Killer_Bot Posted February 10, 2011 Posted February 10, 2011 I've recently enabled BitLocker on some of our staff laptops. I thought this could only be enabled on machines that have TPM? I attempted enabling it on non-TPM laptops, and didn't get anywhere with it. What I found during going through the BitLocker setup wizard is that it creates the necessary partioning and information required. We're not currently implementing storing the recovery information in AD, so I simply stored the recovery key to a file on a protected network share. I'd be interested to know if you get anywhere enabling without the need for TPM You need to deploy a GPO and set the option to enable without TPM on the particular machine/s. You have to use a new method though which requires that a USB Key be inserted at startup and if that key is lost then you need to have it backed up else the entire drive is unusable.
DannyG555 Posted February 10, 2011 Posted February 10, 2011 Thanks guys. I think having to use a USB key to get their laptop booted is going to cause more issues for us than it's worth! Had a teacher the other day that didn't know what a USB key was lol. I didn't think it was possible not to, but there you go.
TheScarfedOne Posted February 10, 2011 Posted February 10, 2011 You might want to go and take a look on my blog. Ive just finished a three poster on how we deploy Windows 7 with Bitlocker on all our staff laptops. Works a dream. We use SCCM to manage the process - but in case you dont have it (and you should get it by the way!!), you can do all the same stuff with MDT as well. I will be posting an app up too shortly for changing pin codes, which needs you to be an Admin user normally. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now