Secure Disk for BitLocker now accepts PIV smartcards for pre-boot authentication. Your users unlock their encrypted drive before Windows starts, with the credential that suits them: a contact smartcard, a contactless NFC card or a USB token.
BitLocker protects data at rest. But in the common TPM-only setup, the drive is decrypted automatically when the device starts, with no user involved. Whoever holds the laptop reaches the Windows logon screen with the disk already unlocked.
Attacks such as cold boot and DMA attacks target exactly that moment. Strong authentication before Windows starts closes the gap, and a PIV smartcard is one of the most robust and widely accepted ways to do it.
Ask us about your BitLocker setupNo proof of who is starting the device. A lost or stolen laptop boots to an unlocked drive.
Passwords get written down, reused and phished. They prove knowledge, not possession.
Something you have (the PIV card or token) plus something you know (the PIN). The private key never leaves the chip.
PIV is an open standard. You decide how the credential reaches the device, per user group or per site, and you can mix form factors in one deployment.
The classic: insert the PIV card into a built-in or external smartcard reader and enter the PIN.
Tap the PIV card on the NFC reader, enter the PIN, done. Fast and with no wear on the card or the reader.
A PIV-capable USB security key (for example a YubiKey 5 series key) holds the certificate. Plug it in, enter the PIN and the drive unlocks.
Secure Disk for BitLocker starts its pre-boot authentication before Windows loads. The BitLocker volume stays locked.
The user inserts the smartcard, taps the NFC card or plugs in the USB token.
The PIN unlocks the private key on the chip, and the certificate-based check confirms the user is authorised for this device.
The drive is decrypted and Windows starts. With single sign-on, the user continues straight to the desktop.
An online demo with our engineers, covering all three form factors.
Works with PIV credentials following NIST FIPS 201 and SP 800-73.
Contact smartcard, contactless NFC card or USB token, freely combinable.
Possession of the card plus knowledge of the PIN. The private key stays on the chip.
The user is verified before Windows and BitLocker unlock the disk.
One authentication from power-on to the desktop.
Several users, each with their own PIV credential, can unlock the same device.
Manage policies, users and recovery keys from one console, which is included.
Use existing certificates and directory groups for a smooth roll-out at scale.
Protect older or mixed hardware fleets with the same strong authentication.
Prove encryption and authentication status to auditors at any time.
Use the PIV and ID cards your staff already carry to meet strict requirements for protecting classified and personal data.
Hardware-bound two-factor authentication before boot for suppliers and operators with high security obligations.
Fast NFC tap-and-PIN unlock on shared ward and practice devices that hold patient data.
Meet regulatory expectations for strong authentication and endpoint encryption on every notebook.
Protect client confidentiality on devices that travel to courts, clients and home offices.
Keep intellectual property locked even if a notebook is lost or stolen.
Secure Disk for BitLocker is licensed per Windows device, regardless of how many users work on it. PIV smartcard authentication is available from USD 50 per device.
Volume pricing applies to larger roll-outs. Maintenance and support are available for 1, 2 or 3 years. Contact us for a quote tailored to your number of devices and your preferred form factors.
Request your personal quotePerpetual licence plus optional maintenance. Smartcards, readers and USB tokens are not included. Prices exclude VAT.
Tell us about your environment, whether smartcards, NFC or USB tokens, and our team will show you how PIV pre-boot authentication fits in, with a live demo and a quote tailored to you.