mavhc Posted March 14, 2018 Posted March 14, 2018 whats the point of tpm only if someone nicks the laptop its unencrypted by turning it on it just stops people removing the drive/altering boot sequence order They need a password to get into Windows to see the data. Stops someone accessing data by removing drive and putting in another machine, or booting from another drive.
CHiLL Posted March 16, 2018 Author Posted March 16, 2018 They need a password to get into Windows to see the data. Stops someone accessing data by removing drive and putting in another machine, or booting from another drive. That sounds good, though how does it work if someone manages to boot the laptop using a USB Linux distro or something?
mavhc Posted March 16, 2018 Posted March 16, 2018 Then the TPM detects Secure Boot wasn't complete, and refuses to release the key
CHiLL Posted March 16, 2018 Author Posted March 16, 2018 Then the TPM detects Secure Boot wasn't complete, and refuses to release the key Hmm, I'm pretty sure w had to turn off Secure Boot to allow Legacy/CSM booting. Either USB booting or SCCM deployment (I have a feeling it was for PXE boot). Maybe I'll have to disable it for imaging and then re-enable it before BitLocker encryption.
mavhc Posted March 16, 2018 Posted March 16, 2018 I'd look into keeping it on, without it you're relying on the bios to not let you boot other drives. https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-countermeasures
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now