Jump to content

Recommended Posts

Posted
you cant enctypt the image what you do is as above set up some gpos on how you want bitlocker to work (ALWAYS ALWAYS force it to store the recovery key in active directory imo) then just turn it on on the pc (if you have tpms you can do it as part of the mdrt/sccm deploy sequence i dont think that works if you dont have tpm chips in the pcs
Posted

Just looking into this myself....

 

ALWAYS force it to store the recovery key in active directory

 

If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)?

 

I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords.

Posted
Just looking into this myself....

 

 

 

If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)?

 

I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords.

 

The item you are entering into AD is the recovery code, not the password. The laptop can be unlocked with your password as long as there isn't some weird and wonderful problem. That is what the recovery code is for.

  • Thanks 1
Posted
ALWAYS force it to store the recovery key in active directory imo

 

The item you are entering into AD is the recovery code, not the password.

 

Doh!

 

That will teach me not to skim read a post whilst doing 4 other things...

 

Senior moment!

 

Carry on, nothing to see here....

Posted
Just looking into this myself....

 

 

 

If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)?

 

I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords.

 

no you just get the 40ish digit recovery key stored in ad on that computers account (obviously details redacted)

blredacted.png

  • Thanks 1
Posted
My word....

 

Just looked at all the GPOs...

 

That's gonna take some serious reading up on!

 

:confused:

 

 

Think I need get my head around Legacy v UEFI boot methods too as we've kept with legacy for now...but I presume I need to look at UEFI to make the best of security settings.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...