How to Deploy the MBAM Client to Desktop or Laptop Computers

This topic explains how to deploy the MBAM Client to end users’ computers. You can deploy the MBAM Client through an electronic software distribution system, such as Active Directory Domain Services or Microsoft System Center Configuration Manager.

To deploy the MBAM Client as part of a Windows deployment, see How to Enable BitLocker by Using MBAM as Part of a Windows Deployment.

Before you start the MBAM Client deployment, review the MBAM 2.5 Supported Configurations.

To deploy the MBAM Client to desktop or laptop computers

  1. Locate the MBAM Client installation files that are provided with the MBAM software.

  2. Use Active Directory Domain Services or an enterprise software deployment tool like Microsoft System Center Configuration Manager to deploy the Windows Installer package to target computers.

  3. Configure the distribution settings or Group Policy settings to run the MBAM Client installation file.

    After successful installation, the MBAM Client applies the Group Policy settings that are received from a domain controller to begin BitLocker Drive Encryption and management functions.

    The MBAM Client does not start BitLocker Drive Encryption actions if a remote desktop protocol connection is active. All remote console connections must be closed and a user must be logged on to a physical console session before BitLocker Drive Encryption begins.

**Got a suggestion for MBAM**? Add or vote on suggestions [here]( **Got a MBAM issue**? Use the [MBAM TechNet Forum](

Deploying the MBAM 2.5 Client

Planning for MBAM 2.5 Client Deployment