You saved my life! I was really struggling with the BitLocker policy, and it just wasn’t working. I can confirm that it works on the latest version of MCM. I had to create a policy to decrypt the system drive, considering that the Checkpoint solution will be used.
@MiguelGonzalez-hs1bkАй бұрын
Thank you for the video it was excellent, i will use it if we upgrade to 2309. i have one very important question once i upgrade to 2309 will the comangement slider work, and if it does work will it work as before the upgrade. thank you in advance.
@globus2000incАй бұрын
you have helped to restore NPS server. thnx
@ncbradyАй бұрын
cool I'm happy to hear it !
@DavidMartinez-r6j8n8 ай бұрын
Do I need to install the ODBC Driver on my DPs as well? Our DPs have the Site System role but dont currently have an ODBC Driver installed
@clivebuckwheat8 ай бұрын
Nial, why is it when you pxe boot and looked at the smspxe.log you still see in ssl but no client cert?, I am having this issue right now and resolving policy is taking forever to bring up the advertise task sequence window
@ncbrady8 ай бұрын
hi Clive, that's a red-herring, ignore it. If policy is taking a long time to flow down from the management point then you need to troubleshoot that, perhaps try deleting then redeploying that task sequence, i think you'll see a difference. If not, reduce the size of the task sequence or improve the network connection (if remote).
@clivebuckwheat8 ай бұрын
@@ncbrady I did all that. I am on day 5 of this. I deleted all the task sequences advertised to unknown computers, our task sequences aren't complicated. I got excited when i saw your video I thought maybe my battle was over. It takes about 10 minutes for the advertise task sequence page to pop up. This all began after I upgraded to CM 2309. I have updated the boot images on the dp, I have even tried boot media instead of PXE and it takes forever, to resolve the policy. I'll say this sometimes its fast, meaning (normal speed) but most of the time it's slow now. oh well my battle is not over it seems thanks for the reply.
@ncbrady8 ай бұрын
@@clivebuckwheat you need to tell me more about the environment that you have then, i bet it's 10 minutes on remote distribution points right ?, what about local dp's ? is PXE boot ok there ? any changes recently to the network infrastructure ?
@clivebuckwheat8 ай бұрын
@@ncbrady one on-premises distribution point one off premises PXE is on the on-premises distribution point and it services our clients across the street It’s really not a PXE problem as I first was certain it was because it happens with boot media as well. Nial here’s a scenario PXE boot a machine or use boot media to connect to our configmgr environment it’s normal speed, find policy for this machine is fast, pick a ts resolving dependencies Is fast and OSD kicks off. PXE boot or boot media the same machine again both looking for policy for this computer is slow and after 10 minutes the advertise task sequence window pops up and resolving dependencies is slow for the task sequence another 10 minutes and OSD kicks off. PXE boot or boot media the machine again it’s slow. Switches were changed in my environment recently Anyways it’s so sporadic I can’t pin it down
@EvansCon409 ай бұрын
I followed your CI/Baseline configuration but I can not get my non encrypted system to encrypt without the user popup. We are using 2309, is any of this still valid for this version?
@Himura66611 ай бұрын
YOO ! YOUR THE MAN BRO
@eavenhuang741911 ай бұрын
I'm running in HTTPS with PKIs but I think I'm missing something when it comes to PXE as I'm getting the following messages spammed in my SMSPXE.log file whenever a machine tries to PXE boot: 7096 0x1bb8 in ssl but with no client cert. I went to Administration, Security and then Certificates. In there I had 2 out of 3 blocked DP certificates and the issued to fields were showing as GUIDs rather than actual FQDNs. Any ideas?
@itips4021 Жыл бұрын
Excellernt series ! I'm shortly going to be involved in a project to migrate MBAM off SCCM to Azure/ Intune - have you been involved with that ? Any guidance on that will be greaat! 😁
@klausvaldek Жыл бұрын
Great !!
@russellfox5332 Жыл бұрын
Luckily now they provide the link to download the odbc driver in the notes of the prerequisite check for that step.
@M365tunes Жыл бұрын
Thanks for the video, couple of questions. 1. If we don't use OSD for clients, do I need update the ADK? 2. the new prereq SQL ODBC, let's say if I skip the 2309 and install 2403 then is it still required to install SQL ODBC? (will this be mentioned in the release info just like current release)
@ncbrady Жыл бұрын
1. i don't think so 2. yes you'll need it for all versions fo ConfigMgr after the 2309 release cheers niall
@M365tunes Жыл бұрын
@@ncbrady thanks Niall 👍, I will keep the points in mind.
@batista98854 Жыл бұрын
best explanation so far with practical examples
@ncbrady Жыл бұрын
thanks I appreciate it !
@andrewmccallum5699 Жыл бұрын
Thanks Niall & Paul, was reading your blog post earlier, the video step by step is ace, greatly appreciate your time going through this (the whole series is super!)
@ncbrady Жыл бұрын
thanks Andrew that means a lot !
@anmasula Жыл бұрын
Awesome Niall. Was the content actually copied from source dp to destination DP or still transffered from site server?
@thotasworld2055 Жыл бұрын
We can migrate the content from one DP to other DP in a single primary site but how about One DP in one primary site to other DP in different primary site under CAS? Will it work ?
@ncbrady Жыл бұрын
there's only one way to find out !
@warrenswaby Жыл бұрын
Amazing info thank you
@chrizzlibaer Жыл бұрын
Hi Niall, thanks for your awesome work with this videos! I am stuck With the key "recoveryserviceendpoint" not being deployed to Clients. When i add it manually, Policy by MECM 2203 just deletes its right away when the policy gets applied. On machines at the primary location, this seems not to be any issue, but at secondary sites, i have connection issues, MBAM Eventlog states problems with connection to the management point. Do you have any idea where i can search for a solution? :-( Thanks!
@ncbrady Жыл бұрын
a lot has changed since i did this video, i think the 'recoveryserviceendpoint' was removed in CM2103 so it's no longer needed. IS there a gap you are trying to fill ? if so what ?
@chrizzlibaer Жыл бұрын
@@ncbrady I finally figured that the Problem seems to be the bitlocker Policy. I Recreated the device collection and the policy and moved some of the clients to the new policy and boom, problems went away. Thanks anyways for getting back to me!
@ncbrady Жыл бұрын
@@chrizzlibaer great to hear it !
@lenneyyip1300 Жыл бұрын
Niall, if you don't install the MDOP agent, will the recover key still change on a schedule?
@ncbrady Жыл бұрын
good question, while i cannot currently prove it (this was a lab after all), the SCCM client agent will now handle the key upload etc, so it should take care of this, are you not seeing this happening ?
@megaperycles Жыл бұрын
Great job guy, thx a lot.
@perfektais Жыл бұрын
Hello! Under task sequnce, shouldn't I also specify the step that installs the MDOP agent? Thank you!
@ncbrady Жыл бұрын
hi Andris, did you see www.niallbrady.com/2022/03/03/escrow-bitlocker-recovery-password-to-the-site-during-a-task-sequence-in-configuration-manager-2203/ which states "Note: You do NOT need to install the MDOP Agent as part of the task sequence and you do NOT need to run any PowerShell script for this functionality to work."
@perfektais Жыл бұрын
@@ncbrady Thank you!
@mattaljanabi5022 Жыл бұрын
Hi @Niall, I have a question, do you have a series of documents on your website of Migration MBAM to Intune?
@ncbrady Жыл бұрын
here you go www.niallbrady.com/2020/01/19/learn-about-mbam-in-microsoft-endpoint-configuration-manager-version-1910-part-8-migration/
@revolutionar2 жыл бұрын
Hi Niall, when you are using this new method of escrowing the Recovery key during TS, do you need also to have CM Bitlocker policies deployed on that particular machine during build time?
@ncbrady2 жыл бұрын
hi Marcel, no as it's handled via the settings defined in the task sequence
@AJBOJACK Жыл бұрын
@@ncbrady Hi Niall, great video, as per Marcel comment. If you are building new VM/machines is there any point of the bitlocker management policy or is that just to enfore bitlocker on machines which don't have it. For some odd reason i am seeing 2 keys being generated on the AD object and within the database. The key is also not recoverable instantly via the helpdesk portal unless the recoverykeypackage has been added to the database. Which only happens to appear once a user has logged on to the machine directly (console not RDP) i checked this on multiple test VMs. Hoping you could help on this as I been scratching my head on this one.
@eduardrusi87612 жыл бұрын
Hello Niall, thank you for the great guides here. I have a small problem. The registry key doesn't have the KeyRecoveryServiceEndPoint entry. Did I miss something? Thank you. Config Mgr is Stand alone, 2207 version. the client got the CI, most of the settings are correct other than the missing config mgr server.
@ncbrady Жыл бұрын
it no longer get's added Eduard as the communication is now handled by the client directly to the MP
@eduardrusi8761 Жыл бұрын
@@ncbrady Thank you so very much!
@jakeersyed19892 жыл бұрын
Hi Niall, Is this feature available from MECM CB 2207 OR earlier or old versions also available ? Please let me know
@ncbrady2 жыл бұрын
hi, this feature was first released in Technical Preview 2207, and then in Configuration Manager 2207 (Current Branch). You can review my blog post here www.niallbrady.com/2022/07/18/first-looks-at-distribution-point-content-migration/ and the release notes here learn.microsoft.com/en-us/powershell/sccm/2207-release-notes?view=sccm-ps
@CharlesBreite2 жыл бұрын
I setup MBAM and its seems to be working for me on the server but the remote helpdesk access is receiving a 403 error. You do not have permission to view this directory or page using the credentials that you supplied.
@leanalighieri65862 жыл бұрын
I love you man!
@Nomelzor2 жыл бұрын
Hey Niall I'm curious if you know why a device ItemKey is NULL under ___hardwarecore.machines?(could add that TpmPolicyState is -1) I can see that a recovery key was added from the ts under ____hardwarecore.keys.
@mohamedgamal-xn6gx2 жыл бұрын
When I evaluate MBAM policy it delete the 2 registry key and the enforce deployment don't work, I need to know why the MBAM policy delete the registry keys I created
@seethetube1002 жыл бұрын
How to find the BitLocker key rotation status in MBAM and MBAM Config
@ncbrady2 жыл бұрын
is this question related to this video ?
@chiller152 жыл бұрын
Firstly, great guides, thank you. Secondly, I have migrated MBAM to CM, but my test device isn't escrowing the key to the CM database and I can't figure out why. Old MBAM GPOs have been removed and the new CM configuration baseline has been deployed. The client's MBAM Event Log shows VolumeEnactmentSuccessful and CM reports that the baseline is compliant - yet the key doesn't appear in the DB like it does in your example. Everything else appears to be working as expected, just not the recovery key. I'm stumped on this at the moment, any ideas? Edit: It helps to look at the right tables when looking for keys. A few years ago, before true MBAM integration with SCCM - I tried to install MBAM on the SCCM server to utilise the same SQL server. At that point, the two IIS sites didn't work with each other, due to SPN issues. So it left the MBAM databases in SQL. I didn't realise the new integratated MBAM places the tables under the CM_SITE DB. So problem sorted and it's writing the keys automatically into the DB. /Facepalm
@ncbrady2 жыл бұрын
what version of SCCM are you running Chris ? did you verify that your clients are indeed getting the bilocker management policy applied and that it has 'client management' enabled ?
@AndersKeisHansen2 жыл бұрын
Great video Niall !
@ncbrady2 жыл бұрын
thanks Anders !
@mattaljanabi50222 жыл бұрын
Hi Niall, Thanks first for your all videos, not just that. my SCCM server HTTPS , but the log did not see the MP. what I have to do?
@ncbrady2 жыл бұрын
thanks Matt, but i don't understand your question, have you followed everything in this guide ? which version of SCCM are you using ?
@mattaljanabi50222 жыл бұрын
@@ncbrady Niall, yes I did. SCCM is Https, but I cannot see in the client regkey is not pointing to the server (MP) which is my SCCM.
@ncbrady2 жыл бұрын
@@mattaljanabi5022 this video was originally created for SCCM 1910, a lot has changed since then, i believe that since sccm 2111 or so the reg keys in use changed somewhat so what you might be seeing is normal. Continue with the videos and guides until you are done.
@RJDavies962 жыл бұрын
my company is looking for this exact thing to move us from on prem to AAD. is there any chance you could make a video step by step guide? i was a bit confused regarding the http app function and filling out the IDs.
@ncbrady2 жыл бұрын
it's all blogged now (3 parts) please check it out
@zjw99462 жыл бұрын
Such a nice tutorial video, Thank you!
@ncbrady Жыл бұрын
You're very welcome!
@danpowell74212 жыл бұрын
This looks amazing! I tend to use an Autopilot rest when migrating to Azure AD/Endpoint Manager. This is another level of awesome!! A lot of companies I work with don't have SCCM. Will that always be a requirement?
@ncbrady2 жыл бұрын
thanks, the SCCM component is not a requirement and you can easily adapt the script to remove those functions and replace them with whatever management solution you are using
@summoner21002 жыл бұрын
It failed to find, because the TS pulls info down each time. So it has settings it thinks is good. Hence the reboot needed once device deleted. Good video and information though.
@summoner21002 жыл бұрын
Eww, don't use apply drivers built in. Use driver packs. If you use auto apply, and you have multiple models around, it will find things like Intel drivers with similar WMI returns and pull the wrong one (the 1, 2, 3, etc that are in the drivers section of console). It's the same driver. It will pull the wrong one. If, like some of mine, it pulls the wrong chipset. It's a pain to fix after. From memory I also believe Microsoft recommend driver packs too
@ncbrady Жыл бұрын
thanks for your comment ! The video isn't focused on drivers specifically, but more on deploying an os via CMG
@RTBrunswick2 жыл бұрын
How does this manage onedrive for business folders? aka onedrive - domain1 to onedrive - domain2 structures? More importantly any file shares therein?
@ncbrady2 жыл бұрын
hi Roger, sorry for the late reply, any migration of folders that you want to migrate needs to be done using OneDrive for Business, so you need to configure THAT for that migration. The Migrate to the Cloud app leverages OneDrive for Business but does not decide/change/depend on how you've configured those policies.
@RTBrunswick2 жыл бұрын
This is outstanding! I would love to test this for a migration we are currently working on.
@ncbrady2 жыл бұрын
i'll try and blog it this week ! thanks Roger
@coreypullman34282 жыл бұрын
Hi Niall, great video, if we previously had the Help Desk portal setup with MBAM (still currently using it) will setting up the new portals take down / conflict with the old one?
@mayurmakwana34412 жыл бұрын
Awesome , would like to try it
@ncbrady2 жыл бұрын
it's all blogged now (3 parts) please check it out
@jerodboisjoli4582 жыл бұрын
This is outstanding
@ncbrady2 жыл бұрын
thanks !
@CharleyBallmer2 жыл бұрын
Love this. I have lots of clients that we've had to go about this using a bunch of cobbled together powershell scripts, psexec, etc. Would love to test this out.
@ncbrady2 жыл бұрын
thanks ! keep an eye on my tweets to see when i blog it :-)
@o0MattE0o2 жыл бұрын
very interesting idea would love to test it out :)
@ncbrady2 жыл бұрын
thanks ! you'll be able to test it out soon, I just have to finalize things and of course, put the effort into blogging it, keep an eye on my twitter handle to see when that happens
@ncbrady2 жыл бұрын
it's all blogged now (3 parts) please check it out
@JessieS2 жыл бұрын
This is fantastic!!!
@ncbrady2 жыл бұрын
thanks !!
@minicustom2 жыл бұрын
Thanks Niall. This was a great video! I'm just wondering if you could share how to decrypt the keys in Sql. All my attempts have been a dismal failure.
@ncbrady2 жыл бұрын
thanks ! if you look at the stored procedures they are already doing just that, dig deeper and you'll figure it out
@minicustom2 жыл бұрын
@@ncbrady Thanks! That helped. Logic prevailed!
@krystian64262 жыл бұрын
Hi! Your manual is a perfect! I have this same problem like you at 18: BMSOSDEncryptionPolicy. I use SCCM 2103, values in regisry look fine... Where I should look for a problem?
@yogeshgupta19912 жыл бұрын
Thank You Niall...Quite Handy and simplified
@ncbrady2 жыл бұрын
Glad it helped
@albertjose67732 жыл бұрын
can you help me? if any other option for the BitLocker key rotation (without INTune)
@ncbrady2 жыл бұрын
i don't understand your question, can you try and explain what your problem is and what you want to do