localzuk Posted June 1, 2012 Posted June 1, 2012 So we're rolling out Windows 7 this year, and we also wish to look at Bitlocker for staff laptops. My question is - what happens with imaging? We use Fog to image machines at the moment, and obviously if a drive is encrypted it isn't going to be possible to grab a resizeable image of the drive - it'll be a RAW image of every sector. Can someone clarify the Bitlocker methodology for me?
Blue_Cookeh Posted June 1, 2012 Posted June 1, 2012 I'd also like to know this... right now I just build staff laptops with our unencrypted image then encrypt them manually...
plexer Posted June 1, 2012 Posted June 1, 2012 Can you not capture unecrypted and the nset bitlocker with gpo? If you capture the encrypted image from a laptop with a tpm that's been setup I don't think it's going to unecrypt on another laptop. Ben
plexer Posted June 1, 2012 Posted June 1, 2012 If the encrypted machine is started with a usb key rather than a tpm then it may start on a clone with the same key. Ben
SYNACK Posted June 1, 2012 Posted June 1, 2012 (edited) Yea, I think the MDT way of doing bitlocker is dropping the image on then triggering a drive encrypt. You just have to make sure that the TPM is enabled and can be initialised. There is a handy blog here: SCCM, Windows 7 and Bitlocker - Part 1 - Blogs - EduGeek.net which outlines how to set it up with SCCM which will have stuff that applies. I would look into using FOG and setting up the BIOS with the required settings as above then setting it to be encrypted through GPO as it will store the recovery keys and stuff in AD automagicly. It does take some time to encrypt but will suspend and continue in the background through shutdowns and restarts. Probably much quicker with a smaller SSD. You could also schedule a task at the end to trigger an encrypt Enabling BitLocker by Using the Command Line MDT or SCCM will also let you do this but if your all setup with FoG the change would not be efficient or worth it. Edited June 1, 2012 by SYNACK
localzuk Posted June 1, 2012 Author Posted June 1, 2012 Ah cool, having it do it on first boot via GPO seems like a good plan. All our new staff laptops will have SSDs, so it shouldn't be a big issue. Just checked and all our laptops old and new have TPM chips, so it makes it easier from that perspective too.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now