Jump to content

Recommended Posts

Posted

Found the first flaw in asking for all usb devices to be encrpted or readonly - BBC Microbits.

 

A member of staff is trying to save to the microbit however with it not having bitlocker on it they can't save to it.

 

Anyone got any bright ideas to get round this?

Posted
The impero way wont work for us as we push out the bitlocker way via regedit - though i may have to re-think the way we do things here. If Impero allowed non-encrypted USB drives to be read rather than block i would use it but i think it's either On or Off in Impero - there's no middle ground.
Posted

We came across this when we enforced bitlocker last year. We had to change our setup slightly so that only devices on the allowed list (GPO) are allowed to be installed. The issue we're now finding is "devices" refers to all devices and not just USB sticks so our allowed list just keeps growing to include keyboards, mice etc.

 

Hoping someone has a simpler way of doing this.

Posted (edited)
We had a similar issue when we made USBs read-only using Bitlocker. Our inelegant workaround was to move our IT rooms into a separate OU without the Bitlocker read-only restriction, and instead block all USB storage devices in those rooms using a Sophos policy. When the teachers want to use Microbits (they're only really used in an after school club here now), we pull that IT room from the Sophos policy, which removes the restrictions for all USB storage devices. It's not ideal, but it works for us. Edited by DeGrimmy
Posted

I think i've just got my head around it.

 

At the moment we are applying USB BitLocker encryption to members of staff only so if they were to use a computer be it staff or student machine, the reg hack in the group policy would apply to staff users. Students on the other hand, they can access unencrypted USB drives.

 

Now, my thought is this... Apply the reg hack across ALL machines as standard. When a student logs in, group policy updates the reg keys and sets the computer to be able to use unencrypted USB sticks. Staff wouldn't have any encryption policies as the computers by default have bitlocker required as standard.

 

As this is one teacher we are talking about who uses MicroBits, they would have to tell us when they are using them. The group policy to only allow encrypted USBs on this machine wouldn't be set but Sophos or Impero would be controlling this so if said teacher wants to use the microbits, they would have to let us know so we can assign that specific computer the appropriate configured via Impero or Sophos.

Posted
The impero way wont work for us as we push out the bitlocker way via regedit - though i may have to re-think the way we do things here. If Impero allowed non-encrypted USB drives to be read rather than block i would use it but i think it's either On or Off in Impero - there's no middle ground.

 

I've put a feature request in to Impero support to allow unencrypted USB drives to be read-only, but I'm not sure how high that is on their list of priorities.

Posted

I've had to slightly change the way we were allowing access to the Microbits. I forgot that a machine policy will override a user policy if the user has been logged on to the machine during the GPO computer sync time.

 

So now, all machines are defaulted back to not requiring encryption so now staff are forced to have USB drives encrypted or they are read only apart from one machine which is controlled via Sophos Removable device policy. To get round this, this is done via a Item-Level Targetting rule based on the user(s) being part of a security group AND the NetBIOS name of the computer not equal to the one that is controlled via Sophos.

Posted
While I haven't looked at the specific issue, in the past USBDLM has been fantastic for me when it comes to handling different USB devices in different way. You might be able to work something with it. For example, if recognised as microbit, mount to M:, if recognised as anything else mount to [your standard external storage letters]: and call a script to handle checking for bitlocker. It is also able to mount devices as read only (something we did to allow staff to transition away from USB storage, while not preventing accessing existing material).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...