fiza Posted August 11, 2020 Posted August 11, 2020 (edited) When we had Windows 7 we had enabled BitLocker for portable drives and each time a user inserted a USB drive into the PC they would get a warning to say the USB needed to be encrypted if it wasnt. With Windows 10 that message no longer appears. I can insert a non-bitlockered USB and see the contents but when I try to write to it I get "disk is write-protected". There is no mention of Bitlocker. How can I get the messaging back please? edit: I should add that we do not allow users to encrypt the drives themselves. They have to bring them to IT Support for us to do it. Edited August 11, 2020 by fiza
Steve21 Posted August 11, 2020 Posted August 11, 2020 (edited) It should pop up by default when it's entered still, I take it you don't have separate GPOs for 7/10 and might have missed a setting? (or added too many to block bitlocker access) - Edit - Also, Do you have Bitlocker enabled for them to access on Control Panel? Or did you block it? Steve Edited August 11, 2020 by Steve21 1
fiza Posted August 11, 2020 Author Posted August 11, 2020 It should pop up by default when it's entered still, I take it you don't have separate GPOs for 7/10 and might have missed a setting? (or added too many to block bitlocker access) - Edit - Also, Do you have Bitlocker enabled for them to access on Control Panel? Or did you block it? Steve We do have separate GPOs but I have checked and the settings are exactly the same. The only difference is that when we had Windows 7 we had Professional which you couldn't use to encrypt anyway. Now we have Windows 10 Education where I believe users can encrypt if we allowed them to. Control Panel is blocked for users.
Steve21 Posted August 11, 2020 Posted August 11, 2020 That might be why if you're blocking it in Control Panel as it uses that wizard, as that popup is one that allows them to run said wizard to encrypt it Have you tried putting bitlocker back on CPanel as the only option? Also I take it you haven't disabled Control use of BitLocker on removable drives? Steve
fiza Posted August 11, 2020 Author Posted August 11, 2020 That might be why if you're blocking it in Control Panel as it uses that wizard, as that popup is one that allows them to run said wizard to encrypt it Have you tried putting bitlocker back on CPanel as the only option? Also I take it you haven't disabled Control use of BitLocker on removable drives? Steve We don't want them to be able to encrypt the drives themselves. We want them to see the warning as they could on Windows 7 then bring the USB to us to encrypt. Control use of Bitlocker on removable drives is enabled
Steve21 Posted August 11, 2020 Posted August 11, 2020 Honestly never seen it work that way even on 7, it's either you had the warning show which the warning says "click here to bitlocker etc", or you had it turned off and it'd block it You got any screenshot of it working on 7, maybe I'm misunderstanding which popup you mean? Steve
fiza Posted August 11, 2020 Author Posted August 11, 2020 Honestly never seen it work that way even on 7, it's either you had the warning show which the warning says "click here to bitlocker etc", or you had it turned off and it'd block it You got any screenshot of it working on 7, maybe I'm misunderstanding which popup you mean? Steve I think I have worked out why. ON Windows 7 Pro users didn't have the ability to encrypt so the popup did nothing. On Windows 10 if I enable "Allow users to apply Bitlocker protection on removable data drives" then Windows 10 users get the popup too but are then able to encrypt. Ideally I would want the popup but not the ability for users to encrypt. Looks like I can't have that.
Steve21 Posted August 11, 2020 Posted August 11, 2020 Ah fair enough, makes sense, guess we didn’t get it as didn’t use Pro on 7 Out of curiosity any reason you won’t let them do it themselves? With the ability to force how they do it, and auto backup keys to AD etc seems no reason not to let them, one less job for you Steve 1
fiza Posted August 11, 2020 Author Posted August 11, 2020 Ah fair enough, makes sense, guess we didn’t get it as didn’t use Pro on 7 Out of curiosity any reason you won’t let them do it themselves? With the ability to force how they do it, and auto backup keys to AD etc seems no reason not to let them, one less job for you Steve Yeh, may have to have a rethink on that now that we are Windows 10. With the backing up of keys to AD are there any gotchas?
Steve21 Posted August 11, 2020 Posted August 11, 2020 Not really (at least during last few years), as soon as they encrypt it’ll copy it up to AD as an attribute on the computers it’s done on, and with the bitlocker management tools you can pull any back as required, remember it’s only needed if they forget their original key But obviously test test test Steve
jthompson Posted August 11, 2020 Posted August 11, 2020 Make sure that people understand that BitLockered USBs are not necessarily going to be readable on non-school machines. It depends on what your users are wanting to use USB storage for, obviously, but when we restricted its use, we took it as an opportunity to phase out all of that "my life is on there" bad practice. 1
fiza Posted August 11, 2020 Author Posted August 11, 2020 we took it as an opportunity to phase out all of that "my life is on there" bad practice. That is what we are trying to do hence why we wanted it set to not allow them to encrypt so they had to bring it to us. Usually that would discourage the majority.
fiza Posted August 11, 2020 Author Posted August 11, 2020 Not really (at least during last few years), as soon as they encrypt it’ll copy it up to AD as an attribute on the computers it’s done on, and with the bitlocker management tools you can pull any back as required, remember it’s only needed if they forget their original key But obviously test test test Steve Are there any issues with re-imaging machines that have been used to encrypt?
Steve21 Posted August 11, 2020 Posted August 11, 2020 As long as you aren't deleting the machines from AD it'll keep the records in AD for the newly imaged machine. I did find a powershell script somewhere in the past that allowed a full export that I did once in a while in case we deleted something, but it'll still sit in recycle bin within AD etc as normal Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now