Ertech Posted November 29, 2019 Posted November 29, 2019 is there a Zero-Touch BitLocker Deployment for domain joined devices (no TPM)? Thanks
DavR Posted November 29, 2019 Posted November 29, 2019 Not that I've found, using vanilla deployment with group policy. Without a TPM, you need to either stick a pin code or password in there, I found no way to automate that.
Ertech Posted November 29, 2019 Author Posted November 29, 2019 Is there a way to automatically backup the key for devices without TPM?
DavR Posted November 29, 2019 Posted November 29, 2019 You can still back the recovery key for devices without TPM, just enable the backup to Active Directory options in group policy. You will still need to manually run through the BitLocker encryption wizard though.
sted Posted November 29, 2019 Posted November 29, 2019 everything that works with a tpm works without gpo wise so backing up keys is the same as if it had a tpm. to the best of my knowledge there is no gpo way of automatically actually encrypting the disk you could probably use a script to do it or (for pcs with tpm) make it part of your mdt setup
mavhc Posted November 29, 2019 Posted November 29, 2019 Zero touch to encrypt? decrypt? More details needed.
mavhc Posted December 2, 2019 Posted December 2, 2019 Yeah, just use a script, modify this one http://www.edugeek.net/forums/windows-10/192536-rolling-out-bitlocker-mbam-needed-yes-no-tpm-owner-password.html#post1648918 1
Ertech Posted December 2, 2019 Author Posted December 2, 2019 (edited) I was looking online and come across BitLocker changing the recovery key randomly - anyone experienced this issue? https://community.spiceworks.com/topic/2062878-why-does-bitlocker-change-the-recovery-key Thanks Edited December 2, 2019 by Ertech
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now