| GC-PO-WIN-C-BitLocker Encryption Settings UEFI | |
| Data collected on: 2-9-2025 10:41:49 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\likaj.7-adm |
| Created | 29-8-2022 14:13:02 |
| Modified | 24-8-2025 15:12:50 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {de40ecf6-5910-47f6-93c0-1c06d68764dc} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/Special-Services/GC/Systems/Clients |
| Name |
|---|
| EMEA\GCDXBL1Y3Y1B3$ |
| EMEA\GCDXBLCD24445V6$ |
| EMEA\GCDXBLND15052VC$ |
| EMEA\GC-G-ORG-DMM-Citzen Account Computers |
| EMEA\GC-G-ORG-JED-Citzen Account Computers |
| EMEA\GC-G-ORG-RUH-ABB Computers |
| EMEA\GC-G-ORG-RUH-AC Computers |
| EMEA\GC-G-ORG-RUH-Citzen Account Computers |
| EMEA\GC-G-ORG-RUH-Hala Computers |
| EMEA\GC-G-ORG-RUH-Hungerstation Computers |
| EMEA\GC-G-ORG-RUH-McDonalds Computers |
| EMEA\GC-G-ORG-RUH-NTDP Computers |
| EMEA\GC-G-ORG-RUH-RX Computers |
| EMEA\GC-G-ORG-RUH-SFC Computers |
| EMEA\GC-G-ORG-RUH-Thamanyah Computers |
| EMEA\GC-G-ORG-RUH-Thiqah Computers |
| EMEA\GC-L-SEC-Bitlocker-Encryption-Settings |
| S-1-5-21-513466819-3096973226-347852806-1232103 |
| S-1-5-21-513466819-3096973226-347852806-1232113 |
| S-1-5-21-513466819-3096973226-347852806-1232815 |
| S-1-5-21-513466819-3096973226-347852806-1232947 |
| S-1-5-21-513466819-3096973226-347852806-1519107 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GCDXBL1Y3Y1B3$ | Read (from Security Filtering) | No |
| EMEA\GCDXBLCD24445V6$ | Read (from Security Filtering) | No |
| EMEA\GCDXBLND15052VC$ | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-DMM-Citzen Account Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-JED-Citzen Account Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GC-G-ORG-RUH-ABB Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-AC Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-Citzen Account Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-Hala Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-Hungerstation Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-McDonalds Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-NTDP Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-RX Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-SFC Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-Thamanyah Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-RUH-Thiqah Computers | Read (from Security Filtering) | No |
| EMEA\GC-G-ORG-ServerAdmin | Edit settings, delete, modify security | No |
| EMEA\GC-L-SEC-Bitlocker-Encryption-Settings | Read (from Security Filtering) | No |
| EMEA\likaj.7-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-1232103 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-1232113 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-1232815 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-1232947 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-1519107 | Read (from Security Filtering) | No |
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Provide the unique identifiers for your organization | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow access to BitLocker-protected fixed data drives from earlier versions of Windows | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose how BitLocker-protected fixed drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Configure use of hardware-based encryption for fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected operating system drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||