Introducing BitLocker; Your Defence Against Stolen Devices

  Рет қаралды 5,120

Jonathan Edwards

Jonathan Edwards

Күн бұрын

Пікірлер: 35
@m_leBrave
@m_leBrave Ай бұрын
I don't know what I would have done without you Jonathan... I can't thank you enough
@HandZ_gaming
@HandZ_gaming 29 күн бұрын
Making me a better tech, one video at a time. Thanks Jonathan!
@lynchn-o9c
@lynchn-o9c Ай бұрын
thanks mate for the this video. Will definitely try this one to our organization. As of now, our subscription still on pending from e1 to e3. I hope it covers Intune using e3 license. great video. Robert here from Philippines :)
@funbala
@funbala Ай бұрын
Hi Jonathan, thank you so much for creating this very useful and simple to understand and deploy the BitLocker. I have one query, as you have disabled the startup PIN and recovery keys while booting, so how does it help and makes more secure if someone try to access the data?
@andrewenglish3810
@andrewenglish3810 Ай бұрын
How does it work with Hybrid systems? Ideally I would love to see Intune manage more hybrid systems.
@Jotaa-lb5iq
@Jotaa-lb5iq Ай бұрын
En español ... muy buen video ,gracias ., Saludos desde Chile
@davidadams421
@davidadams421 Ай бұрын
Great video! I'm sure they could have made those configuration options a little easier, maybe using 'configuration profiles', Standard, High Security etc. QQ When you setup device compliance policies that include, for example, drive encryption, does Windows 'self-remediate' by enabling bitlocker? I've seen non-compliant devices in endpoint manager that failed due to drive encryption magically become complaint the following day.
@sneakystevie_7
@sneakystevie_7 Ай бұрын
Hi Jonathan. Thank you for such an informative video. I had already configured bitlocker policy as shown in your video but I still have to go to end user devices to turn bitlocker on for those devices that had it off Is there a way to configure this policy so it turns bitlocker on automatically without any user or admin interaction?? This has been my challenge
@jon4715
@jon4715 Ай бұрын
PDE is a topic I’m looking forward to seeing explored.
@bearded365guy
@bearded365guy Ай бұрын
@@jon4715 I think it works on Windows 11 Enterprise and not Pro….
@nevilleattwater4760
@nevilleattwater4760 Ай бұрын
thanks for sharing and I hope you enjoy your trip! If we wanted to target a small group for testing, Bitlocker is applied at the device group level, not a user level? And if the policy fails to apply, do you have any troubleshooting tips?
@RTB1910
@RTB1910 Ай бұрын
Can I use the same settings in a hybrid environment?
@AndySaxton-z3d
@AndySaxton-z3d Ай бұрын
Hi Jonathan, great informative video as always, have followed your setup, but am getting a Conflict for Choose drive encryption method and cipher strength (Windows 10 (Version 1511) and later and Require additional authentication at startup, what would you advise please ?
@bearded365guy
@bearded365guy Ай бұрын
Do you have any other bitlocker policies configured? Security baselines etc?
@SamuelLaguisma
@SamuelLaguisma Ай бұрын
Nice to see you in Makati.
@bearded365guy
@bearded365guy Ай бұрын
Do you live in the Philippines?
Ай бұрын
nice video - Bitlocker is not available in home editions of windows 10 / 11 - so I just use the built in disk encryption feature thats in my dell bios
@bearded365guy
@bearded365guy Ай бұрын
That’s true, it isn’t.
@davidadams421
@davidadams421 Ай бұрын
Home editions of Win10/11 do come with a 'bitlocker light' of sorts, it's just called 'device encryption' and can be enabled in settings. It has the same pre-requisites as bitlocker. It's an on/off thing, though, no configuration options.
@sarahjarbou4697
@sarahjarbou4697 3 күн бұрын
Hi Jonathan, very helpful demo, a quick question though, if bitlocker policy was previously deployed on devices that were "Hybrid Joined Devices" and now are "Entra joined devices", the encryption is there, but the lock icon on the drive shows unlocked, should we in this case push the policy again, or manually re-enable the encryption after the device has been disconnected from a local active directory and joined through Entra.
@bearded365guy
@bearded365guy 2 күн бұрын
@@sarahjarbou4697 So the devices are still encrypted?
@mrwaeta1
@mrwaeta1 Ай бұрын
thank you , great content . Quick question here . I have had a project where my clients wanted to have machines required to enter the PIN during boot. I have done some research and learnt that Intune does not support that out of the box and you might need to do some PowerShell to handle that through scripts and remediation's. DO you think this is possible with just Intune? can you do a Video for that?
@bearded365guy
@bearded365guy Ай бұрын
@@mrwaeta1 Mmmmm. My thinking was Intune could support it, but it wouldn’t be a silent configuration….
@mrwaeta1
@mrwaeta1 Ай бұрын
@@bearded365guy yap thats what I thought too , only to realize it does only silent encryption, you cnt force users to set PIN’s with it , hopefully MS sorts this out
@jon4715
@jon4715 Ай бұрын
So you don’t recommend removable data drives be used in a secure environment, but why not enable the security protections here? Do you have another policy to disable their use? And do you allow admins the ability to use usb keys for things creating driver disks and windows 11 installer keys?
@bearded365guy
@bearded365guy Ай бұрын
@@jon4715 I am actually working on next weeks video which is about device control….. watch out for that.
@jon4715
@jon4715 Ай бұрын
@@bearded365guy Thanks, looking forward to it!
@jon4715
@jon4715 Ай бұрын
will the endpoint policy overwrite encryption policies located elsewhere? and is there a way to upgrade 128 to 256 encryption on an already encrypted endpoint?
@bearded365guy
@bearded365guy Ай бұрын
@@jon4715 Check out this script from Nathan Hutchinson - github.com/NateHutch365/Microsoft-Intune/tree/main/Windows/Platform%20Scripts/BitLocker%20decryption
@arthurascalon3867
@arthurascalon3867 Ай бұрын
Can't believed you're in the Philippines. Are you stationed there or a company hired you?
@bearded365guy
@bearded365guy Ай бұрын
Hi, we have a small team here so I came to visit them. Are you based here too? We are always recruiting.
@SonnyLearnsToRock
@SonnyLearnsToRock Ай бұрын
YEAHHHHHHHHHHHHHHHHHHHHHHHHH
@technful
@technful Ай бұрын
BitLocker creates way more problems than it
@bearded365guy
@bearded365guy Ай бұрын
What do you use for encryption?
Windows Autopilot V2? Or just a new profile type? Who cares! It's here!
12:11
How to Manage Personal Smartphones in Microsoft 365
14:12
Jonathan Edwards
Рет қаралды 22 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Леон киллер и Оля Полякова 😹
00:42
Канал Смеха
Рет қаралды 4,7 МЛН
Breaking Bitlocker - Bypassing the Windows Disk Encryption
9:11
stacksmashing
Рет қаралды 1 МЛН
Microsoft 365 SPF, DKIM and DMARC; Improve Your Email Security!
17:37
Jonathan Edwards
Рет қаралды 73 М.
TOP 5 Microsoft 365 Sensitivity Labels for Data Protection
26:58
Jonathan Edwards
Рет қаралды 19 М.
Secure Your Devices with Defender for Endpoint - Part 1
37:05
Jonathan Edwards
Рет қаралды 13 М.
7 HIDDEN Apps in Microsoft 365 that will EXPLODE Productivity
28:35
Jonathan Edwards
Рет қаралды 352 М.
Why I (No Longer) Avoid BitLocker
11:19
Ask Leo!
Рет қаралды 36 М.
BOOST Your Microsoft 365 Security with LAPS in Intune
9:02
Jonathan Edwards
Рет қаралды 12 М.
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 856 М.
Правильный подход к детям
00:18
Beatrise
Рет қаралды 11 МЛН