| PL-PO-WIN-C-Bitlocker Client System Settings | |
| Data collected on: 2-9-2025 08:58:05 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-305342 |
| Created | 21-4-2016 08:25:52 |
| Modified | 9-2-2023 14:45:30 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 115 (AD), 115 (SYSVOL) |
| Unique ID | {9cc83a0f-18e2-47fb-a1ab-73c8d890b8d7} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/PL/Systems/Clients |
| Name |
|---|
| EMEA\PL-L-SEC-Bitlocker TPMOnly Settings |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\PL-L-SEC-Bitlocker TPMOnly Settings | Read (from Security Filtering) | No |
| EMEA\PL-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-203252 | Read | No |
| S-1-5-21-513466819-3096973226-347852806-305342 | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose how users can recover BitLocker-protected drives (Windows Server 2008 and Windows Vista) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Provide the unique identifiers for your organization | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected fixed drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected operating system drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Setting | State |
|---|---|
| Software\Policies\Microsoft\TPM\ActiveDirectoryBackup | 1 |
| Software\Policies\Microsoft\TPM\RequireActiveDirectoryBackup | 1 |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\FVE |
| Value name | EncryptionMethodWithXtsFdv |
| Value type | REG_DWORD |
| Value data | 0x7 (7) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\FVE |
| Value name | EncryptionMethodWithXtsOs |
| Value type | REG_DWORD |
| Value data | 0x7 (7) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\FVE |
| Value name | EncryptionMethodWithXtsRdv |
| Value type | REG_DWORD |
| Value data | 0x7 (7) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Replace |
| Name | Enable Bitlocker | |||
| Author | EMEA\mlynarczyk.5-adm | |||
| Description | ||||
| Run only when user is logged on | ||||
| GroupId | NT AUTHORITY\SYSTEM | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | Yes | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. At startup | ||||
| Activate | 3-11-2019 04:00:00 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 2. At task creation/modification | ||||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -File "\\emea.tpg.ads\SysVol\emea.tpg.ads\Policies\{9CC83A0F-18E2-47FB-A1AB-73C8D890B8D7}\Machine\Scripts\Startup\Enable BT.ps1" |
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | Yes | |||
| Stop task if it runs longer than | Immediately | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |