Solved

Bitlocker on Administrative Shares

Posted on 2013-01-23
5
962 Views
Last Modified: 2013-02-18
I have a win8 workstation that is not domain enabled. The only hard disk on it is bitlocker enabled with TPM. Is it correct that any other machines will not be able to access the Administrative Shares of this workstation?

Not even the Domain Administrator on which this workstation is connected to?
0
Comment
Question by:frukeus
  • 2
5 Comments
 
LVL 54

Expert Comment

by:McKnife
ID: 38809963
Hi.

The encryption Bitlocker does not protect the drive when the key is entered and the drive is mounted, so the answer is "no".
0
 
LVL 1

Author Comment

by:frukeus
ID: 38812861
But this is not an external drive....it is the system drive.

I can understand that when an external drive is connected and key entered, the entire drive is visible to the connected machine. But Bitlocker should protect a system drive from remote access via admin shares since the remote system has no way of entering a key, rite?
0
 
LVL 54

Accepted Solution

by:
McKnife earned 500 total points
ID: 38816682
No, not correct, sorry. Bitlocker does not do anything to protect from against unwanted network access.
Whenever your system starts, c: is mounted after you enter the PIN (if you use a PIN together with your TPM... you should). After it's mounted and windows has booted, the server service shares the shared folders. If we let alone default settings in win7, c: would not be shared, there would be no c$. Only after setting the registry key LocalAccountTokenFilterPolicy (see http://helgeklein.com/blog/2011/08/access-denied-trying-to-connect-to-administrative-shares-on-windows-7/ ), it would be shared and accessible.
No Bitlocker involved.
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 38903973
I've requested that this question be closed as follows:

Accepted answer: 500 points for McKnife's comment #a38816682

for the following reason:

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADFS for O365 login page 2 48
WMIC Command LIne 5 26
parental control on huwei HG658b 1 18
New User Account Creation Issue 4 20
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question