Jump to content

Recommended Posts

Posted

Is there a way we could force bitlocker encryption on removable drives when using Win7 Enterprise? We want to aiming to move towards not permitting removable storage, however some staff say they have teaching resources that don't include sensitive data and it's causing some issues as to the blanket-ban proposal. It seems an interim measure, or where circumstances require, we could enable/force encryption, but we'd want to be making sure that non-encrypted devices couldn't be used freely.

 

As we are RM CC4 then the facility to do so isn't included in an RMMC so we'd be looking at the vanilla gpo approach. What's the most efficient way of achieving this, or is there an alternate way of going about it?

Posted
You only need to set a few policies under the Bitlocker section in the GPO, just be aware though you are best getting staff drives encrypted first as it can take a considerable amount of time in some cases and they are likely to get bored and pull it out before its finished if you force it on them and expect them to go through the process. You can also set it to be read only for unencrypted removable storage which allows them to get things off but not save them which encourages them to get it encrypted. You also have to consider cameras and other items that will be treated as removable storage.
  • Thanks 1
Posted
You only need to set a few policies under the Bitlocker section in the GPO, just be aware though you are best getting staff drives encrypted first as it can take a considerable amount of time in some cases and they are likely to get bored and pull it out before its finished if you force it on them and expect them to go through the process. You can also set it to be read only for unencrypted removable storage which allows them to get things off but not save them which encourages them to get it encrypted. You also have to consider cameras and other items that will be treated as removable storage.

 

I hadn't considered the possibility of alternate approaches before, so perhaps read-only access for no encryption would be a consideration too.

 

 

I wasn't aware of this thread, so useful to see that others have (recently) also been trying to achieve the same thing. Perhaps we'll take a look at MBAM to do this instead.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...