BitLocker configuration GPO settings not propagating


i have windows server 2012 r2 environment. of clients windows 7 pro, windows 7 ultimate, windows 7 enterprise , windows 8.1 enterprise.

i trying use group policy make sure tpm , bitlocker recovery information stored in active directory. have set policies according following document: "backup thetpm recovery information ad ds"

i have following setup in group policy manager:

default domain policy .... no bitlocker or tpm settings configured.

encrypteddevices ..... policy "link enabled" ou, , "enforced".  scope includes groups "domain computers", "everyone", , "encrypted devices" (a security group containing test laptop). have verified permissions read , apply policy members of scope. in ad users , computers, test laptop in encrypteddevices ou.

the problem:

i able encrypt laptop, bitlocker recovery information did not show in active directory. used gpedit.msc view local security policy , bitlocker , tpm policy settings not reflecting gp set in domain controller.

i use rsop on test laptop view policy application. rsop shows encrypteddevices policy winner on each of required settings, laptop behaves though local or domain policy winner.


overlooking something? these settings cannot controlled through gp? there list of such policies somewhere don't keep slamming head against wall?

thanks time , consideration.

--dexter lagrand

hi dexter,

according description, the group policy configured applied successfully. there's misunderstanding local security policy. not policy set on domain controller made related local group policy grayed out.

and regarding backup failure, please check if follow notes below:

note1: must first set appropriate schema extensions , access control settings on domain before ad ds backup can succeed. consult online documentation more information settings active directory domain service tpm.

note2:the tpm can not used provide enhanced security features bitlocker drive encryption , other applications without first setting owner. take ownership of tpm owner password, run "tpm.msc" , select action "initialize tpm".

hope helps.

best regards,

elaine 


please remember mark replies answers if , unmark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group