AngryITGuy Posted September 20, 2017 Posted September 20, 2017 We are looking to enforce USB device encryption across the site and have been testing a couple of different solutions. I've tested the GPOs to lock down USB device installation to a specific brand which means staff can only use the Crypto Dual Encrypted Pens we supply them and this has worked well in testing. We've had requests from staff to be able to encrypt their own drives and again I've had success in testing the deny write access to removable drives not protected by BitLocker GPO. However looking online for assistance it looks like i can only have one of the above solutions implemented and I would prefer to have both. Is this possible? And how are others managing USB encryption?
enjay Posted September 21, 2017 Posted September 21, 2017 We bought a load of https://istorage-uk.com/product/datashur/ for staff (they're the only option we could find which supports non-Windows devices), and issued policy saying to use those or password protect sensitive documents.
Aldmi Posted September 26, 2017 Posted September 26, 2017 We started this in September and using Bit Locker
3s-gtech Posted September 26, 2017 Posted September 26, 2017 We are looking to enforce USB device encryption across the site and have been testing a couple of different solutions. I've tested the GPOs to lock down USB device installation to a specific brand which means staff can only use the Crypto Dual Encrypted Pens we supply them and this has worked well I'd be really interested in how you did this - I have enforced encrypted USB sticks by policy by that can easily be ignored. I'd like to actually restrict the use of others physically. I can't help with your issue sorry - those sort of conflicts often take some logical steps to overcome but I can't think how. Perhaps WMI or OU management of those users who wish to use their own?
MatZeRO Posted September 26, 2017 Posted September 26, 2017 We do this using Bitlocker and store recovery keys in AD in case they forget the password. We enforce this for any storage device staff use. They provide their own devices.
FN-GM Posted September 26, 2017 Posted September 26, 2017 Has anyone banned sticks outright? They are to be made read only here. 1
AngryITGuy Posted September 26, 2017 Author Posted September 26, 2017 I'd be really interested in how you did this - I have enforced encrypted USB sticks by policy by that can easily be ignored. I'd like to actually restrict the use of others physically. I can't help with your issue sorry - those sort of conflicts often take some logical steps to overcome but I can't think how. Perhaps WMI or OU management of those users who wish to use their own? We’ve decided to ban the use of all USB devices unless they are the encrypted devices provided by school. We couldn’t enforce Bitlocker as we only have Windows Professional and denying write access to USB drives not encrypted with BitLocker sounded good but in reality it wasn’t ideal as non encrypted devices could still be read. So we have now whitelisted the school supplied encrypted USB devices and things like school digital cameras by device ID in group policy and whitelisted devices classes such as keyboards, mice, printers allowing the end user to install such things. Testing this allows most USB devices or peripherals to be installed by the end user and only allow the use of the school supplied usb pens and nothing else will work. 1
neonetman Posted September 27, 2017 Posted September 27, 2017 We have banned sticks outright for both staff and students. USers ave Gsuite accounts to transfer documents, or can staff can sign in using a VPN connection. The only exception to this is the sticks used for transferring data to our laser cutter
mavhc Posted September 27, 2017 Posted September 27, 2017 We’ve decided to ban the use of all USB devices unless they are the encrypted devices provided by school. We couldn’t enforce Bitlocker as we only have Windows Professional and denying write access to USB drives not encrypted with BitLocker sounded good but in reality it wasn’t ideal as non encrypted devices could still be read. Windows 10 pro allows bitlocker
enjay Posted September 27, 2017 Posted September 27, 2017 We have banned sticks outright for both staff and students. USers ave Gsuite accounts to transfer documents, or can staff can sign in using a VPN connection. The only exception to this is the sticks used for transferring data to our laser cutter Is that a technical ban or a policy saying "don't do it"?
neonetman Posted September 28, 2017 Posted September 28, 2017 Is that a technical ban or a policy saying "don't do it"? It's a technical ban - we use Sophos Endpoint Protection and then apply a device control policy.
mavhc Posted March 9, 2018 Posted March 9, 2018 Just noticed a new problem with bitlocker, micro:bits, not sure I can whitelist the micro:bit VIDs with bitlocker gpos
djrscally Posted March 9, 2018 Posted March 9, 2018 Just noticed a new problem with bitlocker, micro:bits, not sure I can whitelist the micro:bit VIDs with bitlocker gpos Hmm yeah; https://support.microbit.org/support/solutions/articles/19000013695-how-do-i-use-micro-bit-with-bitlocker- That's annoying. I wonder if the other micro boards have the same problem. I'm pretty sure you can flash arduinos or the cheaper clones using GPIO but that'd be super irritating.
mavhc Posted March 9, 2018 Posted March 9, 2018 If they appear as usb mass storage they will. If serial port or similar, they should be fine. You can probably use the mu editor to talk to it via serial.
fiza Posted March 9, 2018 Posted March 9, 2018 We exclude the rooms where microbits are used from bitlocker enforcement but then use Sophos to block all usbs in those machines until the microbits are used then disable the policy. Re-enable the policy after. This is the only way we have found where we can use microbits.
enjay Posted March 12, 2018 Posted March 12, 2018 We exclude the rooms where microbits are used from bitlocker enforcement but then use Sophos to block all usbs in those machines until the microbits are used then disable the policy. Re-enable the policy after. This is the only way we have found where we can use microbits. Hang on - are you forcing encrypted USB for students too? That seems like overkill...
fiza Posted March 12, 2018 Posted March 12, 2018 Hang on - are you forcing encrypted USB for students too? That seems like overkill... Students don't need to use USBs. Students use G Suite so all work is available online anywhere . Also I thought Bitlocker was a machine policy not a user policy.
mavhc Posted March 12, 2018 Posted March 12, 2018 Hang on - are you forcing encrypted USB for students too? That seems like overkill... As standard bitlocker settings are per machine, and staff can use any machine. Plus might as well teach everyone about good security
gshaw Posted March 12, 2018 Posted March 12, 2018 Students don't need to use USBs. Students use G Suite so all work is available online anywhere . Also I thought Bitlocker was a machine policy not a user policy. @fiza @mavhc the BitLocker GPO is but you can hack around it using GPP under User Configuration to switch the registry key flags around to enable it per-user
enjay Posted March 12, 2018 Posted March 12, 2018 @fiza @mavhc the BitLocker GPO is but you can hack around it using GPP under User Configuration to switch the registry key flags around to enable it per-user Can you expand upon that a bit please? I would like to enable Bitlocker but don't want to block students from using USBs (would need to rethink exam practices if we did). Did you just put the Computer Config options in a GPO which is only applied at a user level for staff, or was it more complex than that?
gshaw Posted March 12, 2018 Posted March 12, 2018 @enjay follow the guide here... https://blogs.technet.microsoft.com/askpfeplat/2013/06/09/how-to-enable-user-based-controlenforcement-of-bitlocker-on-removable-data-drives/ However the page isn't very clear and doesn't make the key point that one of the values is set in a different location to the others so check out my GPP dump here http://www.edugeek.net/forums/windows-10/179827-per-user-bitlocker-usb-encryption-2.html to make sure you've got everything in the right place 3
mavhc Posted March 12, 2018 Posted March 12, 2018 My problem is more if I enabled the bitlocker gpo than my dell vostro machines go crazy, intel me, wifi and touchpad devices don't work.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now