Want to learn about MBAM integrated with Microsoft Endpoint Manager Configuration Manager ?

Introduction

Microsoft BitLocker Administration and Monitoring (MBAM) is the ability to have a client agent (the MDOP MBAM agent) on your Windows devices (7,8 10) to enforce BitLocker encryption including algorithm type, and to store the recovery keys in your database, securely. It includes reporting, key rotation and more.

This is something that has been around for quite some years now and is working great, however, MBAM is currently it’s own separate solution. The following blog post from Microsoft details their future direction with regard to BitLocker Management and is  a must read.

https://techcommunity.microsoft.com/t5/Enterprise-Mobility-Security/Microsoft-expands-BitLocker-management-capabilities-for-the/ba-p/544329

The purpose of this blog post is to gather together previous guides (and videos) I’ve created since MBAM’s first release in Configuration Manager Technical Preview version  1905.

This will help you understand how to get started with MBAM integrated within Configuration Manager, what to expect on the client computers, using help desk functionality, key rotation, self service (for the end user) and finally running reports to get an overview of your compliance.

Videos

  • MBAM BitLocker management – Part 1
  • MBAM BitLocker management – Part 2
  • MBAM BitLocker management – Part 3

Guides

Microsoft Docs

Note: MBAM integrated in 1910 requires a https enabled management point (see below). If you’d like help to configure PKI then see my links at the bottom of this blog post.

Setting up PKI in a lab

Convert Configuration Manager from HTTP to HTTPS (PKI)

 

This entry was posted in 1909, 1910, Key Rotation, MBAM helpdesk, MBAM Reporting, MBAM SelfService, PKI, pki. Bookmark the permalink.

2 Responses to Want to learn about MBAM integrated with Microsoft Endpoint Manager Configuration Manager ?

  1. gowdey says:

    Great stuff as always Niall!

  2. Pingback: Learn about MBAM integration in Microsoft Endpoint Configuration Manager version 1910 | just another windows noob ?

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.