CHiLL Posted July 22, 2020 Posted July 22, 2020 We've been using MBAM for a while now and I'm in the process of migrating MBAM from a standalone server into SCCM. For reasons I can no longer remember, we have separate OUs for laptops that have TPMs and ones that don't. This is specifically for a GPO that is applied to it for MBAM, specifically for the setting "Operating system drive encryption settings". TPM laptops: Allow BitLocker without a compatible TPM (requires a password): Disabled Select protector for operating system drive: TPM only Configure minimum PIN length for startup: 8 Non-TPM laptops: Allow BitLocker without a compatible TPM (requires a password): Enabled Select protector for operating system drive: TPM and PIN Configure minimum PIN length for startup: 8 When I originally implemented MBAM, I think we only had one GPO for OS drives to deal with both TPM and non-TPM laptops. However I think we had issues where the TPM laptops were also asking for passwords, despite they wouldn't need one due to using the TPM chip. Without the password setting applied, non-TPM laptops wouldn't encrypt. Now that I'm migrating to SCCM, I'd rather only have one OS policy applied and it can deal with both TPM and non-TPM laptops. Is there a way to do this? Or have I had this wrong the whole time? Or do I have to continue with having two separate policies?
CHiLL Posted July 23, 2020 Author Posted July 23, 2020 Ah. I was hoping that it was just a configuration issue. Rather than using WMI filters, I think I'll just stick to having two separate policies.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now