X-13 Posted November 24, 2014 Posted November 24, 2014 Ok... I think I have the GPOs set properly, and encryption is part of the MDT sequence, but it's not doing anything. This computer is acting like the GPO isn't set and it doesn't have access to bitlocker. I've kicked off bitlocker manually, and backed up the keys to where it was set in Group Policy [a network share on the server] but I need this to be automated... Any suggestions?
sted Posted November 24, 2014 Posted November 24, 2014 i dont think it will turn on bitlocker via gpo you can fire all the settings out but i think encryption still has to be started manually (or via a scripy/scheduled task) i thik this is by design so you cant acidently encrypt a pc and lose the keys
X-13 Posted November 24, 2014 Author Posted November 24, 2014 It won't turn on by GPO, but the MDT task sequence should encrypt the OS drive.
sted Posted November 24, 2014 Posted November 24, 2014 It won't turn on by GPO, but the MDT task sequence should encrypt the OS drive. dosent that only apply to win 8.1?
mac_shinobi Posted November 24, 2014 Posted November 24, 2014 dosent that only apply to win 8.1? You mean eDrive which requires an SSD or hard drive that supports eDrive ?
X-13 Posted November 24, 2014 Author Posted November 24, 2014 dosent that only apply to win 8.1? I can't see why it would... Bitlocker is built into Win 7 Enterprise. 1
DBi Posted November 25, 2014 Posted November 25, 2014 have you got the TPM modules turned on in the BIOS before you run the task sequence? in our deployment we have it set to go straight to AD to store the keys, the only issues I had before I got it working was turning on the TPM and there was also a driver that was corrupting TPM module
X-13 Posted November 25, 2014 Author Posted November 25, 2014 have you got the TPM modules turned on in the BIOS before you run the task sequence? in our deployment we have it set to go straight to AD to store the keys, the only issues I had before I got it working was turning on the TPM and there was also a driver that was corrupting TPM module Interesting... I have them on and ownership has been taken [allegedly].
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now