| IT-PO-WIN-C-Bitlocker Encyption Settings | |
| Data collected on: 2-9-2025 09:58:51 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\padiglione.5-adm |
| Created | 25-6-2021 10:14:30 |
| Modified | 9-2-2023 15:04:32 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {7ffffd4b-1bef-46ab-9d3c-bbf83fd2a34d} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | Yes | Enabled | emea.tpg.ads/IT/Systems/Clients |
| Name |
|---|
| EMEA\IT-L-SEC-Bitlocker Encrypted Computers |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\IT-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\IT-L-SEC-Bitlocker Encrypted Computers | Read (from Security Filtering) | No |
| EMEA\IT-L-SEC-Delegation Full Access | Edit settings, delete, modify security | No |
| EMEA\padiglione.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||
| Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Allow access to BitLocker-protected fixed data drives from earlier versions of Windows | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose how BitLocker-protected fixed drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Configure use of hardware-based encryption for fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on fixed data drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected operating system drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Configure use of hardware-based encryption for operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||