Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

4
BitLocker & MBR partition debacle
Post Flair (click to view more posts with a particular flair)
Post Body

Mostly posting this to see if anyone has any ideas/suggestions that I have not thought of or may not know of.

Context: I am a solo sys admin with about 175 users, all running Windows 10 Lenovo based thinkpad machines(T,X,P series) about half are older(2-4 years old) and half newly purchased within 1-2 years. We are normally in offices, but are remote due to covid. Recently the company has started venturing towards a SOC II security compliance. A part of working towards this compliance is getting employee machines encrypted. (In our case via BitLocker)

The debacle: Since we are all remote I had created a powershell script to run via our RMM (that has the ability to remote execute Powershell.) The script is for initializing BitLocker, exporting the keys, all that good stuff. I am running into issues and finding out about half of the machines are using a tpm 2.0 chips, but have MBR boot partitions. This brings a problem as tpm 2.0 only works with GPT boot partitions. So I am not able to encrypt about half the machines via BitLocker.

Methods I have thought to try: -Using MBR2GPT to manually convert each end users machine to GPT. -Downgrade 2.0 tpms via BIOS to 1.2 so the MBR partition will work for BitLocker. Done manually.( This seems to only apply to specific models of Lenovo PCs) -looked into Lenovo's WMI capabilities so see if downgrading tpms can be done via WMI.

So my question comes in: Is there any other obvious method I am over looking? What would other sysadmins recommend? (I am trying to figure out the option to make it as easy as possible for the end users).

Any info or recommendations are greatly appreciated :)

Edit: I am trying to figure out how to solve the issue for all the PCs with Tpm 2.0 and a MBR partition.(As tpm 2.0 only works with UEFI aka GPT partition)

Author
Account Strength
100%
Account Age
12 years
Verified Email
Yes
Verified Flair
No
Total Karma
29,462
Link Karma
26,709
Comment Karma
2,653
Profile updated: 1 week ago
Posts updated: 1 year ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
3 years ago