What if you put your notebook file on a Bitlocker'd drive?
And then EFS on top of that, and each VM has its own encryption as well. So even a full compromise won't hurt the VMs I'm not using at the time.
But it doesn't help since OneNote's online slick-access-from-anywhere, doesn't do crypto AFAIK. So all my transparent crypto protect my local device, but OneLook uploads the notebooks unencrypted to SkyDrive.
The biggest win, I think is the internal "e drive" encryption, so that a RAM dump doesn't spill keys. That even somewhat mitigates Lightning DMA attacks. (Although the attacker could just hijack the OS at that point.)