Secure Disk for BitLocker now supports FIDO2 security keys. They work like an extra BitLocker protector: before Windows starts, the user plugs in the FIDO2 security key, enters the FIDO2 PIN, and the BitLocker-protected Windows PC boots. Fully offline, with no web service, and multi-factor thanks to the FIDO2 PIN.
FIDO2 security keys usually protect sign-ins once Windows is running. Secure Disk for BitLocker brings the same key to pre-boot: it works like an extra BitLocker protector, so the user can boot a BitLocker-protected Windows PC with it.
BitLocker's own USB startup key is a key file stored on an ordinary USB stick. Anyone who copies that file holds the key. And FIDO2 keys are not available as a BitLocker protector in Windows itself.
Secure Disk for BitLocker adds the FIDO2 security key as an additional way to unlock the Windows system drive, before Windows starts. The secret stays inside the key's secure chip and is protected by the FIDO2 PIN. It works fully offline, with no web service involved.
FIDO2 is built on public-key cryptography. There is no shared secret to type into a fake page or steal from a server.
A FIDO2 key works with hundreds of applications and web services, from Microsoft Entra ID and Windows Hello for Business to Google, GitHub and many more.
FIDO2 is an open standard of the FIDO Alliance, supported by many vendors in USB-C and USB-A form factors.
The secret is generated inside the security key and cannot be exported or copied, unlike a key file on a USB stick.
No web service, FIDO server or internet connection is needed. The check runs locally between the PC and the key, before Windows starts.
Possession of the security key plus knowledge of the FIDO2 PIN: two factors at every boot. The key locks itself after too many wrong PIN attempts.
Your FIDO2 security key already protects sign-ins to many different services. Unlocking BitLocker with Secure Disk for BitLocker is simply one more cryptographic use of the same key, and your other services keep working as before.
We encourage you to use your existing FIDO2 keys for this added encryption benefit. No new hardware, no new habit for your users.
Check my FIDO2 keysSecure Disk for BitLocker starts its pre-boot authentication before Windows loads. The BitLocker volume stays locked.
The user plugs the FIDO2 security key into a USB-C or USB-A port.
The FIDO2 PIN unlocks the key, and a touch on the key confirms the user is present. Secure Disk for BitLocker verifies the user is authorised to boot this device, fully offline.
The drive is decrypted and Windows starts. With single sign-on, the user continues straight to the desktop.
An online demo with our engineers, from plugging in the key to the Windows desktop.
Works with FIDO2 security keys following the open FIDO Alliance standard.
Plug-in security keys for notebooks and desktops, freely combinable.
Possession of the FIDO2 key plus knowledge of the FIDO2 PIN, confirmed by a touch.
The user is verified before Windows and BitLocker unlock the disk.
One authentication from power-on to the desktop.
Several users, each with their own FIDO2 key, can unlock the same device.
Manage policies, users and recovery keys from one console, which is included.
With Secure Disk for BitLocker 8 and Windows 11, TPM 2.0 strengthens BitLocker and prevents brute-force attacks.
No web service, FIDO server or internet connection needed at boot.
Choose FIDO2 keys from different vendors instead of being tied to one.
Prove encryption and authentication status to auditors at any time.
Secure Disk for BitLocker works with standard FIDO2 security keys. Three typical examples:

Widely used USB-C security key. FIDO2 sits next to PIV, OTP and OpenPGP on one key.

FIDO2 security key from Swissbit. FIDO2 is included in every model; a FIPS 140-3 version is available.

FIDO2.1 certified security key in USB-C and USB-A versions, with optional PIV for certificate-based login.
Illustrations are symbolic. Using a different FIDO2 key? Ask us about compatibility.
Extend your FIDO2 rollout for Windows Hello for Business or Entra ID passkeys to the very first step: booting the PC.
Notebooks on the road stay locked until the owner plugs in their key, with or without a network connection.
Strong pre-boot authentication with affordable, off-the-shelf security keys.
Personal security keys protect patient data on shared and mobile clinical devices.
Phishing-resistant authentication that meets regulatory expectations, from boot to sign-in.
Hardware-bound protection for confidential data on every notebook, based on an open standard.
Secure Disk for BitLocker is licensed per Windows device, regardless of how many users work on it. FIDO2 security key support is available from USD 50 per endpoint.
Volume pricing applies to larger roll-outs. Maintenance and support are available for 1, 2 or 3 years. Request a quote tailored to your number of devices.
Request your personal quotePerpetual licence plus optional maintenance. Security keys are not included. Prices exclude VAT.
Tell us about your environment and the security keys you use, and our team will show you how FIDO2 pre-boot authentication fits in, with a live demo and a quote tailored to you.