kennysarmy Posted January 10, 2018 Posted January 10, 2018 Yesterday I looked at bitlocker on our Windows 10 laptops. Seemed pretty easy enough to setup the bits on the Server so the Recovery Keys are stored in AD. I then created a GPO for my settings and encrypted the OS drive and the data partition on a test laptop. However, on logging on to the laptop as a test teacher offline account I was able to decrypt the hard drive - is there anyway to remove this functionality from teachers or disallow decryption?
jmak Posted January 10, 2018 Posted January 10, 2018 It's another GPO under: Computer Configurations>Policies>Windows Settings>Administrative Settings>Windows Components>MDOP MBAM (Bitlocker Management)>Encryption Policy Enforcement Settings This setting allows you to configure the number of days that fixed drives can remain noncomplaint until they are forced to comply with MBAM policies. Users will not be able to postpone the required action or to request an exemption from it after the grace period. The grace period starts when the fixed data drive is determined to be noncompliant. However, the fixed data drive policy will not be enforced until the operating system drive is compliant.[/Quote]
DJ-1701 Posted January 10, 2018 Posted January 10, 2018 Yesterday I looked at bitlocker on our Windows 10 laptops. Seemed pretty easy enough to setup the bits on the Server so the Recovery Keys are stored in AD. I then created a GPO for my settings and encrypted the OS drive and the data partition on a test laptop. However, on logging on to the laptop as a test teacher offline account I was able to decrypt the hard drive - is there anyway to remove this functionality from teachers or disallow decryption? Out of interest, what level of access do your teachers have on their laptops, are they administrators? If not, it might be something for everyone to ensure they look at.
kennysarmy Posted January 10, 2018 Author Posted January 10, 2018 It's another GPO under: Computer Configurations>Policies>Windows Settings>Administrative Settings>Windows Components>MDOP MBAM (Bitlocker Management)>Encryption Policy Enforcement Settings I don't seem to have such a key....MDOP MBAM
jmak Posted January 10, 2018 Posted January 10, 2018 I don't seem to have such a key....MDOP MBAM Now that I think about it, I seem to recall I had to download an ADMX to add it: https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/solutions/how-to-download-and-deploy-mdop-group-policy--admx--templates MDOP is part of Software Assurance which is included with your EES/OVS agreement it you have it (it used to be an extra)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now