Windows Laptop Encryption

Overview

The purpose of Laptop Encryption is to ensure that in the event of theft, the data stored on a University owned laptop is not accessible by external parties. 

Scope

  • All Windows laptops purchased under the current OGP/HEAnet procurement framework, including laptops purchased using external research funding
  • Existing University owned Windows laptops currently in use on campus
  • The policy applies to Windows 11 

Pre-requisites

The laptop must be connected to University of Galway’s Active Directory service. This is normally done as part of the Node Registration process.

How to encrypt your laptop

 New Laptops

All Dell laptops ordered from the current supplier will be encrypted. The process is as follows:

  • A laptop will be ordered directly by a unit or by ISS under the Registrars Staff PC Scheme
  • The supplier will deliver the laptop to the address indicated on the order. It is the staff members responsibility to ensure the address is accurate
  • When you receive your new device, please do not start it up. Please log a ticket to ISS so that we can begin the process of adding your device to the network including encryption.
  • Once encrypted, the used will be asked to assign a unique PIN number to their laptop
  • A Master Encryption key will be stored in Active Directory. This is to ensure the device can be recovered by ISS in the event of a PIN been forgotten by the system owner

 Existing Laptops

All standard devices purchased through Dell should be encrypted. When you register your device, encryption is part of that process.

However, if you have a standard device that has so far not been encrypted, you must log a ticket to get this done to comply with all relevant university security standards.

The system owner should do the following:

- Raise an ISS ticket either by ringing 5777 or emailing servicedesk@universityofgalway.ie

- It will be logged under the following category  03 Desktop/Laptop Support - Laptop Encryption

- Please ensure you have a backup of all your data using OneDrive (check it online to ensure it has everything) or using a backup USB external hard drive

- Data taken off the laptop is NOT encrypted when emailed/moved to another computer. Data is only encrypted whilst on the actual laptop

- Please give an appropriate PIN you wish to use -  do not share this with anyone and do not have the PIN labelled on your device. Please keep it in a safe place external to your device in case you forget it for example

NB: If you laptop is encrypted and subsequently suffers an error with the operating system (Windows 10/11) OR the laptop hard drive fails, ISS CANNOT recover any data on the laptop due to its encrypted state. It is vitally important that any local data on the laptop is frequently backed up to another source like OneDrive (recommended).

OneDrive is the best method to use as any changes are automatically made to the cloud, but it is important you check OneDrive on your web account to ensure it is accurately synching up all your data.

Exceptions

Please take note of the following:

ISS will not encrypt laptops purchased outside of the OGP/HEAnet framework

ISS cannot encrypt older models where the BIOS/OS does not support BitLocker encryption

ISS will not encrypt Linux laptops or dual-boot laptops

In the event of any of the above exceptions, it is the responsibility of the user to ensure that no sensitive data is stored locally on the device

*Windows 10 is end of life in October 2025 -  it is strongly recommended that the device is reimaged to Windows 11 (if compatible) or you purchase a new replacement device that will have a University approved/supported configuration. Please contact the Service Desk if you wish to get more information