CHiLL Posted May 3, 2018 Posted May 3, 2018 (edited) I have installed MBAM correctly, deployed the MBAM client to a test laptop and now looking at the GPO configuration. I understand that I'm only to change the settings within 'MDOP MBAM (BitLocker Management)' section, not the 'BitLocker Drive Encryption' section, as those settings are autoamtically configured when the MBAM settings are changed and changing those manually could break the BitLocker configuration (stated by MS in MBAM articles). With that, I've enabled the settings for the OS drive encryption and noticed three things: 1) I have set the 'Encryption Policy Enforcement Settings' to '0', which should automatically start the encryption on the device - but it isn't. The device is only being encrypted when I manually enable BitLocker on the OS drive (right clicking the drive) 2) When the BitLocker wizard is manually started by right clicking the OS drive, it opens the wizard but then asks 'Choose how to unlock the drive at start-up' and gives three options; Enter a PIN (recommended), Insert USB flash drive or Let BitLocker unlock my drive automatically. As encrypting OS drives will only be for laptops, I'd prefer to use the latter option, as the drive will be encrypted if it is stolen and a local username and password is required to log in to access any data on it. How to I set the GPO using MBAM to have this as the automatic option? Ideally so that window doesn't appear at all. 3) From what I've gathered the default disk encryption level is used space only. Ideally I'd prefer it to be full disk encryption, but I can't seem to set that via MBAM GPO. Any idea how I can set this? Thanks. Edited May 3, 2018 by CHiLL
CHiLL Posted May 18, 2018 Author Posted May 18, 2018 For 1) and 2) - Turns out the GPO wasn't working correctly. I recreated it from scratch and it worked. For 3) - You can enable the setting 'Enforce drive encryption type on operating system drives' in the normal (non-MBAM) GPO settings (Windows Components > BitLocker Drive Encryption > Operating System Drives) and it won't cause issues with the MBAM settings. That does then enforce full disk encryption.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now