Enabling BitLocker
Using BitLocker allows Ivanti EPMM administrators to encrypt data on Windows 10 Desktop devices and prevent the ability to copy data from a removable drive (such as a USB stick) to a fixed device and vice versa. Administrator create rules to enable BitLocker on Windows 10 Desktop devices to:
-
Encrypt devices
-
Enable USB sticks
-
Enable removable drives
-
Recover stored AD password
-
Recover a password from either AD or Ivanti EPMM
Before you begin
Enable Bridge. See Setting up Bridge for details.
Procedure
-
Log into the Admin Portal.
-
Go to Policies & Configs > Policies.
-
Select the Default Security Policy link and then select Edit in the Policy Details panel.
-
In the Data Encryption section, select On for Data Encryption to enforce the device password option.
-
In the For Windows 10 Desktop section, select Bit Locker On to enable it.
-
Make your configuration settings, referring to the Enable BitLocker fields table for details.
-
Select Save.
The encryption process begins after restarting the device. Depending on the size of the drive, the device can take anywhere from 45 minutes or longer to finish encrypting the device. This is a background process and does not interfere with the users. When a device is not encrypted it is shown out of compliance with Ivanti EPMM until the encryption process is finished.
Bit Locker data encryption
The following table summarizes fields and descriptions for enabling Bit Locker: