Administrating BitLocker for Non-Domain-Joined Machines
I provide IT support for a company of consultants. Many of them have no problems working on the domain, but some of the rogue ones like to re-image and work off the domain. We're using the Microsoft BitLocker Administration and Monitoring (MBAM) tool to enforce BitLocker through group policy for domain-joined machines. However, this tool really isn't useful for non-domain-joined machines. Our corporate policy is that all laptops should have at least one encrypted volume (the boot/OS volume). But it's near impossible to enforce BitLocker for our consultants who are not joined to the domain. So I'd like to get an idea on how some of you are going about supporting BitLocker in this scenario. Right now the only solution I have is to request that our consultants provide us with the BitLocker recovery key or recovery password/ID in a text file. Where we then store this text file in a secured location in SharePoint. Thoughts? MCITP Windows 7 MCTS Windows Server 2008
November 3rd, 2011 10:05am

Hi, As far as I know, there is no way to enforce BitLocker for these computers which are not in domain. These computers are just like private computers. You can let them enable BitLocker, then provide your with the recovery key or recovery password/ID. Best Regards, NikiPlease remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
November 4th, 2011 3:31am

Hi, As far as I know, there is no way to enforce BitLocker for these computers which are not in domain. These computers are just like private computers. You can let them enable BitLocker, then provide your with the recovery key or recovery password/ID. Best Regards, NikiPlease remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
November 4th, 2011 10:22am

Hi, I am currently standing by for an update from you. If you have any other question about Windows 7, please feel free to let me know. Best Regards, NikiPlease remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
November 7th, 2011 9:21pm

Hey Niki, In our attempt to audit BitLocker, we've decided to compare the users in MBAM with users who don't show up in MBAM and then head that direction for those not in compliance. Thanks for your input! MCITP Windows 7 MCTS Windows Server 2008
November 8th, 2011 4:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics