-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Chrome not applying system proxy settings until IE is launched
CHiLL replied to CHiLL's topic in Windows 10
We made this change this morning and it appears to have sorted the issue. Glad it isn't just me that's seeing this issue (even if I am a bit late to the party). -
We have noticed a proxy issue with our Windows 10 1709 clients when using Google Chrome (tested on both v61 and v66). Chrome's proxy settings are managed by a GPO to use the system proxy settings. When a student logs into a desktop and launch Chrome, they can access normally blocked (by Smoothwall) content such as games, Youtube and other stuff. Whilst remaining logged on, the student launches IE11, Chrome will then pick up the system proxy settings and apply the filtering as normal. Browsing to chrome://net-internals/#proxy on the machine before IE is launched shows: Effective proxy settings Use DIRECT connections. Source: SYSTEM Browsing to chrome://net-internals/#proxy on the machine after IE is launched shows: Effective proxy settings Proxy server: smoothwall.sjw.internal:8080 Bypass list: https://fed.sjw.bham.sch.uk 10.22.103* 10.* http://*.sjw.internal https://*.sjw.internal Source: SYSTEM Internet Explorer's proxy settings are also configured in a GPO, and they are manually specified in User Configuration > Preferences > Control Panel Settings > Internet Settings > Internet Explorer 10 (Students). I am completely baffled as to why Chrome won't pick up the proxy settings unless IE is launched. It should pick them up as per the GPO and use the system settings. Anyone have any ideas?
-
ZoneDirector & Smoothwall Filtering
CHiLL replied to CHiLL's topic in Internet Related/Filtering/Firewall
We have a RADIUS server for our school owned devices, however these devices are not school owned. They are the personal smartphones of the students. If not Captive Portal, then how to we audit the access students have on their phones? The idea is that students use their own phones periodically for revision, but we want to be able to pinpoint a student if they access something inappropriate. Obviously being their own personal phones, we have no control of their management. -
Thank you very much, I've managed to make those changes.
-
Thanks for the reply. DHCP is an easy change. The 5406zl does do our routing. What command would I need to run to achieve this?
-
Hello, We have multiple VLANs in place and we need to change the default gateway for one of these VLANs. Is it as simple as changing the 'Router' entry within DHCP? Or will I need to make some config changes on our switches? If so, would it just need doing on our core switch, a HP ProCurve 5406ZL? Or would we have to do it on all edge switches too?
-
I have been experiencing this over the past couple of days. We have some old laptops that we need to get running and I'm installing Windows 10 1607 on them (1703 and 1709 won't work due to hardware/driver limitations). So I deployed 1607 via SCCM and MDT and it installs fine. It logs me into the local account and then BAM, there's the upgrade assistant starting to download updates. There is no option to stop or postpone/delay the process, it just does. We manage Windows Updates with SCCM's SUP and have the relevant GPOs configured. I did a little bit of Googling on this and it appears that the important policy to have enabled is: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update: Do not connect to any Windows Update Internet locations > Enabled. Now, here's my problem. When we deploy Windows, one of the steps joins it to the domain and plops the machine in a resting OU called 'Deployment'. This OU doesn't have any GPOs applied to it as the idea is that the machines are then manually moved to the correct location. My idea is to find the registry setting that the above GPO changess and put that in the TS. What a ballache. Edit: I think the registry entry is: Location: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate Name: DoNotConnectToWindowsUpdateInternetLocations Type: DWORD Value: 1 I will add that into my TS and see how it goes. Edit 2: With this step added, Windows did not start upgrading to a newer version. All good!
-
We sucessfully tested BitLocker and are happy with how it works, so will be implementing it soon for all our users. One scenario that we tested was what happens when BitLocker is enforced on removable media - and then a hardware encrypted USB drives was inserted. We noticed that as per usual, the device required the password to unlock. Once it did unlock and present its partition to Windows...we encountered the BitLocker prompt to encrypt that. So that would mean encrypting the encryption and the user entering two passwords. Is there any way around this, or is that just how it is? Ideally I'd like BitLocker to ignore devices that already have encryption enabled, but I don't think it can.
-
Hmm, I'm pretty sure w had to turn off Secure Boot to allow Legacy/CSM booting. Either USB booting or SCCM deployment (I have a feeling it was for PXE boot). Maybe I'll have to disable it for imaging and then re-enable it before BitLocker encryption.
-
That sounds good, though how does it work if someone manages to boot the laptop using a USB Linux distro or something?
-
I'm currently testing BitLocker encryption on removable media and so far so good. However, there's one niggle that's annoying me. If a member of staff inserts their encrypted drive and enters the password - the drive unlocks and it can be used. If that member of staff then locks their PC with the USB drive still inserted and unlocked...and then another member of staff uses that machine...the USB drive is visible and unlocked for them too. Now, I know this is no different than having an unencrypted drive connected, but I just thought I'd check. I can forsee that being something that they'd complain about. Is there a way of getting the drive to lock if the user locks their machine or the user is switched?
-
I would assume so. I've just checked our licensing and it looks the same.
-
We have Software Assurance via OVS-ES but I too am unsure whether it applied to SCCM. We have our Software Assurance set to expire on the same date as our OVS-ES agreement. According to this page, a valid SCCM or equivilant Software Assurance license will allow you to use the CB for SCCM. I am currently running SCCM 1706, which is the latest CB.
-
At present, we use RM SafetyNet inline filtering (with transparent proxy enabled) and are in the process of migrating to Smoothwall. We have a Ruckus ZD1200 managing our WLANs, which includes a WLAN for BYOD with Captive Portal enabled. Smoothwall have configured a non-inline VM implementation of their filtering, which was recommended by their proposal as being the best option. However, once our users have authenticated onto BYOD, they do not have to put any proxy details on their devices, as transparent proxy works and forces them through RM's filtering. We'd prefer this sort of approach for Smoothwall filtering too, but as it isn't in-line, the traffic will not automatically go there. We could use PAC/WPAD, but from my understanding, Android doesn't play well with this sort of approach. I also cannot find anywhere to force a specific WLAN (or anywhere in Zone Director at all) to go through a specific proxy. Anyone have any ideas?
-
What specifically in BIOS needs to be enabled if it's TPM 1.2? by UFD do you mean a removable drive? I mentioned that because I couldn't launch 'Manage BitLocker' and there was no option on the context menu of the OS disk to 'Turn on BitLocker'. This was making me think that my settings weren't applying correctly. However, I used the same policy to configure BitLocker removable drives too. Since plugging in a USB drive brought up the option to encrypt it with BitLocker...that suggested that the policy was in some way working, but there was an issue with the OS disk configuration. I hope that makes sense.
-
This! My colleague had a quick look with his fresh eyes and found an article regarding 'Shell Hardware Detection'. Lone behold, ours was set to Disabled and thus wasn't running. As soon as we enabled this, we could launch 'Manage BitLocker' and 'Turn on BitLocker' appears in the context menu of the OS drive. I'm not sure I'd have got to that at the rate I was going! Now to carry on with my testing! Thanks for the advice so far, though I may update this thread if (when) I run into more problems!
-
Only AppLocker settings are: Application Control Policieshide Appx Ruleshide No rules of type 'Appx Rules' are defined. Dll Ruleshide No rules of type 'Dll Rules' are defined. Executable Ruleshide Action User Name Rule Type Exceptions Allow Everyone (Default Rule) All files located in the Program Files folder Path No Allow Everyone (Default Rule) All files located in the Windows folder Path No Allow BUILTIN\Administrators (Default Rule) All files Path No Windows Installer Ruleshide No rules of type 'Windows Installer Rules' are defined. Script Ruleshide No rules of type 'Script Rules' are defined. When right clicking 'AppLocker' and selecting 'Properties', all the check boxes are not checked.
-
Maybe it's not an image problem. I've just check another 1709 computer and it also cannot open Manage BitLocker and the options are missing from File Explorer. This was definately imaged using the same image/TS/OSD as my own workstation. The only difference is that it was in an OU that has the computer restrictions. I have moved the computer to the same OU as my own machine and it still isn't working, despite gpupdates and reboots. So there appears to be something killing BitLocker and it won't come back. I'm going to create a new TS (not one to reimage, but steps to enable BitLocker again) and see if that works. That's a good point. I'll look into that.
-
Yes it does. I forgot to add the OS in my OP. It's Windows 10 Education 1709 x64. I have made an amendment to my previous post, which points to an issue with the install of Windows 10 1607, which was then upgraded to 1709.
-
Think I'll have to do that. I've moved the test laptop to the 'Computers' OU, so no policies are being applied, yet Manage BitLocker still doesn't work and there is still no option to 'Turn on BitLocker' when right clicking the OS drive in File Explorer. So I'm guessing that BitLocker hasn't been enabled correctly during the OSD, or there's an issue with the image. This machine was running Windows 10 Education 1607 x64 and has had an in-place OS upgrade to Windows 10 Education 1709 x64. The WIM used for the upgrade is the same WIM that was used on my own workstation, which can launch BitLocker. However, it was an upgrade that was performed, not a fresh install. I may look at re-imaging the laptop. Edit: I have just logged on another machine that is runnign Windows 10 Education 1607 x64 - it also cannot launch BitLocker. Looks like I'll be doing a fresh install.
-
Hmm, OK. The idea was to allow BitLocker to encrypt devices without TPM chips or TPM chips lower than 1.2...but for devices with a TPM 1.2 chip or higher...require a password on boot.
-
The option is also missing for the local admin. I've done RSOP, but not sure what I'm looking for. The configured BitLocker policies are as follows: Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption Policy Setting Winning GPO Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) Enabled TESTING - C - BitLocker Select the encryption method for operating system drives: XTS-AES 256-bit Select the encryption method for fixed data drives: XTS-AES 256-bit Select the encryption method for removable data drives: XTS-AES 256-bit Policy Setting Winning GPO Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) Enabled TESTING - C - BitLocker Select the encryption method: AES 256-bit Policy Setting Winning GPO Disable new DMA devices when this computer is locked Enabled TESTING - C - BitLocker Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) Enabled TESTING - C - BitLocker Require BitLocker backup to AD DS Enabled If selected, cannot turn on BitLocker if backup fails (recommended default). If not selected, can turn on BitLocker even if backup fails. Backup is not automatically retried. Select BitLocker recovery information to store: Recovery passwords and key packages A recovery password is a 48-digit number that unlocks access to a BitLocker-protected drive. A key package contains a drive's BitLocker encryption key secured by one or more recovery passwords Key packages may help perform specialized recovery when the disk is damaged or corrupted. Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Fixed Data Drives Policy Setting Winning GPO Allow access to BitLocker-protected fixed data drives from earlier versions of Windows Enabled TESTING - C - BitLocker Do not install BitLocker To Go Reader on FAT formatted fixed drives Disabled Policy Setting Winning GPO Choose how BitLocker-protected fixed drives can be recovered Enabled TESTING - C - BitLocker Allow data recovery agent Enabled Configure user storage of BitLocker recovery information: Allow 48-digit recovery password Allow 256-bit recovery key Omit recovery options from the BitLocker setup wizard Disabled Save BitLocker recovery information to AD DS for fixed data drives Enabled Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives Enabled Policy Setting Winning GPO Configure use of hardware-based encryption for fixed data drives Enabled TESTING - C - BitLocker Use BitLocker software-based encryption when hardware encryption is not available Enabled Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 Policy Setting Winning GPO Configure use of passwords for fixed data drives Enabled TESTING - C - BitLocker Require password for fixed data drive Disabled Configure password complexity for fixed data drives: Require password complexity Minimum password length for fixed data drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Policy Setting Winning GPO Deny write access to fixed drives not protected by BitLocker Enabled TESTING - C - BitLocker Enforce drive encryption type on fixed data drives Enabled TESTING - C - BitLocker Select the encryption type: Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Operating System Drives Policy Setting Winning GPO Allow enhanced PINs for startup Enabled TESTING - C - BitLocker Configure minimum PIN length for startup Enabled TESTING - C - BitLocker Minimum characters: 8 Policy Setting Winning GPO Configure use of passwords for operating system drives Enabled TESTING - C - BitLocker Configure password complexity for operating system drives: Require password complexity Minimum password length for operating system drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Require ASCII-only passwords for removable OS drives Disabled Policy Setting Winning GPO Enforce drive encryption type on operating system drives Enabled TESTING - C - BitLocker Select the encryption type: Policy Setting Winning GPO Require additional authentication at startup Enabled TESTING - C - BitLocker Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive) Enabled Settings for computers with a TPM: Configure TPM startup: Allow TPM Configure TPM startup PIN: Require startup PIN with TPM Configure TPM startup key: Allow startup key with TPM Configure TPM startup key and PIN: Allow startup key and PIN with TPM Computer Configuration > Policies > Administrative Templates > System > Windows Components > BitLocker Drive Encryption > Removable Data Drives Policy Setting Winning GPO Allow access to BitLocker-protected removable data drives from earlier versions of Windows Enabled TESTING - C - BitLocker Do not install BitLocker To Go Reader on FAT formatted removable drives Disabled Policy Setting Winning GPO Choose how BitLocker-protected removable drives can be recovered Enabled TESTING - C - BitLocker Allow data recovery agent Enabled Configure user storage of BitLocker recovery information: Allow 48-digit recovery password Allow 256-bit recovery key Omit recovery options from the BitLocker setup wizard Disabled Save BitLocker recovery information to AD DS for removable data drives Enabled Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages Do not enable BitLocker until recovery information is stored to AD DS for removable data drives Enabled Policy Setting Winning GPO Configure use of hardware-based encryption for removable data drives Enabled TESTING - C - BitLocker Use BitLocker software-based encryption when hardware encryption is not available Enabled Restrict encryption algorithms and cipher suites allowed for hardware-based encryption Enabled Restrict crypto algorithms or cipher suites to the following: 2.16.840.1.101.3.4.1.42 Policy Setting Winning GPO Configure use of passwords for removable data drives Enabled TESTING - C - BitLocker Require password for removable data drive Enabled Configure password complexity for removable data drives: Require password complexity Minimum password length for removable data drive: 8 Note: You must enable the "Password must meet complexity requirements" policy setting for the password complexity setting to take effect. Policy Setting Winning GPO Control use of BitLocker on removable drives Enabled TESTING - C - BitLocker Allow users to apply BitLocker protection on removable data drives Enabled Allow users to suspend and decrypt BitLocker protection on removable data drives Enabled Policy Setting Winning GPO Deny write access to removable drives not protected by BitLocker Enabled TESTING - C - BitLocker Do not allow write access to devices configured in another organization Disabled Policy Setting Winning GPO Enforce drive encryption type on removable data drives Enabled TESTING - C - BitLocker Select the encryption type: Used Space Only encryption What I've actually noticed in that is the 'Select the encryption type: ' field for both OS and fixed data drives appears blank in RSOP. Whereas the policy states that they should both be set to 'Full encryption'. I had done multiple gpupdate /force and reboots before gathering the RSOP data.
-
TPM is enabled and set to 'Clear TPM Owner' (This is a Toshiba Satellite Pro R50-B).
-
Cheers for the reply. I actually don't have an option to encrypt when I right click the drive, which doesn't bode well.
-
In light of GDPR, we have started looking at BitLocker for our devices that are taken off-site and doing some testing to see how it works. So far I've done the following configuration on our domain and prerequisites: GPO Created defining that all OS and fixed data drives are fully encrypted, and removable drives are used-space only encrypted. I've also specified to use AD DS backup for BitLocker, as well as defining the type of encryption to use, complexity, etc. Incorporated MBAM into SCCM Configured the OU to delegate control for the 'SELF' user (multiple sources recommended this) Added ACE for the TPM to AD DS (as recommended in a MS article) Devices imaged using SCCM have the following step in the TS during the 'Format Disk' stage section: 'Pre-provision BitLocker' and then followed later in the 'Post Install' section with 'Enable BitLocker' I have a test laptop in a test OU with the above GPO linked. When I insert a USB drive into the laptop, BitLocker automatically prompts to encrypt the drive and use it, or not encrypt it and only use it as read-only. This shows that the GPO is working. However, when I run the following command on the laptop to check BitLocker status: manage-bde -status c: It states: [OS Volume] Size: 464.80GB BitLocker Version: None Conversion Status: Fully Decrypted Percentage Encrypted: 0.0% Encryption Method: None Protection Status: Protection Off Lock Status: Unlocked Identification Field: None Key Protectors: None Found I don't understand why BitLocker Version is reporting 'None', yet BitLocker prompts when a USB drive is inserted. Also, I cannot start 'Manage BitLocker'. When I search the Start Menu for it, it shows in the results as a Control Panel item, but pressing it does nothing. I also cannot find it manually in Control Panel. Once I've sorted that out, how can I automatically start the encryption of the laptop? Rather than having to manually start it. Any ideas?
