kennysarmy Posted December 5, 2017 Posted December 5, 2017 Bitlocker question: If I've already created my image to pull down to some test PC's using MDT is it possible to "alter" it so I can incorporate Bitlocker?
Michael Posted December 5, 2017 Posted December 5, 2017 Bitlocker is included - do you mean encrypting the system volume? There are numerous Bitlocker controls via GPO.
sted Posted December 5, 2017 Posted December 5, 2017 you cant enctypt the image what you do is as above set up some gpos on how you want bitlocker to work (ALWAYS ALWAYS force it to store the recovery key in active directory imo) then just turn it on on the pc (if you have tpms you can do it as part of the mdrt/sccm deploy sequence i dont think that works if you dont have tpm chips in the pcs
Koldov Posted December 5, 2017 Posted December 5, 2017 Just looking into this myself.... ALWAYS force it to store the recovery key in active directory If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)? I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords.
DJ-1701 Posted December 5, 2017 Posted December 5, 2017 Just looking into this myself.... If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)? I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords. The item you are entering into AD is the recovery code, not the password. The laptop can be unlocked with your password as long as there isn't some weird and wonderful problem. That is what the recovery code is for. 1
Koldov Posted December 5, 2017 Posted December 5, 2017 ALWAYS force it to store the recovery key in active directory imo The item you are entering into AD is the recovery code, not the password. Doh! That will teach me not to skim read a post whilst doing 4 other things... Senior moment! Carry on, nothing to see here....
sted Posted December 5, 2017 Posted December 5, 2017 Just looking into this myself.... If the passwords are stored in AD, does this cache in some way for logins outside of the AD environment (say, at home)? I'm thinking of using a password rather than TPM as a few of the laptops we have don't have a TPM chip, so rather than setting half to use TPM and half to use a password, I thought I'd go with ALL passwords. no you just get the 40ish digit recovery key stored in ad on that computers account (obviously details redacted) 1
kennysarmy Posted December 5, 2017 Author Posted December 5, 2017 To people create Data Recovery Agents?
Koldov Posted December 5, 2017 Posted December 5, 2017 My word.... Just looked at all the GPOs... That's gonna take some serious reading up on!
kennysarmy Posted December 5, 2017 Author Posted December 5, 2017 My word.... Just looked at all the GPOs... That's gonna take some serious reading up on! Think I need get my head around Legacy v UEFI boot methods too as we've kept with legacy for now...but I presume I need to look at UEFI to make the best of security settings.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now