Guidance for encrypting UBC-owned and personally owned devices used for Microbiology and Immunology work, research, and teaching activities.
Why should I encrypt my devices?
At UBC, we are regulated by the Freedom of Information and Protection of Privacy Act (FIPPA), which requires us to protect personal information from unauthorized collection, use, or disclosure. In support of the law, UBC policy requires that all mobile devices storing personal information must be encrypted. More information is available on the UBC Privacy Matters website.
Encryption prevents unauthorized access to electronic data on computers, laptops, phones, and removable storage. It helps protect documents, email, and research-related information if a device is lost, misplaced, or stolen.
Device ownership and support
- UBC-owned devices — for devices purchased with UBC funds, MBIM IT will enable encryption for you. Please contact us to arrange drop-off.
- Personally owned devices — employees and students may use supported self-service encryption options, but personal devices used for department work must still meet UBC security requirements.
- Windows Education access — Windows 11 Education, Pro, and Enterprise support BitLocker. If you use Windows Home, review the Azure subscription options below.
- Verification required — after encrypting a personal device, bring it to MBIM IT so encryption can be confirmed for departmental compliance.
Department policy for personally owned devices
Encryption is required for work use. All personally owned systems used in the Department of Microbiology and Immunology for work must be encrypted. Once you complete encryption, please visit MBIM IT with your device so we can verify it was successfully encrypted. If the device is not encrypted and not reviewed with us, your lab manager may be notified.
Devices that cannot be encrypted should not be used for work. Personal mobile devices that cannot be encrypted because of age or hardware limitations are not suitable for work purposes. Please contact your lab if your device cannot meet the Information Security Standards so alternate equipment can be assigned.
Please also review the BYOD guidance for important considerations when securing a personal device for work purposes.
Windows Education and student access
Both employees and students qualify for Windows 11 Education. Students using this route must sign up for an Azure Student subscription before accessing the Education license options. Review the UBC Azure Dev Tools information and the student Azure instructions KB article.
How to encrypt your device
If you are using a UBC-owned device, encryption is provided for UBC faculty and staff at no cost. You can request encryption assistance by contacting MBIM IT. For self-service on personally owned devices, follow the Privacy Matters online tutorials and review the BYOD guidance.
Before starting, make sure you have an adequate backup in place. See Backup and File Services for supported options. Encryption always carries some risk during deployment, so complete your backup before visiting MBIM IT or starting the tutorials yourself. The Privacy Matters FAQ covers the main reasons encryption is required and common questions about risk.