Jump to content

Recommended Posts

Posted

Just need a quick sanity check on this...

 

- staff PCs, old Stone kit (Intel and MSI motherboards)

- no TPM on either motherboard

- machines are shared between multiple users

 

Although Bitlocker can in theory be deployed using the USB stick or boot password method is it reasonable to say that's not a feasible method for the scenario above?

 

My thinking being either the USB would stay in the whole time (which defeats the object of it) and similar for password (plus the inevitable glut of helpdesk queries when it gets lost) and realistically for staff machines we simply need to replace the (5-7 year old) hardware with something with TPM support.

Posted
If replacing with something with TPM support is an option, go with that. You might be able to look at SEDs although I think BitLocker still requires TPM even with a SED (could be wrong).
  • Thanks 1
Posted

Are you saving anything on the desktops or are the profiles redirected, the home drives on central storage as well?

 

If there is nothing saved on the computers then why are you encrypting them?

 

Windows 10 should do encryption with Bitlocker and a PIN only, which will inevitably everyone will know if it is shared and will be on a note on the monitor in no time.

  • Thanks 1
Posted
Are you saving anything on the desktops or are the profiles redirected, the home drives on central storage as well?

If there is nothing saved on the computers then why are you encrypting them?

 

A couple of reasons...

  • Local MIS apps may hold temporary data or exported reports (Desktop not redirected, Documents is)
  • Local drives hold OneDrive cache for Files on Demand

 

Windows 10 should do encryption with Bitlocker and a PIN only, which will inevitably everyone will know if it is shared and will be on a note on the monitor in no time.

Yup, which I feel is basically pointless so if we're going to do encryption it should be done in a way that's actually effective.

Posted (edited)
no TPM on either motherboard

On some Asus and Gigabyte motherboards there is a TPM header.

 

If yours have this you might be able to buy a TPM module for them (although given the age of the PCs it might be difficult to source)?

Edited by Arthur
Posted

I am in a similar situation like yourself. We have 6+ year old RM workstations that don't have TPM and some laptops that support TPM whilst others don't.

 

I have Bitlocker'ed the laptops so that upon bootup it asks for a password before you can proceed ahead.

 

Workstations, however, are being left as they are: no encryption. The way I see it is all user data and shared drives are directed to file servers, thus negating the need to encrypt. If you have done a risk assessment around GDPR, Data Protection Act et all, then you're okay. Going forward, when the school gets around to refreshing said workstations that support TPM, then I will enable Bitlocker as standard. Until then, we're not worried about it at all.

Posted
The way I see it is all user data and shared drives are directed to file servers, thus negating the need to encrypt.

What about the page/hibernation file, temp/cache files and everything in %LOCALAPPDATA%? :confused:

 

Without encrypting the entire drive there isn't any way to ensure confidential and/or personal data saved locally is protected.

Posted
What about the page/hibernation file, temp/cache files and everything in %LOCALAPPDATA%? :confused:

 

Without encrypting the entire drive there isn't any way to ensure confidential and/or personal data saved locally is protected.

 

I agree with you. Upon shutdown I have the page file nuked. Hibernation is disabled by default.

 

Using DELPROF, profiles are deleted at shutdown.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...