Jump to content

Recommended Posts

Posted

If you are using something like group policy, you can choose to have the backup key request, or not.

 

The default is to always ask the user to backup the key, even if a pin number is going to be set.

 

My advice, have a play on a test system.

Posted

Always have the keys. I have found that if a machine dies due to lack of charge or having the power cord yanked out it often asks for the recovery key. Ours are setup to store in AD but , on the occasions the process asks to save the key to a file, I have a text file with them in.

 

image.png.3cfaec7335130a570ea389d21999fb18.png

 

Saving to AD was one of those "not sure I can get that done" tasks that turned out to be fairly straightforward.

Posted
15 minutes ago, LeMarchand said:

Always have the keys. I have found that if a machine dies due to lack of charge or having the power cord yanked out it often asks for the recovery key. Ours are setup to store in AD but , on the occasions the process asks to save the key to a file, I have a text file with them in.

 

image.png.3cfaec7335130a570ea389d21999fb18.png

 

Saving to AD was one of those "not sure I can get that done" tasks that turned out to be fairly straightforward.

I can remember being the same when I set ours up. It's actually super easy to get going with group policy

Posted (edited)
11 hours ago, 5nowman said:

backup key for each on a usb stick

 

And a backup of your backup...

 

Ours is set through Group Policy and the recovery passwords recorded in AD (we set the below, to ensure it checks this is recorded before it runs).

 

"Require BitLocker backup to AD DS - Enabled

If selected, cannot turn on BitLocker if backup fails (recommended default)"

 

I was in a similar position to you when I enabled it many years ago when we stopped using Truecrypt so I won't share as some of the settings are, how shall I put it... 'not exactly best practise' and I haven't had the time/inclination/guts to mess about with it (for example we didn't have compatible TPMs in all of our laptops at the time so I went for a password)... and although we have a complicated password system to the uninitiated it's not actually complicated, it's just very basic l33t, so when you get the hang of it, it's actually pretty easy to remember your p455w0rd (and not stick a label with it on to your laptop... yes Miss. Smith, I'm looking at you!)...

 

You might need to access the recovery passwords a fair bit in the beginning, if for some reason this is a new endeavour and your users have never had encrypted drives, be prepared for a few to lock themselves out on a regular basis. I have to unlock a new teacher's device at least two or three times before they get the hang of it.

 

I also teach them about the INS key to show what they've typed before they hit enter (even though it tells them underneath, you know what they're like)....

Edited by Koldov
Posted (edited)

Hi, I wanted to give my considerations for this as when I read it, I feel like there are other things that may not yet be implemented, but are of significant importance.

 

1. install bitlocker on laptops - if it gets stolen nobody can get data. is that right?

 

Configuring Bitlocker alone will not achieve this. 

Bitlocker will encrypt the drive - that's true.

But if you use the TPM to store the key, then whenever a user turns on the laptop, the TPM will unlock it and load the laptop to the Windows login screen. 

This is more convinient for the user, but you must make sure if you choose this route you password protect the BIOS and disable other boot options such as USB or PXE. Because if I got hold of a laptop which got to the login screen, I'd boot into a particular tool, enable the local admin account, whip the password off it and then reboot into Windows, log into the local admin account and then move laterally into your C:\users\ to find your files. 

[Source, I've done this before for folk]

 

With this method, Bitlocker will only prompt for the recovery key if some of the hardware is changed, or the drive is taken from the laptop and put in a caddy/another machine to try and read.

 

 

If you use a USB drive to unlock the laptop, then you should assume that the staff member will store that USB in the same laptop bag as the laptop. It's stupid, but they do it. If not 'they might loose it' - so there's some irony there.

 

If you set an encryption password, then set it to a small sentence of random words. Don't use the traditional aOa8w&"£! nonsense becuase they're only going to write it on a post-it note and keep it with the laptop. A pass 'phrase' such as 'Housing delicate stewards.' would work better, allow them to remember it easier. They'll probably complain it's very long at first, but the reality is, they spend their days typing sentences and once it's engrained, it'll be something they never forget. 

 

In terms of managing Bitlocker recovery codes, the best way would be on Active Directory. In theory, you should have that locked down and secure and have more than 1 DC in play with backups. So using GPO, you can configure it to store those codes. It's very easy to do and there will be a guide or Youtube video demonstrating it. If not, and you're doing it all manually for some reason, store them in some vault like Keepass, don't use Excel. (again, I've seen this happen)

 

They all log on with a local account on laptops

Am I to setup bitlocker to encrypt the whole drive?

will users be asked a secondary password during boot?

 

In my opinion, whilst Bitlocker is a good thing to do, the guys in this thread are right, you have some other priorities first. 

 

1. Remove admin rights to everyone that isn't you. If they need printers, remote support and install them. It takes 1 mistake to be completely ransomed. 

2. Set BIOS passwords on every machine.

3. Look at the boot orders and remove anything you don't need. 

4. Setup a test laptop and get that VPN working.

5. Make sure nobody is using a local account.

6. Similar to setting up Bitlocker, now look into LAPS.

7. Be happy in that you're now in a much better position.

 

 

Maybe you have these in place already, maybe not, but I'd rather mention it than not. 

 

Hope it helps.

 

Edited by Jayloax
Fixed my bad spelling
  • Like 1
Posted
10 hours ago, Jayloax said:

Configuring Bitlocker alone will not achieve this. 

Bitlocker will encrypt the drive - that's true.

But if you use the TPM to store the key, then whenever a user turns on the laptop, the TPM will unlock it and load the laptop to the Windows login screen. 

This is more convinient for the user, but you must make sure if you choose this route you password protect the BIOS and disable other boot options such as USB or PXE. Because if I got hold of a laptop which got to the login screen, I'd boot into a particular tool, enable the local admin account, whip the password off it and then reboot into Windows, log into the local admin account and then move laterally into your C:\users\ to find your files. 

[Source, I've done this before for folk]

 

With this method, Bitlocker will only prompt for the recovery key if some of the hardware is changed, or the drive is taken from the laptop and put in a caddy/another machine to try and read.

 

Not quite correct, it'll ask if any of the PCR registers it decided to check have been altered

 

How would you boot into a tool from the login screen of Windows though?

Posted
10 hours ago, mavhc said:

 

Not quite correct, it'll ask if any of the PCR registers it decided to check have been altered

 

How would you boot into a tool from the login screen of Windows though?

 

Hi,

what I said is correct, but perhaps could have been written more clearly. 

 

Yes, Bitlocker recovery is triggered when there is a change to the PCRs, such as changes to the boot order, or extracting the drive, or changing some hardware.

 

By following the steps I suggested, it mitigates the attack vectors for most of them. 

I think drilling into the PCRs would be too deep for this post as it looked to me like the poster was asking for a place to start. 

 

To answer your question about booting into the tool, you misunderstood.

I'm not saying you can boot from the login screen, but if you turn on a laptop and it gets to the Windows login screen, then from an attackers side, I can see that Bitlocker is decrypted. Knowing that, I can then reboot the system and boot into something like a USB running Hirens Boot CD, I could continue to activate and change the admin credentials, then reboot back into Windows and then login. 

 

There's that, or if you can boot into a Windows recovery environment, then you can do the classical 'ease of access' exploit.

 

I'm new to forums so don't know the rules, so I was trying to be a bit more non-comittal regarding the specifics of how to actually hack/bypass the accounts, but, again, if the boot order is done properly and USB booting is disabled until needed (which I know many IT techs out there leave as default), then these vectors are mitigated.

Posted
12 hours ago, Jayloax said:

 

Hi,

what I said is correct, but perhaps could have been written more clearly. 

 

Yes, Bitlocker recovery is triggered when there is a change to the PCRs, such as changes to the boot order, or extracting the drive, or changing some hardware.

 

By following the steps I suggested, it mitigates the attack vectors for most of them. 

I think drilling into the PCRs would be too deep for this post as it looked to me like the poster was asking for a place to start. 

 

To answer your question about booting into the tool, you misunderstood.

I'm not saying you can boot from the login screen, but if you turn on a laptop and it gets to the Windows login screen, then from an attackers side, I can see that Bitlocker is decrypted. Knowing that, I can then reboot the system and boot into something like a USB running Hirens Boot CD, I could continue to activate and change the admin credentials, then reboot back into Windows and then login. 

 

There's that, or if you can boot into a Windows recovery environment, then you can do the classical 'ease of access' exploit.

 

I'm new to forums so don't know the rules, so I was trying to be a bit more non-comittal regarding the specifics of how to actually hack/bypass the accounts, but, again, if the boot order is done properly and USB booting is disabled until needed (which I know many IT techs out there leave as default), then these vectors are mitigated.

Indeed, as @mavhc alluded to - I don't think the USB booted OS will be able to read the bitlockered volume, despite the presence of the TPM. Try it yourself.

  • Like 1
Posted
On 18/06/2025 at 07:50, andy_nic said:

i have bit locker on devices, which saves the bit locker recovery key to Active Directory, this is done via GPO and done just after the laptop is finished building with MDT and Intune Devices in to Azure. staff login with there normal domain accounts, everything is on OneDrive, but if there is a issue with bit locker normally after a windows update, we just give the the code over the phone or ask them to come in and its back to normal. i've recovered a device once or twice using PowerShell and CMD as the laptops  failed to boot/ got corrupted, the copied the profile off to a USB drive, but now days everything syncs apart from download and music, so we just reimage after speaking ton the member of staff. 

Same here, this has worked really well. I have only ever had issues with the head’s computer for some reason - would be the head’s. When DELL does some firmware updates, it seems to trick the system into thinking it has been tampered with and it requires the Bitlocker key to boot. I have permanently left the key with the head, it is kept in the safe so if I am not around, they can still get on.

 

Other than this, it has worked really well and means we don’t have to worry if staff take systems outside of the building. 

  • 1 month later...
Posted
On 25/06/2025 at 08:51, 3s-gtech said:

Indeed, as @mavhc alluded to - I don't think the USB booted OS will be able to read the bitlockered volume, despite the presence of the TPM. Try it yourself.

You guys are both right - I went and checked it out. I was mistaken.

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...