Jump to content

Recommended Posts

Posted
I've recently enabled BitLocker on some of our staff laptops. I thought this could only be enabled on machines that have TPM? I attempted enabling it on non-TPM laptops, and didn't get anywhere with it.

 

What I found during going through the BitLocker setup wizard is that it creates the necessary partioning and information required. We're not currently implementing storing the recovery information in AD, so I simply stored the recovery key to a file on a protected network share.

 

I'd be interested to know if you get anywhere enabling without the need for TPM :)

 

You need to deploy a GPO and set the option to enable without TPM on the particular machine/s. You have to use a new method though which requires that a USB Key be inserted at startup and if that key is lost then you need to have it backed up else the entire drive is unusable.

Posted
Thanks guys. I think having to use a USB key to get their laptop booted is going to cause more issues for us than it's worth! Had a teacher the other day that didn't know what a USB key was lol. I didn't think it was possible not to, but there you go.
Posted
You might want to go and take a look on my blog. Ive just finished a three poster on how we deploy Windows 7 with Bitlocker on all our staff laptops. Works a dream. We use SCCM to manage the process - but in case you dont have it (and you should get it by the way!!), you can do all the same stuff with MDT as well. I will be posting an app up too shortly for changing pin codes, which needs you to be an Admin user normally.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...