Jump to content

Recommended Posts

Posted

We've been using MBAM for a while now and I'm in the process of migrating MBAM from a standalone server into SCCM. For reasons I can no longer remember, we have separate OUs for laptops that have TPMs and ones that don't. This is specifically for a GPO that is applied to it for MBAM, specifically for the setting "Operating system drive encryption settings".

 

TPM laptops:

Allow BitLocker without a compatible TPM (requires a password): Disabled

Select protector for operating system drive: TPM only

Configure minimum PIN length for startup: 8

 

Non-TPM laptops:

Allow BitLocker without a compatible TPM (requires a password): Enabled

Select protector for operating system drive: TPM and PIN

Configure minimum PIN length for startup: 8

 

When I originally implemented MBAM, I think we only had one GPO for OS drives to deal with both TPM and non-TPM laptops. However I think we had issues where the TPM laptops were also asking for passwords, despite they wouldn't need one due to using the TPM chip. Without the password setting applied, non-TPM laptops wouldn't encrypt.

 

Now that I'm migrating to SCCM, I'd rather only have one OS policy applied and it can deal with both TPM and non-TPM laptops. Is there a way to do this? Or have I had this wrong the whole time? Or do I have to continue with having two separate policies?

Posted
Ah. I was hoping that it was just a configuration issue. Rather than using WMI filters, I think I'll just stick to having two separate policies.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...