

This can be done by simply docking the system’s HDD onto another computer to browse the file system. With traditionally unencrypted disks (the vast majority of the world’s computers), perpetrators could extract all of the data available on the local disk. BitLocker allows for the encryption of drives on the system, as a layer of security. “Physical Presence for Provisioning” is Disabled – In Bios\firmwareīitLocker is a free encryption feature in Windows that comes standard on most versions of Windows (specific requirements listed above).Lenovo\Dell\any big name box systems with remote Bios manageability – Not required, but useful.TPM 1.2 or greater – Required, no chance of automation without this.Any Endpoint Management Server – SCCM, Kace, LanDesk, etc….Windows Server 2008 domain functional Level or higher.

Life Cycle Management with Sample Scripts.Machines with TPM Installed, and Enabled.Active Directory Functional Level for Recovery Keys.Difficulty Level: Intermediate\Advanced Outline
