superaz300 Posted May 31, 2018 Posted May 31, 2018 Hello Guys, Wondering if anyone can help me out. I need to implement BitLocker on some of our Staff Laptops who take them offsite. We have an RM CC4 Network, and the laptops which BitLocker will be on are HP ProBook 450's G5s, and they do have TPM 2.0 support. I have created a GPO on the CC4 Server and applied it to these laptops, and the GPO sets the authentication options to use the TPM and a PIN. Here are the steps I have done. 1. Built the laptop onto CC4, with UEFI and Secure Boot Enabled. 2. After the build, gone into the BIOS and enabled the TPM. (Have to disable it first otherwise Windows 10 machines fail to build on CC4 as per the tech article on the RM website). 3. Logged onto the machine in question, and enabled BitLocker. I put in the users desired PIN, and backup the recovery key. 4. I reboot the machine after the encryption, and this is where I have issues. So, it reboots and I am presented with the screen to enter the users PIN, looks good so far, but I put the PIN in and it just goes straight to the recovery screen asking for the recovery key. If I reboot the machine again, and put in a wrong PIN on purpose, it does tell me the PIN is wrong so I know the PIN is right. Anyways, I do what it asks and type in the Recovery key, but it tells me every time it is invalid! I keep having to rebuild the machine, to get it to boot again. Can anyone tell me if I am missing anything? I have spent 2 days on this now, and I am really stuck. I have asked RM, and they have told me it is not as yet supported on CC4, however they have customers who have successfully implemented this themselves. Many Thanks James
MartinT Posted May 31, 2018 Posted May 31, 2018 Get rid of RM CC4? We have BitLockered all our laptops and tablets. Where they have TPM, they just boot into Windows directly. Where they don't, they stop and ask for the password. It all works very smoothly and, since we record all BitLocker passwords and keep the recovery files, we have not lost a single machine build yet.
superaz300 Posted May 31, 2018 Author Posted May 31, 2018 Get rid of RM CC4? We have BitLockered all our laptops and tablets. Where they have TPM, they just boot into Windows directly. Where they don't, they stop and ask for the password. It all works very smoothly and, since we record all BitLocker passwords and keep the recovery files, we have not lost a single machine build yet. Hi Martin Thanks for your reply. Ah if only that was an option! Although the way things are going here, there is talks abouts scrapping it which I hope we do to be honest! May I ask exactly how you configured it, and what GPO settings you set? Many Thanks James
deano3693 Posted May 31, 2018 Posted May 31, 2018 RM are actively working on Bitlocker Support currently. I'm on the field trial - Drop me a PM and i can give you some more info.
Norphy Posted May 31, 2018 Posted May 31, 2018 Bitlocker has been a thing since Vista appeared on the market. Vista was released at the beginning of 2007. How can RM not be supporting it? Somehow, my opinion of them is now even worse than it was before and it was pretty damned bad to begin with.
MartinT Posted June 1, 2018 Posted June 1, 2018 May I ask exactly how you configured it, and what GPO settings you set? The two critical settings for the OS boot drive are: Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Operating System Drives - Require additional authentication at startup (Enabled, all options set to Allow...) - Enable use of BitLocker authentication requiring preboot keyboard input on slates (Enabled - essential for Microsoft Surface or other tablets when without a keyboard) For USB drives: Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives - Deny write access to removable drives not protected by BitLocker (Enabled)
Lardboy Posted June 26, 2018 Posted June 26, 2018 We have given Veracrypt a try and it seems to work like a charm. All I have done so far is just encrypted the system partition and it doesn't seem to affect the boot up (or anything else for that matter). All in testing though but it might be worth a try for you.
deano3693 Posted June 30, 2018 Posted June 30, 2018 https://support.rm.com/GeneralDownload.asp?cref=DWN6320284&nav=0&referrer=SupportHome
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now