ADMaster Posted August 4, 2021 Posted August 4, 2021 I'm getting around to doing bitlocker this summer and come across some machines that have it turned on and I didn't deploy it. I've been working through the CIS baselines and put most of the bitlocker GPOs in place to prep. I waited a few days to make sure computers had the settings. I deployed it to 4 computers each of different models to verify before wider deployment. I setup a couple reports in PDQ to see what machines have a TPM and what machines have bitlocker. The report shows I have about 30 computers that are fully encrypted. Are my GPOs doing this? The difference between the two are this. The manual deployment with the powershell script has the following protectors. Trusted Platform Module (TPM), Numerical password The automatic deployment has this as the protectors. Numerical password, Trusted Platform Module (TPM) Same protectors different order. I called one of the users who show it as enabled and they said they did not set it up and they do not need a pin to start the computer. So it is working as I want, but it shouldn't be doing it on its own. Ideas? Thank you
Steve21 Posted August 4, 2021 Posted August 4, 2021 By default the GPOs shouldn't start any encryption off on their own (as least not that I've ever seen) What devices are they on? I know certain brands like Dell have auto bitlocker enabled, when certain criteria are met, like a MS account being used on them (even if for apps etc) There's a whole new section since 8.1 about automatic bitlocker based on specs/hardware etc - https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-device-encryption-overview-windows-10#bitlocker-device-encryption Steve 1
ADMaster Posted August 4, 2021 Author Posted August 4, 2021 If I'm reading that correctly... It enabled its self because I didn't set a reg key to prevent it AND I set the policy to backup the keys to AD. All the computers auto enabled so far have been my new Latitude 5510's The only OptiPlex to have it is the one I deployed it to and my older Lenovo's haven't taken well to it yet. I get an error that it cannot be automatically unlocked, so it will not be enabled. I checked a few of the 5510's their keys are stored in AD. The dells enabled with no user input. The Lenovo's wanted me to confirm changing TPM settings, and still failed. 1
LeMarchand Posted December 9, 2021 Posted December 9, 2021 Just came on here to find out why a load of Linx laptops were now Bitlockered. Shame it doesn't work with such efficiency on some of the machines I would like it to!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now