Category Archives: BitLocker

Encrypting devices during Windows Autopilot provisioning (WhiteGlove) – Part 3

Introduction Note: This method is not officially supported by Microsoft. That said, this speeds up compliance and more importantly increases security as the device is already encrypted (part 1) before the user logs on (part 2). BitLocker recovery key changes … Continue reading

Posted in AzureAD, BitLocker, functionapp, httptrigger, Intune, win32 app, Windows AutoPilot | Leave a comment

Encrypting devices during Windows Autopilot provisioning (WhiteGlove) – Part 2

Introduction Windows Autopilot preprovisioning (WhiteGlove) is the ability to pre-stage content and policies to devices while it’s been installed in the factory. We had a challenge to speed up the overall compliance of Windows Autopilot devices and the obvious solution … Continue reading

Posted in BitLocker, Compliance, win32 app, Windows AutoPilot | Leave a comment

Encrypting devices during Windows Autopilot provisioning (WhiteGlove) – Part 1

Introduction Note: This is not supported by Microsoft and your mileage may vary. That said, this speeds up compliance and more importantly increases security as the device is already encrypted by the time the user logs on (in Part 2). … Continue reading

Posted in BitLocker, IntuneWinAppUtil.exe | 2 Comments

Escrow BitLocker recovery password to the site during a task sequence in Configuration Manager 2203

Introduction Update: Microsoft have now released Configuration Manager 2203 and it contains this and other amazing new features. Microsoft released Technical Preview Configuration Manager version 2203 and it contains some cool new features, one of which is the ability to … Continue reading

Posted in 20H2, 2203, 2203, BitLocker, escrow bitlocker recovery info, escrow bitlocker recovery info, Windows 10 | Leave a comment

using BitLocker Management in ConfigMgr and do OSD, read this !

Introduction I like many others have blogged about enabling BitLocker during a task sequence in the past, however recently it’s come to my attention that the Invoke-MBAMClientDeployment.ps1 scripts which were provided for MBAM setups are not supported for use with … Continue reading

Posted in 2103, Bitlocker, BitLocker, policy storm | Leave a comment

Retire My PC – a self-service app to secure company data on old computers

Introduction By now we should all be familiar with Windows Autopilot and how it is used to provision new computers, as explained below in Microsoft’s diagram. For every new computer delivered via the Windows Autopilot process there’s usually an old … Continue reading

Posted in AzureAD, BitLocker, httptrigger, sendgrid | Leave a comment

A quick look at the “Retire MY PC” app

Introduction I tweeted about this recently and it gained a LOT of attention, so I thought I better do a video showing what this actually does. When your users get a new Windows Autopilot PC, their old computer will usually … Continue reading

Posted in 2103, AzureAD, BitLocker, BitLocker Management over CMG, httptrigger, sendgrid | Leave a comment

How can I replace an expired IIS certificate in a PKI enabled ConfigMgr environment

Introduction I was busy putting together another BitLocker Management OSD related blog post in one of my PKI enabled ConfigMgr labs (#11) when I noticed that PXE boot no longer worked. The virtual machine would attempt to PXE boot for … Continue reading

Posted in 2002, BitLocker, expired IIS cert, PKI, smspxe.log | 3 Comments

Full disk encryption (in ConfigMgr 1910) – a closer look using real hardware

Introduction In an earlier post I showed you how you can enable Full Disk Encryption via a task sequence in Microsoft Endpoint Manager Configuration Manager version 1910. The screenshots in that blog post were taken from virtual machines, and I … Continue reading

Posted in 1910, BitLocker, Full Disk Encryption | 6 Comments

Enabling Full Disk Encryption in Microsoft Endpoint Configuration Manager 1910 in a task sequence

Introduction Microsoft Endpoint Configuration Manager 1910 came with BitLocker management capabilities (MBAM features), and this fits together nicely with task sequence steps regarding BitLocker. The option to enable Full Disk Encryption actually started with Configuration Manager 1806 but MBAM integration … Continue reading

Posted in 1910, BitLocker, Full Disk Encryption | 12 Comments

How to fix: “Unable to find suitable Recovery Service MP. Marking policy non-compliant”

Introduction Microsoft introduced on-premises BitLocker management using System Center Configuration Manager in SCCM Technical Preview version 1905. When enabling these MBAM capabilities in SCCM, you may notice the following error in the BitlockerManagement_GroupPolicyHandler.log. Unable to find suitable Recovery Service MP. … Continue reading

Posted in 1905, BitLocker, MBAM | 12 Comments

Why does the Bitlocker recovery key not end up in the MBAM 2.5 SP1 database when using XTS encryption

Introduction If you are using my Windows 10 UEFI FrontEnd HTA to encrypt UEFI devices when installing Windows 10, and if you are using the MBAM 2.5 SP1 hotfix 2 to enable support for XTS-AES encryption, then you might have … Continue reading

Posted in BitLocker, MBAM 2.5 SP1, UEFI | 1 Comment

Why does the Windows 10 1607 reinstall in PXE scenario fail sometimes for BitLockered UEFI enabled computers ?

Introduction Reinstalling computers via PXE boot (in WinPE) is still a valid OSD scenario, however that method brings challenges not least when UEFI capable hardware is in place and when that hardware is also encrypted with Bitlocker. The above HTA … Continue reading

Posted in 1606, 1607, BitLocker, Windows 10 | Leave a comment

How can I retrieve my BitLocker Recovery key ?

Here’s a very quick post, if you are not using MBAM and don’t have access to your Active Directory and want to recover your BitLocker key for whatever reason you can quickly do as follows within Windows:- Open an Administrative … Continue reading

Posted in BitLocker | 57 Comments