question

RoccoDipaolo-7790 avatar image
0 Votes"
RoccoDipaolo-7790 asked JennyFeng-MSFT commented

How to initiate Bitlocker from AD

Could someone explain to me what GPO I would have to setup for my Bitlocker Policy that would allow me to start encrypting on any given machine from AD when I want it to encrypt. I would rather do this so that machines dont start automatically encrypting once I add them to the Bitlocker Policy that I already have setup in AD. Any feedback would help

windows-10-security
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@RoccoDipaolo-7790
Hi,

Just checking in to see if the information provided was helpful.

If the reply helped you, please remember to accept as answer.
If no, please reply and tell us the current situation in order to provide further help.

0 Votes 0 ·
JennyFeng-MSFT avatar image
0 Votes"
JennyFeng-MSFT answered

@RoccoDipaolo-7790
Hi,
Based on my research, if you don't have something like SCCM\Intune\MBAM also set to encrypt the devices, Group Policy alone isn't able to BitLocker a machine.
Of the available GPO settings, the one that is arguably the most important to configure is Store BitLocker Recovery Information in Active Directory Domain Services.
If the machines start encrypting automatically, that are "Connected Standby" devices will automatically enable BitLocker during setup or OOBE (even if automated), so depending on the machines in question this could be expected behavior.

Hope above information can help you.

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MTG-3890 avatar image
0 Votes"
MTG-3890 answered

If you have MBAM, use it. Else, use task scheduler and batch. See my article: https://www.experts-exchange.com/articles/33771/We-have-bitlocker-so-we-need-MBAM-too.html?preview=hG26jVC1xow%3D

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.