| PT-PO-WIN-C-Bitlocker Client System Settings | |
| Data collected on: 2-9-2025 09:46:35 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-510149 |
| Created | 29-5-2020 12:41:36 |
| Modified | 9-2-2023 14:52:56 |
| User Revisions | 8 (AD), 8 (SYSVOL) |
| Computer Revisions | 68 (AD), 68 (SYSVOL) |
| Unique ID | {684e1f65-20ad-4e34-a8f4-350a78557f7a} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | Yes | Enabled | emea.tpg.ads/PT/Systems/Clients |
| Name |
|---|
| EMEA\PT-G-ORG-Bitlocker Workstations |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\PT-G-ORG-Bitlocker Workstations | Read (from Security Filtering) | No |
| EMEA\PT-L-SEC-Delegation Modify Group Policy Settings Access | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-510149 | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure Logon Script Delay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Turn on Script Execution | Enabled | |||
| ||||
| Setting | State |
|---|---|
| Software\Policies\Microsoft\TPM\ActiveDirectoryBackup | 1 |
| Software\Policies\Microsoft\TPM\RequireActiveDirectoryBackup | 1 |
| Action | Update |
| Source file(s) | \\emea.tpg.ads\pt\Lisbon-CIT\Clients\Settings\Bitlocker\BitLockerScriptV001.ps1 |
| Destination file | C:\Bin\BitLockerScriptV001.ps1 |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Name | Bitlocker | |||
| Author | EMEA\rodrigues.1104-adm | |||
| Description | ||||
| Run only when user is logged on | S4U | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.3 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Delay task for | 30 seconds | |||
| Stop task if it runs longer than | 2 hours | |||
| Activate | 4-6-2020 19:49:39 | Synchronize across time zones | No | |
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | %SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe | |||
| Arguments | -ExecutionPolicy Bypass -File "C:\Bin\BitLockerScriptV001.ps1" |
| Stop if the computer ceases to be idle | No | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | No | |||
| Stop if the computer switches to battery power | No | |||
| Allow task to be run on demand | No | |||
| Stop task if it runs longer than | 2 hours | |||
| If the running task does not end when requested, force it to stop | No | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | Yes |