Jump to content

Recommended Posts

Posted

basically this used to work out the box using a GPO would encrypt the drive after joining the domain... works fine with our previous win 11 image which was probably 21H2 as we quickly went back to Win 10. Win10 it also works absolutely fine.

Now it doesn't if you then try and manually turn it on ie right click c drive and turn on BitLocker it says

The path specified in the Boot Configuration Data (BCD) for a BitLocker Drive Encryption

integrity-protected application is incorrect

There is a thread here that I have added too https://forums.fogproject.org/topic/17704/unable-to-encrypt-drives-with-bitlocker-after-deploying-image-with-fog/6

We have tried the BCDedit suggestions in the post and also tried this which I found elsewhere on the internet as possible fixes

Tried separately and together these changes which are suggestions I came across on the net.

group policy editor -> computer config -> admin templates -> windows components -> bitlocker drive encryption -> os drives -> config TPM for UEFI.

PCR 0,2,11 Ticked (i.e. remove 4)

AND OR

group policy editor -> computer config -> admin templates -> windows components -> bitlocker drive encryption -> os drives -> Allow Secure Boot for integrity validation

Disable

 

Does anyone that uses fog tried to deploy 24H2 and noticed BitLocker failing for them? I am sure it relates to the fact that using fog means we disable secure boot ☹

Posted

Also a FOG user here, not quite got to where you are yet but building my 24H2 image at some point in the new year (still mostly on W10 at this point, a couple out there on 23H2 W11.)

 

Not entirely sure I'll go with Bitlocker or third-party disk encryption yet. Could you explore other encryption options there potentially?

 

It does look as though it is a sticking point for sure from what I'm reading.

Posted
Yesterday & Today I created and deployed a win11 23H2 image which will let you bitlocker the boot drive. I have since now forced windows update to install Win11 24H2 and the drive remains encrypted. so this for a while will be a workaround for our staff laptops that need to be encrypted.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...