Solved

bitLocker GPO best practice settings

Posted on 2013-10-31
2
918 Views
Last Modified: 2013-10-31
Hi,

We've enabled machines to be able to store TPM information in AD, run the add-tpm script, and would now like to configure the BitLocker GPO according to some sort of best practice reference. Ideally, we would like to store a recovery password in AD. Any ideas where we can get hold of one?

Thanks!
0
Comment
Question by:rookie_b
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 26

Accepted Solution

by:
Tony Johncock earned 500 total points
ID: 39613773
Have you read the following best practices guides from MS?

http://technet.microsoft.com/en-us/library/dd875532(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/jj592683.aspx

As for storing the recovery password in AD - there are some step-by-step steps here:

http://technet.microsoft.com/en-us/library/dd875529(v=ws.10).aspx

They also provide the scripts you need to run to achieve what you're trying to do.
0
 

Author Closing Comment

by:rookie_b
ID: 39614684
Excellent!
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Here's a look at newsworthy articles and community happenings during the last month.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question