Bit Locker Group Policy

%3CLINGO-SUB%20id%3D%22lingo-sub-1702897%22%20slang%3D%22en-US%22%3EBit%20Locker%20Group%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1702897%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20question%20about%20the%20Bit%20Locker%20Group%20Policy.%20I%20have%20setup%20the%20GPO%20and%20tied%20it%20to%20an%20OU%20in%20our%20domain%20with%20all%20settings%20I%20want%20applied.%20From%20my%20understanding%20Bit%20Locker%20will%20not%20enable%20by%20itself%20just%20by%20configuring%20the%20GPO%20but%20instead%20just%20define%20the%20settings%20I%20want%20to%20apply%20in%20the%20policy.%20I%20would%20have%20to%20either%20enable%20it%20manually%20or%20by%20some%20type%20of%20script.%20But%20what%20I%20am%20noticing%20is%20that%20I%20have%20computers%20that%20are%20automatically%20enabling%20Bit%20Locker.%20Is%20this%20supposed%20to%20happen%3F%20Has%20anybody%20else%20had%20this%20happen.%20Its%20good%20in%20the%20fact%20that%20I%20dont%20have%20to%20touch%20all%20the%20computers%20but%20bad%20if%20it%20enables%20it%20and%20they%26nbsp%3B%20have%20USB%20drives%20attached%20at%20the%20time%20it%20is%20enabled%20which%20would%20cause%20BL%20recovery%20mode%20to%20come%20up.%20Any%20insight%20is%20welcome.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1702897%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EBit%20Locker%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Egpo%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1744586%22%20slang%3D%22en-US%22%3ERe%3A%20Bit%20Locker%20Group%20Policy%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1744586%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F531473%22%20target%3D%22_blank%22%3E%40charlie4872%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eby%20default%2C%20Windows%20does%20not%20encrypt%20disks%20automatically.%20The%20GPO%20only%20configures%20the%20settings%20which%20will%20be%20applied%20if%20BitLocker%20is%20enabled.%3C%2FP%3E%3CP%3EHowever%2C%20there%20are%20some%20scenarios%20where%20BitLocker%20is%20enabled%20automatically%3A%3CBR%20%2F%3E-%20If%20the%20device%20is%20joined%20to%20Azure%20AD%3C%2FP%3E%3CP%3E-%20If%20the%20device%20supports%20some%20special%20requirements%20as%20outlined%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.dell.com%2Fsupport%2Farticle%2Fde-de%2Fsln299056%2Fautomatic-windows-device-encryption-bitlocker-on-dell-systems%3Flang%3Den%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.dell.com%2Fsupport%2Farticle%2Fde-de%2Fsln299056%2Fautomatic-windows-device-encryption-bitlocker-on-dell-systems%3Flang%3Den%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMaybe%20one%20of%20these%20scenarios%20apply%20to%20your%20situation%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

I have a question about the Bit Locker Group Policy. I have setup the GPO and tied it to an OU in our domain with all settings I want applied. From my understanding Bit Locker will not enable by itself just by configuring the GPO but instead just define the settings I want to apply in the policy. I would have to either enable it manually or by some type of script. But what I am noticing is that I have computers that are automatically enabling Bit Locker. Is this supposed to happen? Has anybody else had this happen. Its good in the fact that I dont have to touch all the computers but bad if it enables it and they  have USB drives attached at the time it is enabled which would cause BL recovery mode to come up. Any insight is welcome.

 

Thanks!

1 Reply
Highlighted

Hi @charlie4872,

 

by default, Windows does not encrypt disks automatically. The GPO only configures the settings which will be applied if BitLocker is enabled.

However, there are some scenarios where BitLocker is enabled automatically:
- If the device is joined to Azure AD

- If the device supports some special requirements as outlined here: https://www.dell.com/support/article/de-de/sln299056/automatic-windows-device-encryption-bitlocker-o... 

 

Maybe one of these scenarios applies to your situation?