again, while one resuming from hibernation does. A PIN has costs too. Users who forget it need a recovery key from IT, and unattended restarts stop at the prompt; for devices on the wired corporate network, Microsoft offers BitLocker Network Unlock, which needs a direct Ethernet connection to a Windows Deployment Services server.

BitLocker can be switched on in Windows Pro, Enterprise, Pro Education/SE and Education. [Device encryption](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/) turns itself on for qualifying hardware on all editions, but Microsoft says the data stays unprotected until a recovery key is backed up to Microsoft Entra ID, Active Directory or a Microsoft account.

### Hardware-accelerated BitLocker

Announced at Microsoft Ignite in November 2025 and described on [Microsoft’s Windows IT Pro Blog on 19 December 2025](https://techcommunity.microsoft.com/blog/windows-itpro-blog/announcing-hardware-accelerated-bitlocker/4474609), hardware-accelerated BitLocker moves bulk encryption from the main processor to a dedicated crypto engine and, where the chip supports it, wraps the bulk key in hardware. Microsoft says supported devices with NVMe drives and a new crypto-offload system on chip use it with XTS-AES-256 by default, from the September 2025 update for Windows 11 24H2 and in 25H2. In that December 2025 post, Microsoft named Intel vPro devices with Intel Core Ultra Series 3 processors as the first to support it. Microsoft reports an average 70% saving in CPU cycles against software BitLocker, with results varying by hardware.

- **Check it** with manage-bde -status: the Encryption Method reads Hardware accelerated.
- **Encryption-method policies can block it.** A policy that sets an algorithm or key size the chip does not support keeps the device on software BitLocker. Microsoft’s December 2025 post gives AES-CBC as an example, and said a policy set to XTS-AES-128 blocked it too, pending a planned update that raises new enablements to XTS-AES-256.
- **FIPS policy.** With *System cryptography: Use FIPS 140 compliant cryptographic algorithms* enabled, it is used only if the chip reports FIPS certification of its key wrapping and crypto offload.

Because it depends on the processor, laptops already in service without a crypto-offload chip keep running software BitLocker. Ask the laptop maker whether a model you are buying supports it.

## When a self-encrypting drive earns its place

For a Windows fleet managed in Intune or Active Directory, the BitLocker set-up in the previous section is the starting point. A self-encrypting drive is worth adding, or choosing instead, in narrower cases.

| Situation | Usual answer | Check first |
|---|---|---|
| Windows laptops and desktops managed in Intune or Active Directory | BitLocker: TPM-only as Microsoft’s baseline, TPM and PIN for devices with highly sensitive data or facing a skilled attacker; hardware-accelerated where the processor supports it | PIN policy, recovery-key backup, sleep settings |
| A pre-boot lock that must not depend on Windows | A self-encrypting drive with its own pre-boot authenticator | How forgotten passwords are handled |
| Linux workstations | LUKS (Linux Unified Key Setup) disk encryption at installation; an SED where policy asks for a lock outside the operating system | Vendor support for your distribution |
| A tender or policy that names a self-encrypting drive or TCG Opal | May be met by an Opal drive already fitted in a business laptop, if the tender accepts it; otherwise a replacement or added drive, or one with a specific pre-boot tool | Whether FIPS 140 validation is required, and whether a historical certificate is accepted |
| Desktops and workstations taking extra or replacement drives | Either; an SED can be fitted at build or refresh | Slot, interface and warranty |
| Drives reissued or retired at short notice | Either; an SED’s factory reset generates a new key and loses all data | That the reset is recorded |

On Linux the default answer is software too: [Red Hat’s documentation](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/security_hardening/encrypting-block-devices-using-luks_security-hardening) says Red Hat Enterprise Linux uses LUKS for block device encryption, offered at installation with a passphrase at every boot.

Layering BitLocker over a drive’s own pre-boot login, as defence in depth, depends on the vendor’s pre-boot authenticator and the PC’s firmware. Kanguru’s published documents do not cover it, so ask us to confirm it with Kanguru for your models first.

Neither UAE text we checked says whether the encryption should run in software or in the drive. Control T3.4.2 of the [UAE Information Assurance Standard v2.1](https://csc.gov.ae/documents/38662/0/UAE+INFORMATION+ASSURANCE+STANDARD.pdf/abe25941-cdcf-2e44-9fd9-bf6bc8095f2a) (UAE Cyber Security Council, November 2025) requires the entities it covers to encrypt all classified data stored on end-user devices, including laptops and desktop computers. Those entities are federal ministries and authorities, non-government critical information infrastructure entities and, depending on the emirate, emirate government entities. The standard describes itself as technology agnostic. Section 6.1 of the [ADEK School Digital Policy](https://www.adek.gov.ae/-/media/Project/TAMM/ADEK/Policies/School-Policies/Health-safety-and-wellbeing/ADEK_S_Digital-Policy_EN.pdf) (version 1.1, September 2024) requires the schools it covers to implement hard disk device encryption. Whether a particular BitLocker or SED set-up satisfies either text is for your compliance team and auditor to decide, and no product makes an organisation compliant on its own; our [device management guide sets out the UAE IA Standard controls for device encryption](https://www.protechnology.ae/filewave-unified-endpoint-management-mdm-uae).

**Hypothetical example.** A design consultancy has 180 Windows 11 laptops in Intune and 12 Ubuntu rendering workstations. The laptops hold unreleased client designs and travel to client sites, so they get BitLocker with TPM and PIN, recovery keys in Microsoft Entra ID and hibernate rather than sleep; the workstations get LUKS at installation. Only when a client contract asks for a pre-boot lock that works without the operating system does the firm pilot self-encrypting drives in the workstations, after confirming support for its Ubuntu version.

## Rolling out self-encrypting drives across a fleet

The first three steps follow Kanguru’s knowledge base; the last two are our own advice. Decide before ordering who in your team will run each one, and ask us about anything the knowledge base does not cover; we will take it to Kanguru.

1. Install [Kanguru Opal Commander](https://www.kanguru.com/community/knowledgebase/kanguru-self-encrypting-drives-seds/kanguru-opal-commander). Version 1.2.0.1 (page updated 27 February 2026) enables encryption and manages security on the SED30 and SED300.
2. Download the matching pre-boot authenticator image: Kanguru publishes one for its NVMe models and one for the SATA model.
3. Run Opal Commander’s *Secure Initialization*, which secures the drive and sets the administrator password; Kanguru says to browse to the downloaded pre-boot authenticator image when the process asks for one. The same form has a *Create User* option for user accounts.
4. Record each machine’s drive serial number, the PSID printed on the drive and who holds the administrator password in [a device inventory](https://www.protechnology.ae/it-asset-inventory-device-software-uae-gcc). Once the drive is inside a laptop, the label is hard to reach. Keep that record restricted, because the PSID can reset the drive.
5. Pilot each laptop or desktop model before a wider order: sleep, hibernate, a firmware update and a reset.

Kanguru’s [SED30 product page](https://www.kanguru.com/products/kanguru-opal-sed30-m-2-nvme-internal-self-encrypting-solid-state-drive) also describes provisioning tools for setting enforceable security policies across a workforce; ask us to confirm what they cover for the model you order. Kanguru documents its remote management console for Defender USB devices, not these internal drives: [KRMC manages Defender USB and portable drives](https://www.protechnology.ae/kanguru-krmc-encrypted-usb-management).

Imaging needs a pilot too: Microsoft says images made with disk duplicators do not work for configuring Windows encrypted hard drives, and Kanguru’s duplicator documents do not cover self-encrypting drives, so do not plan on duplicator imaging until one machine has been imaged, initialised and tested; [the KanguruClone 11](https://www.protechnology.ae/kanguruclone-11-nvme-ssd-duplicator) and our [SATA and NVMe duplicators](https://www.protechnology.ae/hard-drive-ssd-duplicators-uae-gcc) explain imaging with ordinary drives.

### Reset and reissue

Kanguru’s [Reset to Factory](https://www.kanguru.com/community/knowledgebase/kanguru-self-encrypting-drives-seds-knowledge-base/how-to-generate-a-new-encryption-key-for-kanguru-sed30-and-sed300), run from Opal Commander with the administrator password or the PSID printed on the drive, reverts the drive to factory settings and generates a new encryption key, and Kanguru warns that all data on the drive is lost. [Back up the laptop first](https://www.protechnology.ae/data-backup-disaster-recovery-uae-business-continuity), record the reset in the asset record with the date and who ran it, and follow our [guide to clear, purge and destroy](https://www.protechnology.ae/secure-data-erasure-drive-decommissioning-uae) for the wider disposal process.

## If you choose a self-encrypting drive: fit checks before ordering

Kanguru’s SED30 is an M.2 2280 NVMe drive on PCIe Gen 4 x4. The SED300 comes as an M.2 2280 NVMe drive on PCIe Gen 3 x4 or as a 2.5-inch SATA drive. For capacities and the current range, see [Kanguru self-encrypting SSDs](https://www.protechnology.ae/kanguru#self-encrypting-ssd) on our Kanguru page and ask us to quote.

- **Slot or bay.** The NVMe models need a replaceable M.2 2280 slot wired for NVMe; the 2.5-inch model needs a SATA bay. Check the maker’s specification sheet; some thin designs have no replaceable storage.
- **Firmware and storage mode.** Ask us to confirm with Kanguru that its pre-boot authenticator supports your PCs’ UEFI settings and storage controller mode.
- **Warranty.** Ask the laptop maker whether replacing the factory drive affects the warranty or support contract.
- **Operating system.** Kanguru’s datasheets state Windows and Linux. Macs are outside this guide.
- **Keys.** Decide before delivery who holds administrator passwords and PSID records.

### Certificate numbers on the quotation

Ask for a certificate number, not a logo. On NIST’s register, certificates [#4295](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4295) and [#4005](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4005) cover the Kanguru Defender SED300 at FIPS 140-2 Level 2 (#4295 lists both NVMe and SATA part numbers, #4005 older ones); both are on the historical list, and both apply only when the module is operated in FIPS mode and set up as its security policy specifies. The SED30 has no FIPS 140 certificate. Check the part number on your quotation against the NIST entry; [our guide to what each FIPS certificate covers and how to check one](https://www.protechnology.ae/fips-140-3-encrypted-usb-compliance-uae-gcc) explains the rest.

## What to send us for an SED quotation

PRO TECHnology is Kanguru’s exclusive distributor and partner for the Middle East. Kanguru [announced the partnership on 1 September 2021](https://www.kanguru.com/blogs/news/kanguru-announces-partnership-with-dubai-based-it-solutions-provider-pro-technology), and Kanguru’s partner directory for Europe, the Middle East and Africa lists PRO TECHnology for the UAE, Saudi Arabia, Qatar, Kuwait, Oman, Bahrain and Jordan. You can read [how the Kanguru partnership started](https://www.protechnology.ae/kanguru-appoints-pro-technology-exclusive-distributor-middle-east).

If an SED is the right answer for part of your fleet, send us the number of laptops and desktops, their makes and models, the operating systems, the slot or bay, the capacity you need and any certificate a tender or policy names. We will quote the matching Kanguru drives and say where BitLocker alone is enough. Saudi enquiries are handled by PRONEXT in Riyadh; [Enterprise IT in Saudi Arabia](https://www.protechnology.ae/enterprise-it-solutions-saudi-arabia) covers the NCA ECC and SAMA controls on devices and storage media.

## Sources

Microsoft Learn pages, the Windows IT Pro Blog post, advisory ADV180028, the KB4516071 release note, NIST CMVP certificates, Kanguru’s product pages, knowledge base, partnership announcement and EMEA partner directory, Lenovo’s PSREF sheet and Red Hat’s documentation were read on 8 October 2026, with update dates given where the page shows them; pages not listed below are linked where they are cited, apart from Kanguru’s EMEA partner directory, found under Where to Buy on kanguru.com. The regulatory wording was read in the UAE Information Assurance Standard v2.1 and the ADEK School Digital Policy v1.1; this is not legal advice.

- [Microsoft Learn: Encrypted hard drives (updated 25 February 2025)](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/encrypted-hard-drive)
- [Microsoft Learn: Configure BitLocker (updated 29 July 2025)](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure)
- [Microsoft Learn: BitLocker countermeasures (updated 29 July 2025)](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/countermeasures)
- [Microsoft Learn: BitLocker planning guide (updated 29 July 2025)](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide)
- [Microsoft Learn: BitLocker overview (updated 24 August 2026)](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/)
- [Microsoft Windows IT Pro Blog: Announcing hardware-accelerated BitLocker (19 December 2025)](https://techcommunity.microsoft.com/blog/windows-itpro-blog/announcing-hardware-accelerated-bitlocker/4474609)
- [Microsoft Security Response Center: ADV180028, guidance for configuring BitLocker to enforce software encryption (6 November 2018)](https://msrc.microsoft.com/update-guide/vulnerability/ADV180028)
- [Microsoft Support: KB4516071 (Windows 10 version 1709), 24 September 2019](https://support.microsoft.com/en-us/help/4516071)
- [Meijer and van Gastel: Self-encrypting deception, weaknesses in the encryption of solid state drives (IEEE S&P 2019)](https://www.ieee-security.org/TC/SP2019/papers/310.pdf)
- [Trusted Computing Group and NVM Express: TCG Storage, Opal, and NVMe joint white paper (August 2015)](https://nvmexpress.org/wp-content/uploads/TCGandNVMe_Joint_White_Paper-TCG_Storage_Opal_and_NVMe_FINAL.pdf)
- [NIST CMVP: certificate #4295, Kanguru Defender SED300](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4295)
- [Kanguru: Defender SED self-encrypting drives overview](https://www.kanguru.com/pages/self-encrypting-internal-secure-ssds-opal-sed-hardware-based-solid-state-drives)
- [Kanguru knowledge base: Kanguru Opal Commander (updated 27 February 2026)](https://www.kanguru.com/community/knowledgebase/kanguru-self-encrypting-drives-seds/kanguru-opal-commander)
- [Kanguru knowledge base: How to generate a new encryption key for the SED30 and SED300 (updated 18 February 2026)](https://www.kanguru.com/community/knowledgebase/kanguru-self-encrypting-drives-seds-knowledge-base/how-to-generate-a-new-encryption-key-for-kanguru-sed30-and-sed300)
- [Kanguru: partnership announcement with PRO TECHnology (1 September 2021)](https://www.kanguru.com/blogs/news/kanguru-announces-partnership-with-dubai-based-it-solutions-provider-pro-technology)
- [UAE Cyber Security Council: UAE Information Assurance Standard v2.1 (November 2025)](https://csc.gov.ae/documents/38662/0/UAE+INFORMATION+ASSURANCE+STANDARD.pdf/abe25941-cdcf-2e44-9fd9-bf6bc8095f2a)

## Frequently asked questions

**Does BitLocker use a self-encrypting drive’s hardware encryption by default?**

No. Microsoft’s 24 September 2019 updates for several Windows 10 versions (KB4516071 for version 1709, for example) made software encryption the default for newly encrypted self-encrypting drives, and Microsoft’s current policy reference says that if the hardware-encryption setting for operating system drives is not configured, BitLocker uses software-based encryption whatever the drive supports. Hardware encryption is used only when that Group Policy setting is enabled and the drive is a Windows encrypted hard drive that meets the TCG and IEEE 1667 requirements. Drives encrypted in hardware before the change kept their encryption type.

**How can I tell which encryption method BitLocker is using on a laptop’s system drive?**

Open a command prompt as an administrator and run manage-bde -status. In the Encryption Method field, Hardware Encryption means BitLocker has handed encryption to a Windows encrypted hard drive, and Hardware accelerated means the processor’s crypto engine is doing the work on a supported new laptop. If it shows an algorithm such as XTS-AES 128 instead, the drive is encrypted in software; None means it is not encrypted. Microsoft’s 2018 advisory ADV180028 describes the first check, and its December 2025 blog post on hardware-accelerated BitLocker describes the second.

**Is hardware-accelerated BitLocker the same as a self-encrypting drive?**

No. Hardware-accelerated BitLocker is still BitLocker: Windows manages the keys, the TPM and PIN options and recovery, but bulk encryption runs on a dedicated crypto engine in the processor package and, where the chip supports it, the bulk key is wrapped in hardware. A self-encrypting drive encrypts inside the SSD controller and, with its own pre-boot authenticator, locks before any operating system loads. Microsoft’s December 2025 post named Intel vPro devices with Core Ultra Series 3 processors as the first with support; ask the laptop maker about other models.

**Can we run BitLocker on a laptop that already has a self-encrypting drive?**

Yes in the ordinary case. If the drive’s own Opal locking has not been set up, BitLocker encrypts it in software like any other drive, which is the Windows default. It is different when the drive’s own pre-boot authenticator is active. Whether BitLocker with TPM and PIN works alongside a particular vendor’s pre-boot login depends on that vendor and the PC’s firmware, so confirm it with the drive maker and test it on each laptop model before a rollout.

**Is a self-encrypting drive still faster than BitLocker in 2026?**

It depends on the laptop. Microsoft’s encrypted hard drive page says drive-based encryption runs at full data rate. Software BitLocker runs on the main processor, and Microsoft says fast NVMe drives make that cost more noticeable in heavy read and write work. On new laptops with a crypto-offload chip, Microsoft reports that hardware-accelerated BitLocker saves on average 70% of CPU cycles compared with software BitLocker and can approach unencrypted NVMe performance. Laptops already in service without such a chip run software BitLocker, so if speed is the concern, test your own workloads before paying for different drives.

**What is the difference between a self-encrypting drive and a Windows encrypted hard drive (eDrive)?**

Every Windows encrypted hard drive is self-encrypting, but not every self-encrypting drive qualifies. Microsoft says the two are not the same type of device: an encrypted hard drive must comply with specific TCG protocols and with IEEE 1667, so that Windows can identify it and BitLocker can manage its hardware encryption. A plain Opal drive without that support can be locked only through a pre-boot authenticator or management tool, such as the drive maker’s, or used as an ordinary drive under software BitLocker.

**Does a self-encrypting drive protect a laptop that is asleep or left switched on?**

Not while it is unlocked. A self-encrypting drive protects data once it has lost power and locked; after the user unlocks it, it serves data like an ordinary drive (Kanguru says its drive “behaves like a normal SSD”), so a running laptop is as exposed as any unlocked disk. Behaviour on sleep and resume depends on the platform and the vendor’s software, so test it. For BitLocker, Microsoft notes that resuming from sleep does not ask for the PIN again, and recommends hibernate or shutdown before a device leaves the user’s control.

**What happens if an employee forgets the pre-boot password on a self-encrypting drive?**

Plan for it before rollout. With BitLocker, IT unlocks the drive with the recovery key backed up to Microsoft Entra ID or Active Directory. Of Kanguru’s published procedures for its self-encrypting drives, the one that does not need the user’s password is Reset to Factory, run with the administrator password or the PSID printed on the drive. Kanguru documents it for generating a new key, and it loses all data. Ask us to confirm with Kanguru whether an administrator can reset a user’s password without erasing the drive, and keep user files backed up or synced.

**Can Intune or another MDM switch BitLocker to hardware encryption on the system drive?**

Not through Microsoft’s documented settings. Microsoft’s Configure BitLocker reference lists the setting for hardware-based encryption on operating system drives as Group Policy only, with no configuration service provider, so Intune’s BitLocker settings cannot set it. Intune can still enforce software BitLocker, startup authentication such as TPM and PIN, and recovery-key backup. On new laptops with supported chips, hardware-accelerated BitLocker is used by default with XTS-AES-256, provided the policy’s encryption method is one the chip supports: AES-CBC blocks it, and Microsoft’s December 2025 post said XTS-AES-128 did too, pending a planned update that raises new enablements to 256-bit.

**Can a self-encrypting drive protect Linux workstations?**

Yes, if the vendor supports your distribution, but it is not the usual first choice. Linux has its own full-disk encryption: Red Hat’s documentation says Red Hat Enterprise Linux uses LUKS for block device encryption, offered as an option at installation with a passphrase at every boot. A self-encrypting drive adds a pre-boot lock that does not depend on the installed system. Kanguru, for example, lists Opal Commander installers for Ubuntu 22.04 and RHEL, so check any other distribution with the vendor.

## القرص ذاتي التشفير أم BitLocker؟ تشفير قرص النظام في حواسيب الشركات

يقتصر هذا الدليل على القرص الداخلي الذي يُقلع منه الحاسوب، أما أقراص USB والأقراص المحمولة فلها قرار مختلف. في معظم حواسيب الشركات المحمولة والمكتبية التي تعمل بنظام Windows، يكون الخيار المعتاد لقرص النظام هو BitLocker مع حفظ مفاتيح الاسترداد مركزيًا؛ وتعدّ Microsoft الاعتماد على شريحة TPM وحدها المستوى الأساسي، وتوصي بإضافة رمز PIN عند الإقلاع واستخدام السبات أو الإيقاف الكامل بدل وضع السكون للأجهزة التي تحمل بيانات شديدة الحساسية أو المعرّضة لمهاجم متمرّس يمكنه الوصول إليها فعليًا لمدة طويلة. ومنذ تحديثات Windows 10 الصادرة في سبتمبر 2019 يشفّر BitLocker برمجيًا الأقراص ذاتية التشفير التي يُفعَّل تشفيرها حديثًا ما لم يُفعَّل إعداد نهج المجموعة الخاص بالتشفير العتادي، ولا تُدرج Microsoft لهذا الإعداد على قرص النظام أي موفّر خدمة تكوين (CSP)، لذا لا يمكن ضبطه من إعدادات BitLocker في Intune، فهو إعداد في نهج المجموعة فقط. أما BitLocker المسرَّع عتاديًا، الذي أعلنته Microsoft في مؤتمر Ignite في نوفمبر 2025 وشرحته في مدوّنتها في ديسمبر 2025، فينقل عمليات التشفير إلى محرك تشفير مخصص داخل المعالج في الأجهزة الجديدة الداعمة، وقد سمّت Microsoft أجهزة Intel vPro بمعالجات Core Ultra Series 3 أولَ الأجهزة الداعمة له، بينما تبقى الأجهزة العاملة حاليًا دون هذه الشريحة على التشفير البرمجي.

وبعض حواسيب الأعمال تُشحن أصلًا بأقراص تدعم Opal، لكن BitLocker لا يستخدم تشفيرها العتادي إلا إذا كان القرص من فئة الأقراص المشفّرة لنظام Windows وفُعّل إعداد نهج المجموعة، وإلا يبقى قفل Opal غير مفعَّل، مع أن القرص يواصل التشفير داخليًا، ما لم تُشغّله أداة مصادقة قبل الإقلاع أو أداة إدارة. ويصبح القرص ذاتي التشفير وفق معيار TCG Opal خيارًا مناسبًا عند الحاجة إلى قفل قبل الإقلاع لا يعتمد على نظام Windows، أو في محطات Linux، التي تستخدم عادةً تشفير LUKS عند التثبيت، حين تطلب سياستها قفلًا مستقلًا عن نظام التشغيل، أو في مناقصة تشترط هذا النوع من الأقراص، أو عند الحاجة إلى توليد مفتاح جديد بسرعة قبل إعادة تسليم الجهاز، علمًا بأن إعادة الضبط تمحو جميع البيانات. ويُدار تجهيز أقراص Kanguru Defender الداخلية ذاتية التشفير (SED30 وSED300) عبر برنامج Opal Commander الذي يوفّر مُثبّتات لأنظمة Windows وUbuntu 22.04 وRHEL. وشهادتا FIPS 140-2 من المستوى الثاني لطراز SED300 مدرجتان في القائمة التاريخية لدى NIST، أما طراز SED30 فلا يحمل شهادة FIPS 140.

بروتكنولوجي (PRO TECHnology) هي الموزع الحصري والشريك لـ Kanguru في الشرق الأوسط، وقد أعلنت Kanguru هذه الشراكة في 1 سبتمبر 2021، ويُدرج دليل شركائها لأوروبا والشرق الأوسط وأفريقيا بروتكنولوجي في الإمارات والسعودية وقطر والكويت وعُمان والبحرين والأردن. أرسلوا إلينا عدد الأجهزة وطرازاتها وأنظمة التشغيل وفتحة القرص أو حجيرته والسعة المطلوبة وأي شهادة تشترطها المناقصة أو السياسة، لنرسل لكم عرض سعر لأقراص Kanguru المناسبة ونوضح متى يكفي BitLocker وحده. وتتولى PRONEXT في الرياض استفسارات العملاء في المملكة العربية السعودية.

## Planning a laptop or desktop refresh? Ask before you order drives

Not sure an SED is needed? Ask us first: for many fleets BitLocker alone is enough, and where it is not, we will quote the Kanguru drive that fits.

[Talk to our team](https://www.protechnology.ae/contact-us)[Kanguru self-encrypting SSDs](https://www.protechnology.ae/kanguru#self-encrypting-ssd)[Enterprise IT solutions](https://www.protechnology.ae/enterprise-and-corporate-it-solutions)
