| AL-PO-WIN-C-BitLocker Encryption Settings Workstations WAHA | |
| Data collected on: 2-9-2025 09:59:39 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\likaj.7-adm |
| Created | 15-7-2021 09:13:00 |
| Modified | 16-6-2023 09:20:00 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 124 (AD), 124 (SYSVOL) |
| Unique ID | {62ab1056-59e3-4ef2-9d31-d540706bca55} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/AL/Systems/Clients |
| Name |
|---|
| EMEA\ALDRZ-G-ORG-Computers |
| EMEA\ALDRZ-G-ORG-HP-G1 |
| EMEA\ALTIR-G-ORG-Computers |
| EMEA\ALTIR-G-ORG-Computers CTI |
| EMEA\ALTIR-G-ORG-Computers Staff |
| EMEA\ALTIR-G-ORG-Computers WEBDEV |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\ALDRZ-G-ORG-Computers | Read (from Security Filtering) | No |
| EMEA\ALDRZ-G-ORG-HP-G1 | Read (from Security Filtering) | No |
| EMEA\AL-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\ALTIR-G-ORG-Computers | Read (from Security Filtering) | No |
| EMEA\ALTIR-G-ORG-Computers CTI | Read (from Security Filtering) | No |
| EMEA\ALTIR-G-ORG-Computers Staff | Read (from Security Filtering) | No |
| EMEA\ALTIR-G-ORG-Computers WEBDEV | Read (from Security Filtering) | No |
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\likaj.7 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Provide the unique identifiers for your organization | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow access to BitLocker-protected fixed data drives from earlier versions of Windows | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose how BitLocker-protected fixed drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Configure use of hardware-based encryption for fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected operating system drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Action | Update |
| Name | Enable bitlocker workstation | |||
| Author | EMEA\pengili.6-adm | |||
| Description | ||||
| Run only when user is logged on | S4U | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Delay task for | 1 minute | |||
| Stop task if it runs longer than | 1 hour | |||
| Activate | 5-4-2023 11:57:37 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\emea.tpg.ads\sysvol\emea.tpg.ads\Policies\{62AB1056-59E3-4EF2-9D31-D540706BCA55}\Machine\Preferences\ScheduledTasks\Enable Bitlocker.bat |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | Yes | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Delete |
| Name | Enable Bitlocker WAHA | |||
| Author | EMEA\likaj.7-adm | |||
| Description | 1.1 run Weekly to supress some problems with PCs that get locked in Bitlocker key reuqirement every restart. | |||
| Run only when user is logged on | InteractiveToken | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Start a program | ||||
| Program/script | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | |||
| Arguments | Enable-Bitlocker -MountPoint c: -SkipHardwareTest -UsedSpaceOnly -RecoveryPasswordProtector |
| Stop processing items on this extension if an error occurs on this item | No |
| Apply once and do not reapply | No |