Jump to content

Recommended Posts

Posted

We are looking at encrypting our staff laptops.

 

Installed W7 Enterprise thinking to use bitlocker... Need TPM :( these laptops do not have TPM.

 

Looking for some free encryption software, easy for staff to use, and will encrypt the whole hard drive.

Posted

We use TrueCrypt if we can't use BitLocker, though it involves an additional password page which the staff don't like.

 

Easy to use, though - the staff just input a password at boot, then everything is as normal.

Posted (edited)
Also on Truecrypt. Any laptops that leave the site have a password on boot, very simple. Their external HDDs are also encrypted. We went with it for the same reason - no TPMs (Lenovo X130e). Edited by 3s-gtech
Posted
you dont NEED a tpm for bitlocker it makes things easier but im sure it can be used with a flashdrive and pin if you dont have a tpm
Posted

You can still use bitlocker without tpm - use a flash drive as a key. Only problem is if staff lose/forget them then you have use recovery password to start the laptop.

Advantage of bitlocker is that recovery keys are saved in active directory.

Posted
And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost.
Posted
And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost.

 

and if you have a tpm you can be a real swine and require usb/pin/tpm to get in

Posted
What happens if the laptop breaks? and the motherboard is replaced?

 

with bitlocker you look up the recovery key in active directory shove the drive in another win7 pc (as either boot or extra drive) and type in the 40 digit code when it asks for it

Posted
You can still use bitlocker without tpm - use a flash drive as a key. Only problem is if staff lose/forget them then you have use recovery password to start the laptop.

Advantage of bitlocker is that recovery keys are saved in active directory.

 

Shouldn't that be when they lose them?

 

What happens if the laptop breaks? and the motherboard is replaced?

 

We have offline files set up, and all staff are briefed that anything not stored in the "documents" part of "My Documents" is not synced (that includes the rubbish they coat their desktops with as well as their dubiously obtained media) and that if the drive/laptop fails then such files will almost certainly be lost - so they should make their own backups. (I'm betting they don't, but that's not my problem and I will have no sympathy when the inevitable happens).

Posted
One other option is to use usb startup keys with the laptops without TPM or use Windows 8 which allows you to use password on startup as well as the usb startup option in Windows 7 for laptops without TPM.
Posted

for bitlocker if you have server 2008r2 (and i assume 2012 is the same or near enough) go to server manager, add features, remote server admin tools, feature administration tools, and tick the bitlocker drive encryption admin utils (for windows 7 install rsat tools then do the same as above). then in active directory users and computers you get an extra tab on computer accounts

 

bitlocker.jpg

Posted
And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost.

 

possibly might keep them on heavy key rings and damage the usb socket from the weight

Posted
Anyway of scripting the truecrypt install and encryption? Thats its downside. Bitlocker is better but not really secure as staff will leave the usb stick in the laptop making it pointless. You really should be using truecrypt even if you have to install it manually The ico can fine if sensative data is lost.
Posted
It has a command-line version that accepts all necessary parameters. I've posted in detail about the scripting we use here to automate the entire re-imaging process here.
Posted
Anyway of scripting the truecrypt install and encryption? Thats its downside. Bitlocker is better but not really secure as staff will leave the usb stick in the laptop making it pointless. You really should be using truecrypt even if you have to install it manually The ico can fine if sensative data is lost.

 

even with the pendrive in they still require a pin code or ot wont boot with bitlocker

Posted
even with the pendrive in they still require a pin code or ot wont boot with bitlocker
That's not true. No TPM, no pin option with Bitlocker. If you're thinking of deploying Windows 8, the password option is well worth a look for devices without TPM. I believe it allows standard users to change the Bitlocker boot password with the key benefit of the encryption keys being stored in AD in case you need to preform any recovery etc.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...