Jump to content

Recommended Posts

Posted

I'm getting around to doing bitlocker this summer and come across some machines that have it turned on and I didn't deploy it.

 

I've been working through the CIS baselines and put most of the bitlocker GPOs in place to prep. I waited a few days to make sure computers had the settings.

 

I deployed it to 4 computers each of different models to verify before wider deployment.

 

I setup a couple reports in PDQ to see what machines have a TPM and what machines have bitlocker.

 

The report shows I have about 30 computers that are fully encrypted. Are my GPOs doing this?

 

The difference between the two are this.

The manual deployment with the powershell script has the following protectors.

Trusted Platform Module (TPM), Numerical password

 

The automatic deployment has this as the protectors.

Numerical password, Trusted Platform Module (TPM)

 

Same protectors different order.

 

I called one of the users who show it as enabled and they said they did not set it up and they do not need a pin to start the computer. So it is working as I want, but it shouldn't be doing it on its own.

 

Ideas?

 

Thank you

Posted

By default the GPOs shouldn't start any encryption off on their own (as least not that I've ever seen)

 

What devices are they on? I know certain brands like Dell have auto bitlocker enabled, when certain criteria are met, like a MS account being used on them (even if for apps etc)

 

There's a whole new section since 8.1 about automatic bitlocker based on specs/hardware etc - https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-device-encryption-overview-windows-10#bitlocker-device-encryption

 

Steve

  • Thanks 1
Posted

If I'm reading that correctly...

It enabled its self because I didn't set a reg key to prevent it AND I set the policy to backup the keys to AD.

 

All the computers auto enabled so far have been my new Latitude 5510's

The only OptiPlex to have it is the one I deployed it to and my older Lenovo's haven't taken well to it yet. I get an error that it cannot be automatically unlocked, so it will not be enabled.

 

I checked a few of the 5510's their keys are stored in AD.

 

The dells enabled with no user input. The Lenovo's wanted me to confirm changing TPM settings, and still failed.

  • Thanks 1
  • 4 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...