Jump to content

Recommended Posts

Posted

Hello all,

 

I'm looking for information to setup bitlocker via Group Policy but can't really find any information at all that provides tutorials on the Internet. I just want a situation where users who plug in their USB sticks are required to encrypt them if they haven't done so already.

 

They mainly run Windows 10 Education or LTSB, some are still on Windows 7 Pro, to be upgraded. Customers run Windows Server 2016.

 

Thanks all for any help.

Posted

I could be wrong here but I'm not sure that Group Policy can block unencrypted USB drives completely, although it can prevent write access to unencrypted drives, with the following setting:

 

Computer Configuration > Administrative Templates > Windows Components > Bitlocker Drive Encryption > Removable Data Drives

 

We use Netsupport DNA to manage our USB drives, so that only approved ones can be used.

  • Thanks 1
Posted
Put massive signs up saying "We can't recover your password on USB drives" though.

 

Not technically true, if you set Bitlocker to save recovery information to Active Directory, you can get the Bitlocker recovery password from AD, as long as you know which PC encrypted the drive. Although yes, a bit of tactical fibbing / managing expectation is far easier.

 

Pretty much all the settings you want for this are under Windows Components | BitLocker Drive Encryption | Removable Data Drives. Pretty sure you can achieve most combinations between fully open and fully encrypted here, but it is a case of trying settings until you get what you want.

 

The key setting for us was "Deny write access to removable drives not protected by BitLocker". This means users can only write to encrypted drives, but can read from unencrypted ones, eg, for when we have visiting trainers / speakers etc with presentations on USB sticks.

  • Thanks 1
Posted
Given the number of times fixed system drives failed to upload their key to AD, I'd be amazed if usb drives managed it that often

 

Oh really? Never had a problem here. But then, I've not necessarily been checking, or had to fall back on the AD backups. System drives would just get wiped, and memory sticks are the user's problem.

Posted
Given the number of times fixed system drives failed to upload their key to AD, I'd be amazed if usb drives managed it that often

 

In our experience it's pretty reliable, though we don't allow encryption to proceed until a laptop successfully uploads the key to AD.

 

However (unless you're exporting to CSV regularly), those USB drive recovery keys are stored in the computer object of the device that's used to encrypt them. If you delete that computer object, you've lost the recovery keys.

Posted
Not technically true, if you set Bitlocker to save recovery information to Active Directory, you can get the Bitlocker recovery password from AD, as long as you know which PC encrypted the drive. Although yes, a bit of tactical fibbing / managing expectation is far easier.

 

Pretty much all the settings you want for this are under Windows Components | BitLocker Drive Encryption | Removable Data Drives. Pretty sure you can achieve most combinations between fully open and fully encrypted here, but it is a case of trying settings until you get what you want.

 

The key setting for us was "Deny write access to removable drives not protected by BitLocker". This means users can only write to encrypted drives, but can read from unencrypted ones, eg, for when we have visiting trainers / speakers etc with presentations on USB sticks.

 

Thanks all for the replies. I may go with this setting.

 

- - - Updated - - -

 

http://www.edugeek.net/forums/windows-10/192536-rolling-out-bitlocker-mbam-needed-yes-no-tpm-owner-password.html#post1648918

 

Post is mostly about encrypting the system drive, but also has the policies for removables. Put massive signs up saying "We can't recover your password on USB drives" though.

 

Thanks for this

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...