enjay Posted August 21, 2018 Posted August 21, 2018 I'm struggling somewhat with Bitlocker here. I thought I'd created the GPOs correctly, but I can't see how to enforce a drive must be encrypted. Is there a dummy's guide anywhere? All the ones I've found on a quick search are for the more advanced settings, not the noob basics...
Steve21 Posted August 21, 2018 Posted August 21, 2018 Deny write access to removable drives not protected by BitLocker Is the GPO to force removable to be encrypted if they're writing to them. (Or did you mean OS drives?) Will try to get a screenshot of ours once home as I've only enabled the basics for them as still using split site. Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 Deny write access to removable drives not protected by BitLocker That's the tick box I can't find in the GPO... Is the GPO to force removable to be encrypted if they're writing to them. (Or did you mean OS drives?) Memory sticks only, staff don't have school laptops so no need to worry about OS drive encryption Will try to get a screenshot of ours once home as I've only enabled the basics for them as still using split site. That would be great, thanks.
Steve21 Posted August 22, 2018 Posted August 22, 2018 Sorry forgot to do that yesterday! (We don't force the newer bitlocker encryption as still running split site so this is a 7/10 GPO) Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 Thanks. That's more of less what I've got too. The only difference is I ticked "allow users to apply Bitlocker protection on removable data drives" too. I don't have the very top one about forced password complexity, but that is coming from another GPO so is still in the mix. I wonder if the issue is in my GPO targetting then. I'd made it a Computer Policy, applied at a computer-level OU but changed the "Security Filtering" from 'Authenticated Users' to the staff user group (in case students were to log in to teacher PCs).
Steve21 Posted August 22, 2018 Posted August 22, 2018 You can't do that, it's a computer based GPO so it's applied to computers, not users. (Unless you do the bitlocker per user "workaround" that's in another thread on here) Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 You can't do that, it's a computer based GPO so it's applied to computers, not users. (Unless you do the bitlocker per user "workaround" that's in another thread on here) Yeah, that got it. I'll take another look at the GPP per user thing now I've got a working GPO, but this will do if need be. Not exactly speedy though - going to take perhaps 10 minutes to encrypt the 8GB stick I'm testing with. If I wanted to prompt for encryption but not require it (initially, just to give people time to encrypt) would I just untick the "deny write access to removable drives not protected by Bitlocker"?
Steve21 Posted August 22, 2018 Posted August 22, 2018 Are you running Win7 or 10? If 10 there's the option of only encrypting used space rather than the whole drive which makes it a lot quicker, and remember it runs in the background so doesn't seem so bad for an end user who plugs it in to use it Err not sure it'll prompt at all if you remove that GPO, as you aren't forcing it so they'd have to right-click turn on bitlocker etc Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 10 in school, but users may have 7 or 8 at home (plus the Macs of course, but I'll handle them separately) I note in your GPO, you've removed the recovery options from the wizard. That would make it simpler to encrypt, but doesn't it increase the chance of users bricking their drives when (and I do mean "when" not "if") they forget the password?
Steve21 Posted August 22, 2018 Posted August 22, 2018 No, it's set to auto backup to AD all passwords, so removing it just removes the option for the user to do an additional key backup. All passwords get stored against the AD account and can be retrieved through AD. Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 (edited) I can't see the option in my AD. Also, even if I could, wouldn't I need to know which PC had been used to encrypt the stick? I can't imagine staff remembering that, and even if they did, what if we'd ditched the computer since? Sorry if I'm being thick! Edited August 22, 2018 by enjay
mavhc Posted August 22, 2018 Posted August 22, 2018 USB drives do take ages to write to, the cheaper they are, the longer they take
Steve21 Posted August 22, 2018 Posted August 22, 2018 You need to turn it on as a feature first. (All DCs enable Bitlocker Drive Encryption (no you don't need to use it on DC just need it installed)) The keys get stored in AD when it's encrypted (using that GPO options I set) Then in AD you can do a search by the recovery ID and it finds what machine it was and the key. etc Steve
mavhc Posted August 22, 2018 Posted August 22, 2018 https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-use-bitlocker-recovery-password-viewer you need this You can also search for the unique key it gives you for recovery, to find the right password
enjay Posted August 22, 2018 Author Posted August 22, 2018 Is it just the Bitlocker Recovery Password Viewer feature which I need to add to my DC? Even with the key search, I'd still have problems if the PC had been deleted, wouldn't I? Should I start keeping old PCs in a sub-OU somewhere in AD in case the account is needed for Bitlocker key recovery?
Steve21 Posted August 22, 2018 Posted August 22, 2018 Literally just enable Bitlocker Drive Encryption role (ok and a reboot for any fussy pots ) In regards to the deleting part, it's not often (well at least in my case) that a machine is actually deleted, as renames/reimage doesn't wipe it from AD. But yes in that case you'd either need to make a backup of the key or keep the old AD account somewhere. But that's still going to be less often and more likely to be done properly than relying on a user to do it and save the key somewhere Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 Literally just enable Bitlocker Drive Encryption role (ok and a reboot for any fussy pots ) I'd seen that feature, but was being cautious as I don't want our servers to require Bitlocker encryption on them. In regards to the deleting part, it's not often (well at least in my case) that a machine is actually deleted, as renames/reimage doesn't wipe it from AD We tend to delete the old machine account from AD after renaming a computer.
Steve21 Posted August 22, 2018 Posted August 22, 2018 It'll give you the option to enable it on the server, but unless you push a GPO to it or something silly it'll just sit there quietly If you rename a computer that's connected to a domain it should rename the AD account automatically for you. But there is an option to just right-click copy the bitlocker details if you want to still do that. Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 The machine account will still be deleted eventually though.
Steve21 Posted August 22, 2018 Posted August 22, 2018 I don't get what you mean, If for arguments sake you have 500 computers and 500 AD accounts there's never a "need" to delete an AD account really, rebuild a machine and it'll link back to that account, rename a computer and the account renames etc. Ok yes if you cut 500 pcs to 250, no doubt you'd delete them sometime, but in reality if that's the case there's probably a bigger story behind it and exporting a few keys isn't the end of the world Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 I'm thinking of a scenario where a room is decommissioned and the PCs in it thrown out - we will likely be doing that to one of our IT Suites next summer. In that instance, the computer IT3-01 will be going in the bin, not being renamed Finance02 or whatever.
enjay Posted August 22, 2018 Author Posted August 22, 2018 I'm thinking of a scenario where a room is decommissioned and the PCs in it thrown out - we will likely be doing that to one of our IT Suites next summer. In that instance, the computer IT3-01 will be going in the bin, not being renamed Finance02 or whatever. it is not uncommon for a PC to be re-imaged with a new name either. This summer, for example, my technician rebuilt all our Win7 PCs to Win10 and renamed them all with a W10 suffix in the process (don't ask me why!). If for any reason he rebuilds one of these later in the year to fix a problem on it, he will likely give it another suffix too, e.g. IT1-07-W10-B. He would then delete the old machine accounts for IT1-07 and IT1-07-W10. I could always stop him doing this, I suppose...
Steve21 Posted August 22, 2018 Posted August 22, 2018 Yep, but I'm assuming in that scenario of say 30 computers, only 1 is a staff one with bitlocker enabled? So you'd only have to keep 1 AD account or copy one set of bitlocker keys off of it. There's always going to be issues with any system, but as mentioned what's likely to cause more issues 100s of staff having to save keys and remember where they are etc, or IT copying one set of bitlocker keys when deleting a machine? Steve
enjay Posted August 22, 2018 Author Posted August 22, 2018 Yes, although often staff PCs move to student locations when they're upgraded, so the student PCs in the Learning Support area may well have been staff PCs earlier in their lives. I'm just trying to make sure I have all eventualities covered, because I really don't want my team to be responsible for an encrypted memory stick getting irrecoverably bricked, so I want to make sure I understand how and where the keys are stored and how to make sure I don't lose any over time. For obvious reasons, I'm not brave/stupid enough to tick the boxes for Bitlocker and restart our servers overnight today so I'll save that part for later in the week.
mavhc Posted August 22, 2018 Posted August 22, 2018 It's just a text string, so you can export it if you want to delete the computer
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now