

I will use a Configuration Baseline (CB) to determine this and also to find the computers that are not ready to encrypt the disks.ĭuring this How-to there might be some changes you need to perform in your SCCM environment but they are minor and shouldn’t be an issue for you. First off we need to find out which computers require BitLocker and if they are ready to be enabled. In this case, I will use SCCM and a Task Sequence to enable BitLocker. TPM is a hardware component that is installed by the manufacturer and can be used to ensure that the computers have not been tampered with while the computer was powered off.

This can easily be done during OS installation for all new computers but it might be troublesome to enable BitLocker on existing devices.īitLocker can use multiple key information methods but in this case, I will focus on TPM. A big part of this is to encrypt the disks of their devices using BitLocker. All businesses want to protect their data to make sure it is safe from unauthorized users.
