Jump to content

Recommended Posts

Posted

Ok... I think I have the GPOs set properly, and encryption is part of the MDT sequence, but it's not doing anything.

 

This computer is acting like the GPO isn't set and it doesn't have access to bitlocker.

 

I've kicked off bitlocker manually, and backed up the keys to where it was set in Group Policy [a network share on the server] but I need this to be automated...

 

 

Any suggestions?

Posted
i dont think it will turn on bitlocker via gpo you can fire all the settings out but i think encryption still has to be started manually (or via a scripy/scheduled task) i thik this is by design so you cant acidently encrypt a pc and lose the keys
Posted

have you got the TPM modules turned on in the BIOS before you run the task sequence?

 

in our deployment we have it set to go straight to AD to store the keys, the only issues I had before I got it working was turning on the TPM and there was also a driver that was corrupting TPM module

Posted
have you got the TPM modules turned on in the BIOS before you run the task sequence?

 

in our deployment we have it set to go straight to AD to store the keys, the only issues I had before I got it working was turning on the TPM and there was also a driver that was corrupting TPM module

 

Interesting...

 

I have them on and ownership has been taken [allegedly].

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...