CHiLL Posted March 13, 2018 Posted March 13, 2018 (edited) In light of GDPR, we have started looking at BitLocker for our devices that are taken off-site and doing some testing to see how it works. So far I've done the following configuration on our domain and prerequisites: GPO Created defining that all OS and fixed data drives are fully encrypted, and removable drives are used-space only encrypted. I've also specified to use AD DS backup for BitLocker, as well as defining the type of encryption to use, complexity, etc. Incorporated MBAM into SCCM Configured the OU to delegate control for the 'SELF' user (multiple sources recommended this) Added ACE for the TPM to AD DS (as recommended in a MS article) Devices imaged using SCCM have the following step in the TS during the 'Format Disk' stage section: 'Pre-provision BitLocker' and then followed later in the 'Post Install' section with 'Enable BitLocker' I have a test laptop in a test OU with the above GPO linked. When I insert a USB drive into the laptop, BitLocker automatically prompts to encrypt the drive and use it, or not encrypt it and only use it as read-only. This shows that the GPO is working. However, when I run the following command on the laptop to check BitLocker status: manage-bde -status c: It states: [OS Volume] Size: 464.80GB BitLocker Version: None Conversion Status: Fully Decrypted Percentage Encrypted: 0.0% Encryption Method: None Protection Status: Protection Off Lock Status: Unlocked Identification Field: None Key Protectors: None Found I don't understand why BitLocker Version is reporting 'None', yet BitLocker prompts when a USB drive is inserted. Also, I cannot start 'Manage BitLocker'. When I search the Start Menu for it, it shows in the results as a Control Panel item, but pressing it does nothing. I also cannot find it manually in Control Panel. Once I've sorted that out, how can I automatically start the encryption of the laptop? Rather than having to manually start it. Any ideas? Edited March 13, 2018 by CHiLL
sted Posted March 13, 2018 Posted March 13, 2018 have you actually encrypted the drive as gpo alone will just put settings there so you can you need to right click the drive and encrypt and follow any prompts for password etc. Its easy to create a gpo for bitlocker that dosent work as it has conflicting settings usually the require additional authentication at startup settings. if you set them wrong you are effectively asking it to do mutually exclusive things and when you try to encrypt the drive it will fail. as for encrypting as part of the imaging process id test the gpos before doing that as i did the above mistake and it took me ages to get the drive to encrypt as it wrote info to it that was wrong and i had to mess around with manage-bde powershell to remove encryption options that had failed. you also to deploy it as part of a task sequence (at least in mdt) need to have a tpm chip 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 have you actually encrypted the drive as gpo alone will just put settings there so you can you need to right click the drive and encrypt and follow any prompts for password etc. Its easy to create a gpo for bitlocker that dosent work as it has conflicting settings usually the require additional authentication at startup settings. if you set them wrong you are effectively asking it to do mutually exclusive things and when you try to encrypt the drive it will fail. as for encrypting as part of the imaging process id test the gpos before doing that as i did the above mistake and it took me ages to get the drive to encrypt as it wrote info to it that was wrong and i had to mess around with manage-bde powershell to remove encryption options that had failed. you also to deploy it as part of a task sequence (at least in mdt) need to have a tpm chip Cheers for the reply. I actually don't have an option to encrypt when I right click the drive, which doesn't bode well.
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 Is the TPM enabled in the BIOS? TPM is enabled and set to 'Clear TPM Owner' (This is a Toshiba Satellite Pro R50-B).
sted Posted March 13, 2018 Posted March 13, 2018 what about if you log in as local admin have you somehow removed the option with gpo? might be worth running rsop/rsop and seeing exactly what policies are applied to the machine maybe theres some other settings somewhere else 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 (edited) what about if you log in as local admin have you somehow removed the option with gpo? might be worth running rsop/rsop and seeing exactly what policies are applied to the machine maybe theres some other settings somewhere else The option is also missing for the local admin. I've done RSOP, but not sure what I'm looking for. The configured BitLocker policies are as follows: Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption Policy Setting Winning GPO Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) Enabled TESTING - C - BitLocker Select the encryption method for operating system drives: XTS-AES 256-bit Select the encryption method for fixed data drives: XTS-AES 256-bit Select the encryption method for removable data drives: XTS-AES 256-bit Policy Setting Winning GPO Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) Enabled TESTING - C - BitLocker Select the encryption method: AES 256-bit Policy Setting Winning GPO Disable new DMA devices when this computer is locked Enabled TESTING - C - BitLocker Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) Enabled TESTING - C - BitLocker Require BitLocker backup to AD DS Enabled If selected, cannot turn on BitLocker if backup fails (recommended default). If not selected, can turn on BitLocker even if backup fails. Backup is not automatically retried. Select BitLocker recovery information to store: Recovery passwords and key packages A recovery password is a 48-digit number that unlocks access to a BitLocker-protected drive. A key package contains a drive's BitLocker encryption key secured by one or more recovery passwords Key packages may help perform specialized recovery when the disk is damaged or corrupted. Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Fixed Data Drives Policy Setting Winning GPO Allow access to BitLocker-protected fixed data drives from earlier versions of Windows Enabled TESTING - C - BitLocker Do not install BitLocker To Go Reader on FAT formatted fixed drives Disabled Policy Setting Winning GPO Choose how BitLocker-protected fixed drives can be recovered Enabled TESTING - C - BitLocker Allow data recovery agent Enabled Configure user storage of BitLocker recovery information: Allow 48-digit recovery password Allow 256-bit recovery key Omit recovery options from the BitLocker setup wizard Disabled Save BitLocker recovery information to AD DS for fixed data drives Enabled Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives Enabled Policy Setting Winning GPO Configure use of hardware-based encryption for fixed data drives Enabled TESTING - C - BitLocker Use BitLocker software-based encryption when hardware encryption is not available Enabled Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 Policy Setting Winning GPO Configure use of passwords for fixed data drives Enabled TESTING - C - BitLocker Require password for fixed data drive Disabled Configure password complexity for fixed data drives: Require password complexity Minimum password length for fixed data drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Policy Setting Winning GPO Deny write access to fixed drives not protected by BitLocker Enabled TESTING - C - BitLocker Enforce drive encryption type on fixed data drives Enabled TESTING - C - BitLocker Select the encryption type: Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Operating System Drives Policy Setting Winning GPO Allow enhanced PINs for startup Enabled TESTING - C - BitLocker Configure minimum PIN length for startup Enabled TESTING - C - BitLocker Minimum characters: 8 Policy Setting Winning GPO Configure use of passwords for operating system drives Enabled TESTING - C - BitLocker Configure password complexity for operating system drives: Require password complexity Minimum password length for operating system drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Require ASCII-only passwords for removable OS drives Disabled Policy Setting Winning GPO Enforce drive encryption type on operating system drives Enabled TESTING - C - BitLocker Select the encryption type: Policy Setting Winning GPO Require additional authentication at startup Enabled TESTING - C - BitLocker Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive) Enabled Settings for computers with a TPM: Configure TPM startup: Allow TPM Configure TPM startup PIN: Require startup PIN with TPM Configure TPM startup key: Allow startup key with TPM Configure TPM startup key and PIN: Allow startup key and PIN with TPM Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Removable Data Drives Policy Setting Winning GPO Allow access to BitLocker-protected removable data drives from earlier versions of Windows Enabled TESTING - C - BitLocker Do not install BitLocker To Go Reader on FAT formatted removable drives Disabled Policy Setting Winning GPO Choose how BitLocker-protected removable drives can be recovered Enabled TESTING - C - BitLocker Allow data recovery agent Enabled Configure user storage of BitLocker recovery information: Allow 48-digit recovery password Allow 256-bit recovery key Omit recovery options from the BitLocker setup wizard Disabled Save BitLocker recovery information to AD DS for removable data drives Enabled Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages Do not enable BitLocker until recovery information is stored to AD DS for removable data drives Enabled Policy Setting Winning GPO Configure use of hardware-based encryption for removable data drives Enabled TESTING - C - BitLocker Use BitLocker software-based encryption when hardware encryption is not available Enabled Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 Policy Setting Winning GPO Configure use of passwords for removable data drives Enabled TESTING - C - BitLocker Require password for removable data drive Enabled Configure password complexity for removable data drives: Require password complexity Minimum password length for removable data drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Policy Setting Winning GPO Control use of BitLocker on removable drives Enabled TESTING - C - BitLocker Allow users to apply BitLocker protection on removable data drives Enabled Allow users to suspend and decrypt BitLocker protection on removable data drives Enabled Policy Setting Winning GPO Deny write access to removable drives not protected by BitLocker Enabled TESTING - C - BitLocker Do not allow write access to devices configured in another organization Disabled Policy Setting Winning GPO Enforce drive encryption type on removable data drives Enabled TESTING - C - BitLocker Select the encryption type: Used Space Only encryption What I've actually noticed in that is the 'Select the encryption type: ' field for both OS and fixed data drives appears blank in RSOP. Whereas the policy states that they should both be set to 'Full encryption'. I had done multiple gpupdate /force and reboots before gathering the RSOP data. Edited March 13, 2018 by CHiLL
sted Posted March 13, 2018 Posted March 13, 2018 i think id start a new ou and get a test machine and try settings a few at a time but Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive) Enabled Settings for computers with a TPM: Configure TPM startup: Allow TPM Configure TPM startup PIN: Require startup PIN with TPM Configure TPM startup key: Allow startup key with TPM Configure TPM startup key and PIN: Allow startup key and PIN with TPM theres your problem id bet you have Allow BitLocker without a compatible TPM ticked but Require startup PIN with TPM selected as well. those settings are odd if you want require a pin and tpm everything else has to be set to do not allow or even if the wizard shows it will bomb out saying basically you cant apply a contradictory policy as to why you cant see the bitlocker options i dont know i suspect control panel; access is restricted somewhere rather than bitlocker itself maybe you have a policy to only show specif control panel applets set 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 i think id start a new ou and get a test machine and try settings a few at a time but theres your problem id bet you have Allow BitLocker without a compatible TPM ticked but Require startup PIN with TPM selected as well. those settings are odd if you want require a pin and tpm everything else has to be set to do not allow or even if the wizard shows it will bomb out saying basically you cant apply a contradictory policy as to why you cant see the bitlocker options i dont know i suspect control panel; access is restricted somewhere rather than bitlocker itself maybe you have a policy to only show specif control panel applets set Hmm, OK. The idea was to allow BitLocker to encrypt devices without TPM chips or TPM chips lower than 1.2...but for devices with a TPM 1.2 chip or higher...require a password on boot.
sted Posted March 13, 2018 Posted March 13, 2018 Hmm, OK. The idea was to allow BitLocker to encrypt devices without TPM chips or TPM chips lower than 1.2...but for devices with a TPM 1.2 chip or higher...require a password on boot. thats what i thought but i had to create 2 policies/ous one for laptops with tpm one for those without. you can just set all to allow but then im not sure what settigns that laptop will get 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 (edited) thats what i thought but i had to create 2 policies/ous one for laptops with tpm one for those without. you can just set all to allow but then im not sure what settigns that laptop will get Think I'll have to do that. I've moved the test laptop to the 'Computers' OU, so no policies are being applied, yet Manage BitLocker still doesn't work and there is still no option to 'Turn on BitLocker' when right clicking the OS drive in File Explorer. So I'm guessing that BitLocker hasn't been enabled correctly during the OSD, or there's an issue with the image. This machine was running Windows 10 Education 1607 x64 and has had an in-place OS upgrade to Windows 10 Education 1709 x64. The WIM used for the upgrade is the same WIM that was used on my own workstation, which can launch BitLocker. However, it was an upgrade that was performed, not a fresh install. I may look at re-imaging the laptop. Edit: I have just logged on another machine that is runnign Windows 10 Education 1607 x64 - it also cannot launch BitLocker. Looks like I'll be doing a fresh install. Edited March 13, 2018 by CHiLL
Fazza Posted March 13, 2018 Posted March 13, 2018 Silly question, but I assume the OS you have on the computer supports BitLocker as not all do? 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 Silly question, but I assume the OS you have on the computer supports BitLocker as not all do? Yes it does. I forgot to add the OS in my OP. It's Windows 10 Education 1709 x64. I have made an amendment to my previous post, which points to an issue with the install of Windows 10 1607, which was then upgraded to 1709.
Martin48 Posted March 13, 2018 Posted March 13, 2018 I would worry about auto encrypting portable data drives, we force ours to read/only until encrypted as its vital what information leaving is encrypted, we get alot of users accidently encrypting then finding they cannot use on a mac then un-encrypting. 1
sted Posted March 13, 2018 Posted March 13, 2018 (edited) Think I'll have to do that. I've moved the test laptop to the 'Computers' OU, so no policies are being applied, yet Manage BitLocker still doesn't work and there is still no option to 'Turn on BitLocker' when right clicking the OS drive in File Explorer. So I'm guessing that BitLocker hasn't been enabled correctly during the OSD, or there's an issue with the image. This machine was running Windows 10 Education 1607 x64 and has had an in-place OS upgrade to Windows 10 Education 1709 x64. The WIM used for the upgrade is the same WIM that was used on my own workstation, which can launch BitLocker. However, it was an upgrade that was performed, not a fresh install. I may look at re-imaging the laptop. Edit: I have just logged on another machine that is runnign Windows 10 Education 1607 x64 - it also cannot launch BitLocker. Looks like I'll be doing a fresh install. id jsut try it on a vm at this point windows 10 (1709 at least) hyper v allows you to use fake tpm to test this stuff with and thats handy saves a lot of prating around with real pcs. i suspect on that laptop you may need to do some manage-bde and remove protectors that way as it did odd things to me when i mdt built a pc when the policies applied to it were contradictory. i never lost the control panel stuff but it wouldnt let me encrypt the drive jsut kept complaining about stuff (sorry i cant remember the specifics) iirc i had to remove some protectors Edited March 13, 2018 by sted 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 Maybe it's not an image problem. I've just check another 1709 computer and it also cannot open Manage BitLocker and the options are missing from File Explorer. This was definately imaged using the same image/TS/OSD as my own workstation. The only difference is that it was in an OU that has the computer restrictions. I have moved the computer to the same OU as my own machine and it still isn't working, despite gpupdates and reboots. So there appears to be something killing BitLocker and it won't come back. I'm going to create a new TS (not one to reimage, but steps to enable BitLocker again) and see if that works. I would worry about auto encrypting portable data drives, we force ours to read/only until encrypted as its vital what information leaving is encrypted, we get alot of users accidently encrypting then finding they cannot use on a mac then un-encrypting. That's a good point. I'll look into that.
sted Posted March 13, 2018 Posted March 13, 2018 you haven't got applocker policies applied have you as in my experience they seem to be once set they stay applied whatever you do to the pc short of a rebuild. 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 you haven't got applocker policies applied have you as in my experience they seem to be once set they stay applied whatever you do to the pc short of a rebuild. Only AppLocker settings are: Application Control Policieshide Appx Ruleshide No rules of type 'Appx Rules' are defined. Dll Ruleshide No rules of type 'Dll Rules' are defined. Executable Ruleshide Action User Name Rule Type Exceptions Allow Everyone (Default Rule) All files located in the Program Files folder Path No Allow Everyone (Default Rule) All files located in the Windows folder Path No Allow BUILTIN\Administrators (Default Rule) All files Path No Windows Installer Ruleshide No rules of type 'Windows Installer Rules' are defined. Script Ruleshide No rules of type 'Script Rules' are defined. When right clicking 'AppLocker' and selecting 'Properties', all the check boxes are not checked.
sted Posted March 13, 2018 Posted March 13, 2018 Only AppLocker settings are: Application Control Policieshide Appx Ruleshide No rules of type 'Appx Rules' are defined. Dll Ruleshide No rules of type 'Dll Rules' are defined. Executable Ruleshide Action User Name Rule Type Exceptions Allow Everyone (Default Rule) All files located in the Program Files folder Path No Allow Everyone (Default Rule) All files located in the Windows folder Path No Allow BUILTIN\Administrators (Default Rule) All files Path No Windows Installer Ruleshide No rules of type 'Windows Installer Rules' are defined. Script Ruleshide No rules of type 'Script Rules' are defined. When right clicking 'AppLocker' and selecting 'Properties', all the check boxes are not checked. its been a while since i looked at applocker i gave it up as a bad job it seemed to cause me many more issues than it solved sorry 1
mariohi Posted March 13, 2018 Posted March 13, 2018 Just go to run command by using Windows+R, then type Services.msc. Go to "shell hardware detection properties" and try to enable it. You can try to change it to Automatic or Manual. That's it. 1
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 Just go to run command by using Windows+R, then type Services.msc. Go to "shell hardware detection properties" and try to enable it. You can try to change it to Automatic or Manual. That's it. This! My colleague had a quick look with his fresh eyes and found an article regarding 'Shell Hardware Detection'. Lone behold, ours was set to Disabled and thus wasn't running. As soon as we enabled this, we could launch 'Manage BitLocker' and 'Turn on BitLocker' appears in the context menu of the OS drive. I'm not sure I'd have got to that at the rate I was going! Now to carry on with my testing! Thanks for the advice so far, though I may update this thread if (when) I run into more problems!
mavhc Posted March 13, 2018 Posted March 13, 2018 If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot. In your first post you were checking drive C using managebde but talking about a UFD?
CHiLL Posted March 13, 2018 Author Posted March 13, 2018 If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot. In your first post you were checking drive C using managebde but talking about a UFD? What specifically in BIOS needs to be enabled if it's TPM 1.2? by UFD do you mean a removable drive? I mentioned that because I couldn't launch 'Manage BitLocker' and there was no option on the context menu of the OS disk to 'Turn on BitLocker'. This was making me think that my settings weren't applying correctly. However, I used the same policy to configure BitLocker removable drives too. Since plugging in a USB drive brought up the option to encrypt it with BitLocker...that suggested that the policy was in some way working, but there was an issue with the OS disk configuration. I hope that makes sense.
mavhc Posted March 13, 2018 Posted March 13, 2018 USB Flash Drive, weird how no one knows the correct term. Anyway. What manufacturer? What BIOS? My HP desktops had 1.2, so I just ran the hp bios config exe with some options to enable it as a gpo script
sted Posted March 14, 2018 Posted March 14, 2018 If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot. In your first post you were checking drive C using managebde but talking about a UFD? whats the point of tpm only if someone nicks the laptop its unencrypted by turning it on it just stops people removing the drive/altering boot sequence order
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now