Windows Vista Forums

BitLocker: Is there a GPO option to forbid decryption/re-encryptio
  1. #1


    tavis Guest

    BitLocker: Is there a GPO option to forbid decryption/re-encryptio

    I see GPO settings to set options for BitLocker, such as mandating recovery
    keys into AD or the level of encryption, but is there an option to keep a
    user from decrypting the drive once it has been deployed to them as encrypted?

    This applies to the case where a company policy deploys all laptops with
    encryption, and doesn't want users to decrypt or re-encrypt the drive
    themselves.



    Thanks!

      My System SpecsSystem Spec

  2. #2


    Jamie Hunter [MS] Guest

    Re: BitLocker: Is there a GPO option to forbid decryption/re-encryptio

    There is currently no GPO to block this.
    You can catch this with a 'health check' script, in particular to
    (a) make sure the backup key is backed up (you can set a GPO to require that
    this key is always backed up, which will block encryption if the AD is not
    available)
    (b) make sure the volume is encrypted, and to begin encrypting if the user
    manually decrypted it / paused it.

    Or, our more preferred approach, is to not allow the user to be able to log
    on as an Administrator .

    -
    Jamie Hunter [MS]

    "tavis" <tavis@discussions.microsoft.com> wrote in message
    news:7B9658F3-9C70-4BCC-8415-5D0B6F4E116B@microsoft.com...
    >I see GPO settings to set options for BitLocker, such as mandating recovery
    > keys into AD or the level of encryption, but is there an option to keep a
    > user from decrypting the drive once it has been deployed to them as
    > encrypted?
    >
    > This applies to the case where a company policy deploys all laptops with
    > encryption, and doesn't want users to decrypt or re-encrypt the drive
    > themselves.
    >
    > Thanks!



      My System SpecsSystem Spec

BitLocker: Is there a GPO option to forbid decryption/re-encryptio problems?

Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: How to forbid the Windows Updates Dave Patrick Server General 1 19 Apr 2010
Decryption fail due to forgotten password :'( SHili General Discussion 1 26 Feb 2009
Free en-/decryption solution [PGP]? Phil Live Mail 1 01 Feb 2009
Forbid Vista from waking PC??? Mark Sullivan Vista performance & maintenance 3 05 Oct 2007
Windows XP Pro encryption/Decryption (EFS) Marty Vista mail 3 27 Apr 2007