Not every machine is a guaranteed boot. It depends on MBR/GPT etc and whether UEFI is disabled in the BIOS and other configurations. However generally yes, they will. I've even have setups where the SSD would would have macOS/Windows/Linux. Much older motherboard pre-2012 generally don't like this setup and it can be v.slow.
For example, with bitlocker, won’t you need to enter the recovery key when trying to boot from a new machine? And have to sign out and back in to all relevant OS level accounts? Even then I face authentication issues at times
I really would like this to work seamlessly because moving my internal SSD work disk to an external one would be far safer than lugging it around inside my personal laptop all the time. But the work disk has to be encrypted...
Also, for hardware compatibility’s sake, I’d think Linux would be a far superior daily driver OS to ‘multi-hardware boot’, considering relevant drivers are loaded from kernel on boot rather than selectively pre-installed at OS creation time for that one device, increasing plug and play compatibility
But try move a bootable bitlocker encrypted disk to new hardware and you’ll have to enter the recovery key
I would really like to be wrong about this since it would make my life much easier, but this understanding is based on experience using multiple work machines with encrypted boot drives every day :(
this is not true. you can configure bitlocker with or without TPMs.
just google it. also the doc for the powershell command talks about it in the establishing a key protector section
https://docs.microsoft.com/en-us/powershell/module/bitlocker...
I used the `manage-bde` command rather than powershell:
https://docs.microsoft.com/en-us/windows/security/informatio...
The GUI for bitlocker doesn't provide access to all the functionality that manage-bde provides (iirc: if a TPM is present, the passphrase options aren't presented in the GUI. And it used to talk about a "PIN" instead of a passphrase/password, but the "PIN" can (with some gpo tweaking) contain letters/space/punct as well as numbers.
At work due to remote work I cannot have fully encrypted disc with Windows as I have to reboot remotely. So I left a small enough partition for Windows, then created another partition for my data that I encrypted with strong password in Bitlocker. Then I symlinked my user directory from C:\Users\UserName to a directory on D: and created an extra account that I use after reboot to unlock the encrypted disc with my data.
This is not ideal, as Windows still may store my data on C:\, but if one disables virtual memory, it is a reasonably secure setup.