Jump to content

Recommended Posts

Posted (edited)

In light of GDPR, we have started looking at BitLocker for our devices that are taken off-site and doing some testing to see how it works. So far I've done the following configuration on our domain and prerequisites:

 

  • GPO Created defining that all OS and fixed data drives are fully encrypted, and removable drives are used-space only encrypted. I've also specified to use AD DS backup for BitLocker, as well as defining the type of encryption to use, complexity, etc.
  • Incorporated MBAM into SCCM
  • Configured the OU to delegate control for the 'SELF' user (multiple sources recommended this)
  • Added ACE for the TPM to AD DS (as recommended in a MS article)
  • Devices imaged using SCCM have the following step in the TS during the 'Format Disk' stage section: 'Pre-provision BitLocker' and then followed later in the 'Post Install' section with 'Enable BitLocker'

I have a test laptop in a test OU with the above GPO linked. When I insert a USB drive into the laptop, BitLocker automatically prompts to encrypt the drive and use it, or not encrypt it and only use it as read-only. This shows that the GPO is working.

 

However, when I run the following command on the laptop to check BitLocker status:

manage-bde -status c:

It states:

[OS Volume]
Size: 464.80GB
BitLocker Version: None
Conversion Status: Fully Decrypted
Percentage Encrypted: 0.0%
Encryption Method: None
Protection Status: Protection Off
Lock Status: Unlocked
Identification Field: None
Key Protectors: None Found

 

I don't understand why BitLocker Version is reporting 'None', yet BitLocker prompts when a USB drive is inserted.

 

Also, I cannot start 'Manage BitLocker'. When I search the Start Menu for it, it shows in the results as a Control Panel item, but pressing it does nothing. I also cannot find it manually in Control Panel.

 

Once I've sorted that out, how can I automatically start the encryption of the laptop? Rather than having to manually start it.

 

Any ideas?

Edited by CHiLL
Posted

have you actually encrypted the drive as gpo alone will just put settings there so you can you need to right click the drive and encrypt and follow any prompts for password etc.

 

Its easy to create a gpo for bitlocker that dosent work as it has conflicting settings usually the require additional authentication at startup settings. if you set them wrong you are effectively asking it to do mutually exclusive things and when you try to encrypt the drive it will fail. as for encrypting as part of the imaging process id test the gpos before doing that as i did the above mistake and it took me ages to get the drive to encrypt as it wrote info to it that was wrong and i had to mess around with manage-bde powershell to remove encryption options that had failed. you also to deploy it as part of a task sequence (at least in mdt) need to have a tpm chip

  • Thanks 1
Posted
have you actually encrypted the drive as gpo alone will just put settings there so you can you need to right click the drive and encrypt and follow any prompts for password etc.

 

Its easy to create a gpo for bitlocker that dosent work as it has conflicting settings usually the require additional authentication at startup settings. if you set them wrong you are effectively asking it to do mutually exclusive things and when you try to encrypt the drive it will fail. as for encrypting as part of the imaging process id test the gpos before doing that as i did the above mistake and it took me ages to get the drive to encrypt as it wrote info to it that was wrong and i had to mess around with manage-bde powershell to remove encryption options that had failed. you also to deploy it as part of a task sequence (at least in mdt) need to have a tpm chip

Cheers for the reply. I actually don't have an option to encrypt when I right click the drive, which doesn't bode well.

Posted

what about if you log in as local admin have you somehow removed the option with gpo?

might be worth running rsop/rsop and seeing exactly what policies are applied to the machine maybe theres some other settings somewhere else

  • Thanks 1
Posted (edited)
what about if you log in as local admin have you somehow removed the option with gpo?

might be worth running rsop/rsop and seeing exactly what policies are applied to the machine maybe theres some other settings somewhere else

The option is also missing for the local admin. I've done RSOP, but not sure what I'm looking for. The configured BitLocker policies are as follows:

 

Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption

Policy Setting Winning GPO 
Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) Enabled TESTING - C - BitLocker 
Select the encryption method for operating system drives: XTS-AES 256-bit 
Select the encryption method for fixed data drives: XTS-AES 256-bit 
Select the encryption method for removable data drives: XTS-AES 256-bit 

Policy Setting Winning GPO 
Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) Enabled TESTING - C - BitLocker 
Select the encryption method: AES 256-bit 

Policy Setting Winning GPO 
Disable new DMA devices when this computer is locked Enabled TESTING - C - BitLocker 
Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) Enabled TESTING - C - BitLocker 
Require BitLocker backup to AD DS Enabled 
If selected, cannot turn on BitLocker if backup fails (recommended default).  
If not selected, can turn on BitLocker even if backup fails. Backup is not automatically retried. 
Select BitLocker recovery information to store: Recovery passwords and key packages 

A recovery password is a 48-digit number that unlocks access to a BitLocker-protected drive. 
A key package contains a drive's BitLocker encryption key secured by one or more recovery passwords 
Key packages may help perform specialized recovery when the disk is damaged or corrupted.  

 

Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Fixed Data Drives

Policy Setting Winning GPO 
Allow access to BitLocker-protected fixed data drives from earlier versions of Windows Enabled TESTING - C - BitLocker 
Do not install BitLocker To Go Reader on FAT formatted fixed drives Disabled 

Policy Setting Winning GPO 
Choose how BitLocker-protected fixed drives can be recovered Enabled TESTING - C - BitLocker 
Allow data recovery agent Enabled 
Configure user storage of BitLocker recovery information: 
Allow 48-digit recovery password 
Allow 256-bit recovery key 
Omit recovery options from the BitLocker setup wizard Disabled 
Save BitLocker recovery information to AD DS for fixed data drives Enabled 
Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages 
Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives Enabled 

Policy Setting Winning GPO 
Configure use of hardware-based encryption for fixed data drives Enabled TESTING - C - BitLocker 
Use BitLocker software-based encryption when hardware encryption is not available Enabled 
Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled 
Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 

Policy Setting Winning GPO 
Configure use of passwords for fixed data drives Enabled TESTING - C - BitLocker 
Require password for fixed data drive Disabled 
Configure password complexity for fixed data drives: Require password complexity 
Minimum password length for fixed data drive: 8 
Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. 

Policy Setting Winning GPO 
Deny write access to fixed drives not protected by BitLocker Enabled TESTING - C - BitLocker 
Enforce drive encryption type on fixed data drives Enabled TESTING - C - BitLocker 
Select the encryption type:   

 

Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Operating System Drives

Policy Setting Winning GPO 
Allow enhanced PINs for startup Enabled TESTING - C - BitLocker 
Configure minimum PIN length for startup Enabled TESTING - C - BitLocker 
Minimum characters: 8 

Policy Setting Winning GPO 
Configure use of passwords for operating system drives Enabled TESTING - C - BitLocker 
Configure password complexity for operating system drives: Require password complexity 
Minimum password length for operating system drive: 8 
Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. 
Require ASCII-only passwords for removable OS drives Disabled 

Policy Setting Winning GPO 
Enforce drive encryption type on operating system drives Enabled TESTING - C - BitLocker 
Select the encryption type:   

Policy Setting Winning GPO 
Require additional authentication at startup Enabled TESTING - C - BitLocker 
Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive) Enabled 
Settings for computers with a TPM: 
Configure TPM startup: Allow TPM 
Configure TPM startup PIN: Require startup PIN with TPM 
Configure TPM startup key: Allow startup key with TPM 
Configure TPM startup key and PIN: Allow startup key and PIN with TPM 

 

Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Removable Data Drives

Policy Setting Winning GPO 
Allow access to BitLocker-protected removable data drives from earlier versions of Windows Enabled TESTING - C - BitLocker 
Do not install BitLocker To Go Reader on FAT formatted removable drives Disabled 

Policy Setting Winning GPO 
Choose how BitLocker-protected removable drives can be recovered Enabled TESTING - C - BitLocker 
Allow data recovery agent Enabled 
Configure user storage of BitLocker recovery information: 
Allow 48-digit recovery password 
Allow 256-bit recovery key 
Omit recovery options from the BitLocker setup wizard Disabled 
Save BitLocker recovery information to AD DS for removable data drives Enabled 
Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages 
Do not enable BitLocker until recovery information is stored to AD DS for removable data drives Enabled 

Policy Setting Winning GPO 
Configure use of hardware-based encryption for removable data drives Enabled TESTING - C - BitLocker 
Use BitLocker software-based encryption when hardware encryption is not available Enabled 
Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled 
Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 

Policy Setting Winning GPO 
Configure use of passwords for removable data drives Enabled TESTING - C - BitLocker 
Require password for removable data drive Enabled 
Configure password complexity for removable data drives: Require password complexity 
Minimum password length for removable data drive: 8 
Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. 

Policy Setting Winning GPO 
Control use of BitLocker on removable drives Enabled TESTING - C - BitLocker 
Allow users to apply BitLocker protection on removable data drives Enabled 
Allow users to suspend and decrypt BitLocker protection on removable data drives Enabled 

Policy Setting Winning GPO 
Deny write access to removable drives not protected by BitLocker Enabled TESTING - C - BitLocker 
Do not allow write access to devices configured in another organization Disabled 

Policy Setting Winning GPO 
Enforce drive encryption type on removable data drives Enabled TESTING - C - BitLocker 
Select the encryption type: Used Space Only encryption 

 

What I've actually noticed in that is the 'Select the encryption type: ' field for both OS and fixed data drives appears blank in RSOP. Whereas the policy states that they should both be set to 'Full encryption'. I had done multiple gpupdate /force and reboots before gathering the RSOP data.

Edited by CHiLL
Posted

i think id start a new ou and get a test machine and try settings a few at a time but

 

Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive) Enabled Settings for computers with a TPM: Configure TPM startup: Allow TPM Configure TPM startup PIN: Require startup PIN with TPM Configure TPM startup key: Allow startup key with TPM Configure TPM startup key and PIN: Allow startup key and PIN with TPM

theres your problem id bet

you have Allow BitLocker without a compatible TPM ticked but Require startup PIN with TPM selected as well. those settings are odd if you want require a pin and tpm everything else has to be set to do not allow or even if the wizard shows it will bomb out saying basically you cant apply a contradictory policy

 

as to why you cant see the bitlocker options i dont know i suspect control panel; access is restricted somewhere rather than bitlocker itself maybe you have a policy to only show specif control panel applets set

  • Thanks 1
Posted
i think id start a new ou and get a test machine and try settings a few at a time but

 

theres your problem id bet

you have Allow BitLocker without a compatible TPM ticked but Require startup PIN with TPM selected as well. those settings are odd if you want require a pin and tpm everything else has to be set to do not allow or even if the wizard shows it will bomb out saying basically you cant apply a contradictory policy

 

as to why you cant see the bitlocker options i dont know i suspect control panel; access is restricted somewhere rather than bitlocker itself maybe you have a policy to only show specif control panel applets set

Hmm, OK.

The idea was to allow BitLocker to encrypt devices without TPM chips or TPM chips lower than 1.2...but for devices with a TPM 1.2 chip or higher...require a password on boot.

Posted
Hmm, OK.

The idea was to allow BitLocker to encrypt devices without TPM chips or TPM chips lower than 1.2...but for devices with a TPM 1.2 chip or higher...require a password on boot.

thats what i thought but i had to create 2 policies/ous one for laptops with tpm one for those without. you can just set all to allow but then im not sure what settigns that laptop will get

  • Thanks 1
Posted (edited)
thats what i thought but i had to create 2 policies/ous one for laptops with tpm one for those without. you can just set all to allow but then im not sure what settigns that laptop will get

Think I'll have to do that.

 

I've moved the test laptop to the 'Computers' OU, so no policies are being applied, yet Manage BitLocker still doesn't work and there is still no option to 'Turn on BitLocker' when right clicking the OS drive in File Explorer.

 

So I'm guessing that BitLocker hasn't been enabled correctly during the OSD, or there's an issue with the image. This machine was running Windows 10 Education 1607 x64 and has had an in-place OS upgrade to Windows 10 Education 1709 x64. The WIM used for the upgrade is the same WIM that was used on my own workstation, which can launch BitLocker. However, it was an upgrade that was performed, not a fresh install. I may look at re-imaging the laptop.

 

Edit: I have just logged on another machine that is runnign Windows 10 Education 1607 x64 - it also cannot launch BitLocker. Looks like I'll be doing a fresh install.

Edited by CHiLL
Posted
Silly question, but I assume the OS you have on the computer supports BitLocker as not all do?

Yes it does. I forgot to add the OS in my OP. It's Windows 10 Education 1709 x64. I have made an amendment to my previous post, which points to an issue with the install of Windows 10 1607, which was then upgraded to 1709.

Posted
I would worry about auto encrypting portable data drives, we force ours to read/only until encrypted as its vital what information leaving is encrypted, we get alot of users accidently encrypting then finding they cannot use on a mac then un-encrypting.
  • Thanks 1
Posted (edited)
Think I'll have to do that.

 

I've moved the test laptop to the 'Computers' OU, so no policies are being applied, yet Manage BitLocker still doesn't work and there is still no option to 'Turn on BitLocker' when right clicking the OS drive in File Explorer.

 

So I'm guessing that BitLocker hasn't been enabled correctly during the OSD, or there's an issue with the image. This machine was running Windows 10 Education 1607 x64 and has had an in-place OS upgrade to Windows 10 Education 1709 x64. The WIM used for the upgrade is the same WIM that was used on my own workstation, which can launch BitLocker. However, it was an upgrade that was performed, not a fresh install. I may look at re-imaging the laptop.

 

Edit: I have just logged on another machine that is runnign Windows 10 Education 1607 x64 - it also cannot launch BitLocker. Looks like I'll be doing a fresh install.

id jsut try it on a vm at this point windows 10 (1709 at least) hyper v allows you to use fake tpm to test this stuff with and thats handy saves a lot of prating around with real pcs.

 

i suspect on that laptop you may need to do some manage-bde and remove protectors that way as it did odd things to me when i mdt built a pc when the policies applied to it were contradictory. i never lost the control panel stuff but it wouldnt let me encrypt the drive jsut kept complaining about stuff (sorry i cant remember the specifics) iirc i had to remove some protectors

Edited by sted
  • Thanks 1
Posted

Maybe it's not an image problem. I've just check another 1709 computer and it also cannot open Manage BitLocker and the options are missing from File Explorer. This was definately imaged using the same image/TS/OSD as my own workstation. The only difference is that it was in an OU that has the computer restrictions. I have moved the computer to the same OU as my own machine and it still isn't working, despite gpupdates and reboots.

 

So there appears to be something killing BitLocker and it won't come back.

 

I'm going to create a new TS (not one to reimage, but steps to enable BitLocker again) and see if that works.

 

I would worry about auto encrypting portable data drives, we force ours to read/only until encrypted as its vital what information leaving is encrypted, we get alot of users accidently encrypting then finding they cannot use on a mac then un-encrypting.

That's a good point. I'll look into that.

Posted
you haven't got applocker policies applied have you as in my experience they seem to be once set they stay applied whatever you do to the pc short of a rebuild.
  • Thanks 1
Posted
you haven't got applocker policies applied have you as in my experience they seem to be once set they stay applied whatever you do to the pc short of a rebuild.

Only AppLocker settings are:

Application Control Policieshide
Appx Ruleshide
No rules of type 'Appx Rules' are defined.
Dll Ruleshide
No rules of type 'Dll Rules' are defined.
Executable Ruleshide
Action User Name Rule Type Exceptions 
Allow Everyone (Default Rule) All files located in the Program Files folder Path No 
Allow Everyone (Default Rule) All files located in the Windows folder Path No 
Allow BUILTIN\Administrators (Default Rule) All files Path No 

Windows Installer Ruleshide
No rules of type 'Windows Installer Rules' are defined.
Script Ruleshide
No rules of type 'Script Rules' are defined.

When right clicking 'AppLocker' and selecting 'Properties', all the check boxes are not checked.

Posted
Only AppLocker settings are:

Application Control Policieshide
Appx Ruleshide
No rules of type 'Appx Rules' are defined.
Dll Ruleshide
No rules of type 'Dll Rules' are defined.
Executable Ruleshide
Action User Name Rule Type Exceptions 
Allow Everyone (Default Rule) All files located in the Program Files folder Path No 
Allow Everyone (Default Rule) All files located in the Windows folder Path No 
Allow BUILTIN\Administrators (Default Rule) All files Path No 

Windows Installer Ruleshide
No rules of type 'Windows Installer Rules' are defined.
Script Ruleshide
No rules of type 'Script Rules' are defined.

When right clicking 'AppLocker' and selecting 'Properties', all the check boxes are not checked.

 

its been a while since i looked at applocker i gave it up as a bad job it seemed to cause me many more issues than it solved sorry

  • Thanks 1
Posted
Just go to run command by using Windows+R, then type Services.msc. Go to "shell hardware detection properties" and try to enable it. You can try to change it to Automatic or Manual. That's it.
  • Thanks 1
Posted
Just go to run command by using Windows+R, then type Services.msc. Go to "shell hardware detection properties" and try to enable it. You can try to change it to Automatic or Manual. That's it.

This! My colleague had a quick look with his fresh eyes and found an article regarding 'Shell Hardware Detection'. Lone behold, ours was set to Disabled and thus wasn't running. As soon as we enabled this, we could launch 'Manage BitLocker' and 'Turn on BitLocker' appears in the context menu of the OS drive. I'm not sure I'd have got to that at the rate I was going!

 

Now to carry on with my testing! Thanks for the advice so far, though I may update this thread if (when) I run into more problems!

Posted

If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot.

 

In your first post you were checking drive C using managebde but talking about a UFD?

Posted
If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot.

 

In your first post you were checking drive C using managebde but talking about a UFD?

What specifically in BIOS needs to be enabled if it's TPM 1.2?

 

by UFD do you mean a removable drive? I mentioned that because I couldn't launch 'Manage BitLocker' and there was no option on the context menu of the OS disk to 'Turn on BitLocker'. This was making me think that my settings weren't applying correctly. However, I used the same policy to configure BitLocker removable drives too. Since plugging in a USB drive brought up the option to encrypt it with BitLocker...that suggested that the policy was in some way working, but there was an issue with the OS disk configuration. I hope that makes sense.

Posted

USB Flash Drive, weird how no one knows the correct term. Anyway.

 

What manufacturer? What BIOS? My HP desktops had 1.2, so I just ran the hp bios config exe with some options to enable it as a gpo script

Posted
If you have TPM 1.2 you have to enable in the BIOS, if 2.0 it's automatic. With TPM you don't need a password on boot.

 

In your first post you were checking drive C using managebde but talking about a UFD?

 

whats the point of tpm only if someone nicks the laptop its unencrypted by turning it on it just stops people removing the drive/altering boot sequence order

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...