Jump to content

Recommended Posts

Posted

I'm looking to set up BitLocker and link it to AD but I've found several documents online all stating different things. I was hoping somewhere could bring to light some key facts.

 

First of all can you remove the fact the user has to enter a password to get into their laptop?

Second: If BitLocker links to AD does the password key link to the laptop and desktop name? Because I am in an enviroment where hard drives and SSD's are swapped in and out, I'm trying to figure how AD would link the key to the machine?

Posted
I'm looking to set up BitLocker and link it to AD but I've found several documents online all stating different things. I was hoping somewhere could bring to light some key facts.

 

First of all can you remove the fact the user has to enter a password to get into their laptop?

 

Under the condition that you have a Trusted Platform Module (TPM) on the machine, yes.

I believe you can also do this if you have a USB stick, but said USB stick must be connected to the device on bootup.

Second: If BitLocker links to AD does the password key link to the laptop and desktop name? Because I am in an enviroment where hard drives and SSD's are swapped in and out, I'm trying to figure how AD would link the key to the machine?

 

The password key will refer to the HDD in the laptop you encrypt, so if you take it out of one machine and put it in another to read, you will need that key.

The key should last for that device until you wipe the drive and re-encrypt it, in which case a new one should be generated.

Posted
the key is linked to the computer name in ad. if you swap the drive from machine to machine you'll need to enter the recovery key which is quite long.
Posted
in ad the recovery key is stored in active directory on the pcs account (you have to enable the add on to view it) and it will show multiple if that pc has been encrypted (so say hdd changed etc) and a date but beyond it showing a date thats about all the info you get as to what it applies to.
Posted

The issue I have with that is I work in a school. Teachers are notorious for losing USB sticks. It's their thing lol. Having a small pen drive sticking out the laptop puts BitLocker out there as pointless.

 

We have over 2000 machines on the site and hard drives are refreshed or swapped out all the time. I'm wondering if linking it to AD would make everything messy and hard to keep track of.

Posted
The issue I have with that is I work in a school. Teachers are notorious for losing USB sticks. It's their thing lol. Having a small pen drive sticking out the laptop puts BitLocker out there as pointless.

 

We have over 2000 machines on the site and hard drives are refreshed or swapped out all the time. I'm wondering if linking it to AD would make everything messy and hard to keep track of.

if your swapping bitlockered drives out whatever you do is going to be messy. You can if the laptop dosent have a tpm use usb or if the laptop has one an sd card to hold the certificate and in theory pair the drive and sd card but swapping encrypted drives around is going to be a pain (unless its literally replacing and the drive will never go back in that pc in which case the correct recovery key will always be the newest dated one and just nuke the drive before you put it in another pc so it gets a new key)

Posted
The issue I have with that is I work in a school. Teachers are notorious for losing USB sticks. It's their thing lol. Having a small pen drive sticking out the laptop puts BitLocker out there as pointless.

 

We have over 2000 machines on the site and hard drives are refreshed or swapped out all the time. I'm wondering if linking it to AD would make everything messy and hard to keep track of.

 

But if you swap a hard drive wouldn't you then reimage the machine?

 

If so the new key would get written to AD anyway.

 

I think you may be over thinking this a little

Posted
The issue I have with that is I work in a school. Teachers are notorious for losing USB sticks. It's their thing lol. Having a small pen drive sticking out the laptop puts BitLocker out there as pointless.

 

We have over 2000 machines on the site and hard drives are refreshed or swapped out all the time. I'm wondering if linking it to AD would make everything messy and hard to keep track of.

 

But if you swap a hard drive wouldn't you then reimage the machine?

 

If so the new key would get written to AD anyway.

 

I think you may be over thinking this a little

 

I assume @Katalyst would be imaging the machines from HDD to SSD. In which case it may be worth suspending bitlocker while cloning and enabling it when replaced. It should still have the same key if a drive is cloned.

Posted

I probably am over thinking this. Some of our old PC images are on Fog and the newer are on WDS. Each time we swap a hard drive out we will reimage the machine and add it to AD. The difficulty comes from when you swap a teacher laptop out for a newer model. We tend to keep their old hard drive aside for three months just in case they are missing a file.

 

It's just getting feelers out there really for how I would do it. Swapping hard drives in such a large computer based area is going to get messy but if AD could locate a hard drive by it's SN or MAC then I could never worry about losing a key as I could just reset it in AD.

Posted
I probably am over thinking this. Some of our old PC images are on Fog and the newer are on WDS. Each time we swap a hard drive out we will reimage the machine and add it to AD. The difficulty comes from when you swap a teacher laptop out for a newer model. We tend to keep their old hard drive aside for three months just in case they are missing a file.

 

It's just getting feelers out there really for how I would do it. Swapping hard drives in such a large computer based area is going to get messy but if AD could locate a hard drive by it's SN or MAC then I could never worry about losing a key as I could just reset it in AD.

 

Well, if you are replacing a drive, couldn't you just print out or save a copy of the Bitlocker data from AD before you place the new drive in and re-image it? :)

Posted
if you are decommissioning the old laptops and removing the hdds from them presumably you are keeping them in a safe location? If so just unencrypt them as part of your decommission process if they never leave the premises and are in a secure location do they still need to be encrypted?
Posted
The difficulty comes from when you swap a teacher laptop out for a newer model. We tend to keep their old hard drive aside for three months just in case they are missing a file.

 

 

I see the problem here. You are too nice 😀

Posted
Just take it out and leave it encrypted. If you ever want to put their old HDD into your PC or a dock to retrieve files you can always simply enter the usb key (we have a master USB key for all laptops) or enter the recovery key from AD if you need access.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...