Jump to content

Recommended Posts

Posted

We are looking to enforce USB device encryption across the site and have been testing a couple of different solutions.

 

I've tested the GPOs to lock down USB device installation to a specific brand which means staff can only use the Crypto Dual Encrypted Pens we supply them and this has worked well in testing.

 

We've had requests from staff to be able to encrypt their own drives and again I've had success in testing the deny write access to removable drives not protected by BitLocker GPO.

 

However looking online for assistance it looks like i can only have one of the above solutions implemented and I would prefer to have both. Is this possible?

 

And how are others managing USB encryption?

Posted
We are looking to enforce USB device encryption across the site and have been testing a couple of different solutions.

 

I've tested the GPOs to lock down USB device installation to a specific brand which means staff can only use the Crypto Dual Encrypted Pens we supply them and this has worked well

 

I'd be really interested in how you did this - I have enforced encrypted USB sticks by policy by that can easily be ignored. I'd like to actually restrict the use of others physically. I can't help with your issue sorry - those sort of conflicts often take some logical steps to overcome but I can't think how. Perhaps WMI or OU management of those users who wish to use their own?

Posted

We do this using Bitlocker and store recovery keys in AD in case they forget the password.

 

We enforce this for any storage device staff use. They provide their own devices.

Posted
I'd be really interested in how you did this - I have enforced encrypted USB sticks by policy by that can easily be ignored. I'd like to actually restrict the use of others physically. I can't help with your issue sorry - those sort of conflicts often take some logical steps to overcome but I can't think how. Perhaps WMI or OU management of those users who wish to use their own?

 

We’ve decided to ban the use of all USB devices unless they are the encrypted devices provided by school.

 

We couldn’t enforce Bitlocker as we only have Windows Professional and denying write access to USB drives not encrypted with BitLocker sounded good but in reality it wasn’t ideal as non encrypted devices could still be read.

 

So we have now whitelisted the school supplied encrypted USB devices and things like school digital cameras by device ID in group policy and whitelisted devices classes such as keyboards, mice, printers allowing the end user to install such things.

 

Testing this allows most USB devices or peripherals to be installed by the end user and only allow the use of the school supplied usb pens and nothing else will work.

  • Thanks 1
Posted

We have banned sticks outright for both staff and students. USers ave Gsuite accounts to transfer documents, or can staff can sign in using a VPN connection.

 

The only exception to this is the sticks used for transferring data to our laser cutter

Posted
We’ve decided to ban the use of all USB devices unless they are the encrypted devices provided by school.

 

We couldn’t enforce Bitlocker as we only have Windows Professional and denying write access to USB drives not encrypted with BitLocker sounded good but in reality it wasn’t ideal as non encrypted devices could still be read.

 

Windows 10 pro allows bitlocker

Posted
We have banned sticks outright for both staff and students. USers ave Gsuite accounts to transfer documents, or can staff can sign in using a VPN connection.

 

The only exception to this is the sticks used for transferring data to our laser cutter

 

Is that a technical ban or a policy saying "don't do it"?

  • 5 months later...
Posted
If they appear as usb mass storage they will. If serial port or similar, they should be fine. You can probably use the mu editor to talk to it via serial.
Posted
We exclude the rooms where microbits are used from bitlocker enforcement but then use Sophos to block all usbs in those machines until the microbits are used then disable the policy. Re-enable the policy after. This is the only way we have found where we can use microbits.
Posted
We exclude the rooms where microbits are used from bitlocker enforcement but then use Sophos to block all usbs in those machines until the microbits are used then disable the policy. Re-enable the policy after. This is the only way we have found where we can use microbits.

 

Hang on - are you forcing encrypted USB for students too? That seems like overkill...

Posted
Hang on - are you forcing encrypted USB for students too? That seems like overkill...

Students don't need to use USBs. Students use G Suite so all work is available online anywhere . Also I thought Bitlocker was a machine policy not a user policy.

Posted
Hang on - are you forcing encrypted USB for students too? That seems like overkill...

 

As standard bitlocker settings are per machine, and staff can use any machine. Plus might as well teach everyone about good security

Posted
Students don't need to use USBs. Students use G Suite so all work is available online anywhere . Also I thought Bitlocker was a machine policy not a user policy.

 

@fiza @mavhc the BitLocker GPO is but you can hack around it using GPP under User Configuration to switch the registry key flags around to enable it per-user ;)

Posted
@fiza @mavhc the BitLocker GPO is but you can hack around it using GPP under User Configuration to switch the registry key flags around to enable it per-user ;)

 

Can you expand upon that a bit please? I would like to enable Bitlocker but don't want to block students from using USBs (would need to rethink exam practices if we did). Did you just put the Computer Config options in a GPO which is only applied at a user level for staff, or was it more complex than that?

Posted

@enjay follow the guide here...

 

https://blogs.technet.microsoft.com/askpfeplat/2013/06/09/how-to-enable-user-based-controlenforcement-of-bitlocker-on-removable-data-drives/

 

However the page isn't very clear and doesn't make the key point that one of the values is set in a different location to the others so check out my GPP dump here

 

http://www.edugeek.net/forums/windows-10/179827-per-user-bitlocker-usb-encryption-2.html

 

to make sure you've got everything in the right place

  • Thanks 3
Posted
My problem is more if I enabled the bitlocker gpo than my dell vostro machines go crazy, intel me, wifi and touchpad devices don't work.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...