| ROBUH-PO-WIN-C-BITLOCKER-ANT | |
| Data collected on: 2-9-2025 11:34:51 | |
| Domain | emea.tpg.ads |
| Owner | S-1-5-21-513466819-3096973226-347852806-612168 |
| Created | 11-10-2023 10:08:30 |
| Modified | 12-10-2023 08:55:00 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 12 (AD), 12 (SYSVOL) |
| Unique ID | {ab7f5b13-a2d5-4132-932e-490d0b92ce35} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| ANT | No | Enabled | emea.tpg.ads/RO/Systems/Clients/ANT |
| Name |
|---|
| EMEA\ROBU1VMANT01$ |
| S-1-5-21-513466819-3096973226-347852806-1108829 |
| S-1-5-21-513466819-3096973226-347852806-1504198 |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\ROBU1VMANT01$ | Read (from Security Filtering) | No |
| EMEA\RO-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| S-1-5-21-513466819-3096973226-347852806-1108829 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-1504198 | Read (from Security Filtering) | No |
| S-1-5-21-513466819-3096973226-347852806-612168 | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose default folder for recovery password | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Choose drive encryption method and cipher strength (Windows 8, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows 10 [Version 1507]) | Disabled | |||||||||||||||||
| Store BitLocker recovery information in Active Directory Domain Services (Windows Server 2008 and Windows Vista) | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Choose how BitLocker-protected operating system drives can be recovered | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Enforce drive encryption type on operating system drives | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Policy | Setting | Comment | ||||||||||||||||
| Require additional authentication at startup | Enabled | |||||||||||||||||
| ||||||||||||||||||
| Action | Update |
| Name | Bitlocker Auto Encryption | |||
| Author | EMEA\bujor.8-adm | |||
| Description | ||||
| Run only when user is logged on | S4U | |||
| UserId | NT AUTHORITY\System | |||
| Run with highest privileges | HighestAvailable | |||
| Hidden | No | |||
| Configure for | 1.2 | |||
| Enabled | Yes |
| 1. Run at user logon | ||||
| Stop task if it runs longer than | 3 days | |||
| Enabled | Yes | |||
| 1. Start a program | ||||
| Program/script | \\robuhemeadc01\SYSVOL\emea.tpg.ads\Policies\{33E7D701-E2C7-4A8C-990D-9D48BDA10E7F}\Machine\Bitlocker.bat |
| Start the task only if the computer is idle for | 5 minutes | |||
| Wait for idle for | 1 hour | |||
| Stop if the computer ceases to be idle | Yes | |||
| Restart if the idle state resumes | No | |||
| Start the task only if the computer is on AC power | Yes | |||
| Stop if the computer switches to battery power | Yes | |||
| Allow task to be run on demand | Yes | |||
| Run task as soon as possible after a scheduled start is missed | Yes | |||
| Stop task if it runs longer than | 3 days | |||
| If the running task does not end when requested, force it to stop | Yes | |||
| If the task is already running, then the following rule applies | IgnoreNew |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |