Dualbooting Windows 11/Zorin OS 18 and Hard Driver Encryption

I currently have Zorin OS 18 installed in my SSD. I'll also install a windows 11 dual boot with rufus but i don't want more future headaches so i have a couple questions.

1 - Should i install Windows 11 first and then select Install Zorin OS alongside Windows 11 or first install Zorin and then Windows?

2 - Can i activate hard drive encryption for both my Zorin Installation and Windows? Windows uses bitlocker apparently, i never used it before. Can i use both at the same time? And also will Windows 11 force me to use a microsoft account if enable bitlocker despite me having a local account?

3 - I never used disk encrytion before but since i'm using a laptop now i have some concerns for security. If it gets stolen etc. I read that hard drive encryption can cause more corrupted files, is that true? Also will it slow down and bog the pc down?

4 - Is removing Secure Boot and TPM 2.0 requirements for Windows 11 a good idea? I assume that my pc supports it (Never checked though pretty sure) but I'm wary of breaking stuff in the future.

From me to this a definetely Yes. I would would install Windows first and then Zorin.

For the Encryption Stuff, I can't help You sorry. But would guess that You only can use on Encryption Type when You encrypt with it the whole Drive.

For Windows it can make Sense to have it, yes. On Linux it can cause more Issues than it helps.

So if i don't check the Disable BitLocker automatic device encrytion for windows 11, and bitlocker is enabled, will i have a problem installing Zorin.

I was asking more in terms of the rufus installation. Rufus can just remove the requirements for TPM and Secure Boot. Should i do that? Will it cause more problems down the line?

If BitLocker is enabled, you will not be able to successfully install Zorin OS - it encrypts the drive preventing write access.

No, this will not cause problems later.
This removes the stipulation for them, not how or whether they function.

1 Like

Is there a way to just encrypt the windows partition with bitlocker? And use the other partition for Zorin and encrypt it separately?

I was thinking of installing Windows 11, disabling bitlocker after installation, installing zorin alongside windows and then reenabling bitlocker. This way both parts would be encrypted. I'm hoping that Zorin allows for just a single partition to be encrypted.

Yes. You can disable BitLocker from within WIndows > control panel > Privacy and security only for the duration of installing Zorin OS.
BitLocker will monitor the bootchain, so if it is enabled during the install of Zorin OS, it will block write to disk for boot files.

I am not very familiar with BitLocker, but certainly there are guides available for specifying a partition.

Zorin OS uses LUKS encryption which by default, encrypts the whole drive (with some small exceptions), but it can be restricted to just the partitions you use for Zorin OS.

No, BitLocker only operates with NTFS format, whereas Zorin OS uses EXT4 by default.

Do i need to do anything extra to encrypt only it's own partition in Zorin or will i have the option to do that in the installation screen?

I meant like 2 different partitions and 2 different encryption methods for those partitions. One for Zorin and one for Windows 11.

Bitlocker and LUKS can interfere with each other and this can result in data loss.

What you are asking about can be done - but you need more expert advice than I can give - I know little about BitLocker.

1 Like

Alright thank you. I'll only do bitlocker probably