Hi,
ok, let me try to answer a few of your questions.
@
admin: Feel free to join in and correct me if something in my reply should be wrong
Here we go!
(4 hours ago)zx81 Wrote: Unlocking bitlocker just refers to logging into my PC which decrypts everything automatically in the background. Whereas, manually decrypting a disk means disabling bitlocker on that disk, which removes its encryption completely.
Unlocking Bitlocker doesn't change any data on your drive, the encryption stays intact and data is decrypted in memory on the fly.
Decrypting unlocks the drive by rewriting all data on the disk unencrypted which removes BitLocker completely.
(4 hours ago)zx81 Wrote: So with Hasleo Backup Suite, system images and file/folder backups are backed-up with encryption intact and also restored with encryption intact. No user intervention required. Easy and simple.
In general that's right. But the details are important:
If you boot a WinPE image, VSS is not available. If you're currently within Windows, VSS is available.
Keep that in mind for the following:
Image backups:
If the source drive is BitLocker encrypted, currently unlocked and VSS is available (e.g. you booted a BitLocker encrypted OS), your data will be backed up BitLocker unencrypted. That means data is saved in the image file as if there was no BitLocker. That's why it's important to set a backup password to protect your image. If you restore (delta or normal) your data from that image, you'll have the option to retain BitLocker. So your data will be put back on the drive and BitLocker will be enabled like nothing ever happened.
If your source drive is BitLocker encrypted, but currently locked or VSS is not available (e.g. you booted from WinPE or try to back up a third partition that is still locked), your data can only be backed up sector-by-sector, which basically is a forensic copy of the BitLocker locked partition that can't be accessed or looked into directly. You can restore that as well, but only sector-by-sector as a large inaccessible binary block of data.
File/Folder backups:
Those will only work if your BitLocker partition is unlocked and files can be accessed. For restore, make sure your destination partition has BitLocker unlocked or doesn't use BitLocker at all.
Data is restored by just copying the data back to the partition.
(4 hours ago)zx81 Wrote: When cloning a bitlocker encrypted source disk, the encryption will remain intact on the source disk but will not be carried forward onto the target disk. Bitlocker encryption will need to be manually re-enabled on the new clone disk.
Just like with image backups, that is true if the source disk is currently unlocked and VSS is available, e.g. you booted into Windows and try to clone your system disk. Cloning will not keep BitLocker, your data will be unencrypted on your destination disk as if BitLocker was never enabled. You can then boot from your cloned disk and reenable BitLocker from scratch, which will take a bit because all data needs to be encrypted again.
(4 hours ago)zx81 Wrote: Question: I assume the encrypted source drive which is being cloned doesn’t need to be installed inside the computer (eg. C: drive) and HSB can clone an encrypted external USB drive to another USB drive?
Yes, that can be done. Cloning a Windows partition to USB is only available in HBS Home or higher, not in the Free edition. See this
comparison chart for details.
Remember: Destination disk will only be encrypted if you copied the locked source disk sector-by-sector.
(4 hours ago)zx81 Wrote: Question: Does all of this assume that when cloning an encrypted disk, HBS should be run from regular Windows system booted normally, so the disk will be unlocked and decrypted anyway. Rather than running it from WinRE/PE (whatever it’s called) rescue/boot media?
In general I would always recommend to run HBS from within Windows so that you have VSS available. Only with VSS you get all the HBS features when it comes to BitLocker.
(4 hours ago)zx81 Wrote: I ask this because a while back, someone on the Macrium reflect forum said the best way to create a system image or disk clone is to boot from the WinRE/PE rescue media and run the clone or image backup from there, so it will forensically duplicate every sector identically, whereas running it from regular Windows does not. But does this mean the source system disk would still be encrypted because I wouldn’t be logged in to my user account? So which is best method to run HBS?, from the actual installed program booting windows normally or boot from rescue media?
Your source disk will always stay encrypted and untouched, if that's what you ask. The method you choose only changes the outcome of the destination drive.
You can always clone your drives sector-by-sector while keeping your data BitLocker locked. But then you can't change the size of the destination partition because the data will be a huge (scrambled) binary block of data.
I personally would recommend unlocking (not decrypting!) your drives first. Then image/clone your data in that state.
HBS has you covered when it comes to images, you can always restore your data while retaining BitLocker. And for clones you can just reenable BitLocker. Yes, it will take some time but SSDs are still quite fast. Even if you only get around 500 MB/s and your whole 2 TB drive is full of data, your BitLocker encryption should be done in 1-2 hours.
(4 hours ago)zx81 Wrote: I want to get this all straight in my head. I have more cloning/imaging programs than I need and some are more limited than Hasleo. I have Hasleo Disk Clone pro, Hasleo Backup Suite home/family, Macrium Reflect 8, Samsung Migration tool, plus a few others. But Hasleo software seems by far the most user friendly.
Totally get your point. It's sometimes confusing and BitLocker is quite complicated if you ask me

.
I also tested a lot of tools and ended up sticking with HBS.
It just works
Hope my answers helped a bit!
Cheers,