Jump to content

Recommended Posts

Posted

At the moment all (well, most!) of our devices are encrypted using McAfee Drive Encryption, simply enough agent goes on device and links to McAfee ePO server to pick up encryption policies etc.

 

Now we've just been given a site wide license for Windows 10 Enterprise and I've been asked to look at the prospect at implementing BitLocker rather than McAfee Drive Encryption going forward as well...it's part of Windows 10 Enterprise so would save a few quid down the line if it worked out

 

The thing I'm struggling to get my head round is I was looking to do it all directly through Microsoft and stumbled across MBAM (Microsoft Bitlocker Administration and Monitoring) only to find Microsoft have essentially stopped supporting it in favour of SCCM and/or Azure (neither of which we have or are considering as a non educational establishment = £££££!)

 

So then I found McAfee offer extensions for ePO, Native Encryption for BitLocker - sounds great but what if we ditch McAfee in the future and either go native or to another solution e.g. Sophos would BitLocker still work even if we ripped the McAfee management part out? Someone else mentioned storing the recovery keys in AD but I'm not sure they would be if McAfee took over the management of them!

 

Very confused, the actual BitLocker part seems fairly simple it is just encrypting drives but it is the management and monitoring of the estate that is also quite important to keep our security auditors happy with some facts and figures!

 

Also for anyone that does use BitLocker what do you do in terms of laptops and pre boot authentication? McAfee is quite good in that respect in it sort of links in with Active Directory credentials then SSO to the actual OS, not so much an issue for desktops as they bypass pre boot authentication

Posted

I would imagine if they are bitlocker encrypted it wouldn’t really matter which software you use to manage them. As long as you can access recovery keys.

 

In terms of practice, if your clients have a TPM chip they won’t need a password/pin at boot (unless you specify you want one).

In our school settings we just use the TPM where possible.

Posted
Same here. Just enable the TPM in the BIOS if it isn't on already and configure bitlocker in GPO to store the keys with the computer's Active Directory object. It's all seamless as far as the user is concerned. If you need to find an encryption key that can be done through ADUC after you install the bitlocker feature on the server.
  • 3 months later...
Posted

bitlocker.JPG

 

I finally got around to looking at this properly, do the attached Group Policy settings look vaguely correct? (I added the Recovery Key tab to AD and can see those going in which is good) :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...