Jump to content

Recommended Posts

Posted (edited)

Really hope someone can help here or shed some light on how this happened

 

Had a parent come in & say that they let their child use their computer to sign into their Microsoft account & now when they turn the computer on, it asks for a bitlocker key!! This is their personal computer.

 

I asked for as many details as possible but the parent didn't seem to know much about it. They just said the student had "signed in" to access teams.

 

I have checked the students azure account and can see the connected device - No bitlocker key stored - perfect!!

 

Edit : Device is not azure ad joined, rather azure ad registered.

Edited by Olliedawg
Posted

This depends how your Azure AD is configured. I think if you don't change anything by default, users can register a device with your Azure, and chances are your default policy will enforce Bitlocker. If you've changed your default policies then it depends how you've done that.

 

When the student signed into office, there was probably a box like this:

 

allow-org-manage-575x563.png

 

Leaving the box ticked would likely have done the registration and enforced the bitlocker policy.

 

Try getting the student to go to https://myaccount.microsoft.com/device-list and see if it's in their account settings, rather than your Azure...

  • Thanks 1
Posted
This depends how your Azure AD is configured. I think if you don't change anything by default, users can register a device with your Azure, and chances are your default policy will enforce Bitlocker. If you've changed your default policies then it depends how you've done that.

 

When the student signed into office, there was probably a box like this:

 

[ATTACH=CONFIG]69414[/ATTACH]

 

Leaving the box ticked would likely have done the registration and enforced the bitlocker policy.

 

Try getting the student to go to https://myaccount.microsoft.com/device-list and see if it's in their account settings, rather than your Azure...

 

Brilliant... I will get them to check, although i'm not hopeful that the key will be there.. Need to look at disabling this as this could cause some serious headaches.

Posted

Had a dig around and no policies are set with regards to drive encryption - I assume by default this means devices can be / are automatically encrypted if they meet criteria? I can't disable registering completely as we use intune for mobile devices. (albeit we are on a basic azure licence). Going to have a play around with policies tomorrow to try and prevent this from happening again. So in theory, if a student uses a family members laptop for an evening for example, and adds their microsoft account via workplace join, this may encrypt the drive?!?

 

In my opinion, this would make a little more sense on a device which is Azure AD JOINED, or even Hybrid Azure Joined - not on a Azure AD Registered/Workplace device...

 

I spoke to the student & showed him the image, he can recall seeing that & most likely just whizzed through and pressed ok. I have asked the parent to check any other drives on the home PC / any external drives which may have been connected during the time the student signed in, with a possibility that the bitlocker key is stored on there (doubt it..). I'm not even sure if it prompts the user to save the encryption key file at all.

 

Luckily the parent has stated that the drive which has been encrypted held nothing of importance - although I now may have to assist the parent with reinstalling windows over the encrypted drive :(

Posted

I can understand why they do it by default - we live in an environment where data protection should be a higher priority, and the majority of 365 tenancies will be in other industries that operate a heavy BYOD infrastructure. Where you allow users to use their own devices and then access company data, you want to safeguard that by enforcing a level of security by default, so I get it. It doesn't help us in this case, however.

 

If you go to https://endpoint.microsoft.com/ and click on EndPoint Security on the left, then "Disk Encryption", do you have anything in there? I can't remember what the default license allows you to do.

Posted (edited)
I can understand why they do it by default - we live in an environment where data protection should be a higher priority, and the majority of 365 tenancies will be in other industries that operate a heavy BYOD infrastructure. Where you allow users to use their own devices and then access company data, you want to safeguard that by enforcing a level of security by default, so I get it. It doesn't help us in this case, however.

 

If you go to https://endpoint.microsoft.com/ and click on EndPoint Security on the left, then "Disk Encryption", do you have anything in there? I can't remember what the default license allows you to do.

 

I have had a look there & do not have any policies set. It does allow me to create a policy though. I know I don't have conditional access, so would have to just blanket apply the policy to all users.

 

Edit: If i go to devices > monitor > encryption report - this shows no data which is strange. I have no devices showing within intune apart from staff mobile phones. Although I can see the azure registered devices within azure AD

Edited by Olliedawg
  • 3 weeks later...
Posted

Great reminder for me to turn this off before we go to BYOD next year! These are the settings you're going to want to have a look at on Entra (Azure Active Directory :/) under Devices > Device settings

prev.PNG

If you're using Intune there's no way to stop users from 'registering' their devices to your AAD. Still, you can stop them from actually joining which should prevent them from being affected by policies like Bitlocker.

We had a similar issue last year (but a one-off so it sorta got brushed away), where a student had joined their device to our AAD and then once we deleted their account because they had left it had almost totally bricked the laptop. Such a pain!

Posted
Great reminder for me to turn this off before we go to BYOD next year! These are the settings you're going to want to have a look at on Entra (Azure Active Directory :/) under Devices > Device settings

[ATTACH=CONFIG]69567[/ATTACH]

If you're using Intune there's no way to stop users from 'registering' their devices to your AAD. Still, you can stop them from actually joining which should prevent them from being affected by policies like Bitlocker.

We had a similar issue last year (but a one-off so it sorta got brushed away), where a student had joined their device to our AAD and then once we deleted their account because they had left it had almost totally bricked the laptop. Such a pain!

 

I've now set AD join to "selected" & are only allowing staff.

 

Yes that is similar to what happened to a student here, unfortunately could not recover the bitlocker key - had to assist parent with re-installing windows!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...