Setup and configure Bit locker network unlock remotely

%3CLINGO-SUB%20id%3D%22lingo-sub-1557023%22%20slang%3D%22en-US%22%3ESetup%20and%20configure%20Bit%20locker%20network%20unlock%20remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1557023%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Fellow%20members%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20a%20question%20for%20anyone%20who%20has%20setup%20and%20configured%20the%20Bitlocker%20network%20unlock%20feature.%20I%20have%20been%20asked%20to%20set%20this%20up%20in%20my%20enterprise%20however%20with%20COVID-19%20I%20am%20working%20remotely.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20anyone%20who%20has%20done%20this%20already%2C%20is%20it%20possible%20to%20do%20all%20the%20configuration%20and%20testing%20of%20this%20remotely%20or%20will%20I%20need%20to%20be%20in%20the%20office%3F%20I%20am%20thinking%20that%20whilst%20the%20server%20configuration%20I%20could%20do%20remotely%2C%20my%20question%20would%20be%20how%20would%20I%20test%20it%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20I%20will%20be%20following%20this%20article%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fbitlocker%2Fbitlocker-how-to-enable-network-unlock%23%3A~%3Atext%3D%2520Configure%2520Network%2520Unlock%2520%25201%2520Install%2520the%2Cproperly%2520configured%2520Active%2520Directory%2520Services%2520Certification...%2520More%2520%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fbitlocker%2Fbitlocker-how-to-enable-network-unlock%23%3A~%3Atext%3D%2520Configure%2520Network%2520Unlock%2520%25201%2520Install%2520the%2Cproperly%2520configured%2520Active%2520Directory%2520Services%2520Certification...%2520More%2520%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20thoughts%20on%20this%20would%20be%20most%20appreciated.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1557023%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Ebitlocker%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1578116%22%20slang%3D%22en-US%22%3ERe%3A%20Setup%20and%20configure%20Bit%20locker%20network%20unlock%20remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1578116%22%20slang%3D%22en-US%22%3E%3CP%3EGot%20a%20question%20around%20Bitlocker%26nbsp%3B%20Network%20Unlock.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThought%20first%20it%20be%20useful%20to%20add%20some%20details%20of%20the%20infrastructure%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2008%20R2%20Domain%20controllers....Yes%20I%20know!%26nbsp%3B%3C%2FP%3E%3CP%3EWindows%20based%20PKI%20infrastructure%3C%2FP%3E%3CP%3EServer%202019%20running%20Windows%20Deployment%20services%3C%2FP%3E%3CP%3E%3CSPAN%3EUsing%20MBAM.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EBitlocker%20256-bit%20encryption%20used%20with%20startup%20PIN%26nbsp%3B%3C%2FP%3E%3CP%3EWindows%2010%20Enterprise%2C%20managed%20using%20Microsoft%20Configuration%20Endpoint%20Manager%201910%3C%2FP%3E%3CP%3ESo%20after%20a%20successful%20implementation%20of%20BitLocker%2C%20we%20now%20want%20to%20move%20to%20the%20next%20stage%20of%20implementing%20network%20unlock%20on%20machines%20on%20the%20internal%20network.%26nbsp%3B%3C%2FP%3E%3CP%3EFollowed%20this%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fbitlocker%2Fbitlocker-how-to-enable-network-unlock%23bkmk-unsupportedsystems%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fbitlocker%2Fbitlocker-how-to-enable-network-unlock%23bkmk-unsupportedsystems%3C%2FA%3E%3C%2FP%3E%3CP%3EAll%20configuration%20on%20server%20side%20complete%2C%20certificate%20is%20valid%20and%20on%20the%20client.%20BitLocker%20config%20currently%20performed%20by%20MCEM%20at%20OSD.%20additional%20policies%20set%20within%20GPO%20including%20network%20unlock%20set%20to%20enabled.%20Running%20manage-bde%20status%20shows%20Network%20(certificate%20based)%20key%20protector%20with%20correct%20certificate%20thumbprint%20and%20is%20also%20show%20in%20registry.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20anyone%20have%20any%20experience%20with%20network%20unlock.%20Whilst%20the%20core%20requirements%20are%20Windows%202012%20I%20understand%20this%20is%20for%20the%20WDS%20server%20which%20is%20server%202019%20and%20you%20can%20still%20use%20this%20with%202008%20DCs%20as%20mentioned%20in%20the%20article%20but%20struggling%20to%20understand%20why%20it%20still%20doesnt%20work.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20tried%20the%20implementation%20on%20both%20a%20desktop%20and%20laptop%2C%20the%20laptop%20doesn't%20have%20an%20onboard%20network%20card%20(as%20most%20new%20thin%20laptops)%20and%20has%20to%20use%20an%20ethernet%20adapter%2C%20all%20the%20requirements%20on%20client%20side%20have%20been%20met%20such%20as%20TPM%2C%20native%20mode%20etc%20so%20should%20still%20work%20and%20is%20able%20to%20PXE%20boot%20successfully%20for%20OSD%20build.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAny%20suggestions%20would%20be%20greatly%20appreciated.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi Fellow members

 

This is a question for anyone who has setup and configured the Bitlocker network unlock feature. I have been asked to set this up in my enterprise however with COVID-19 I am working remotely. 

 

For anyone who has done this already, is it possible to do all the configuration and testing of this remotely or will I need to be in the office? I am thinking that whilst the server configuration I could do remotely, my question would be how would I test it? 

 

So I will be following this article: https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-how-to-...

 

Any thoughts on this would be most appreciated.


Thanks

 

1 Reply

Got a question around Bitlocker  Network Unlock.

 

Thought first it be useful to add some details of the infrastructure

 

2008 R2 Domain controllers....Yes I know! 

Windows based PKI infrastructure

Server 2019 running Windows Deployment services

Using MBAM.

Bitlocker 256-bit encryption used with startup PIN 

Windows 10 Enterprise, managed using Microsoft Configuration Endpoint Manager 1910

So after a successful implementation of BitLocker, we now want to move to the next stage of implementing network unlock on machines on the internal network. 

Followed this article https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-how-to-...

All configuration on server side complete, certificate is valid and on the client. BitLocker config currently performed by MCEM at OSD. additional policies set within GPO including network unlock set to enabled. Running manage-bde status shows Network (certificate based) key protector with correct certificate thumbprint and is also show in registry. 

 

Does anyone have any experience with network unlock. Whilst the core requirements are Windows 2012 I understand this is for the WDS server which is server 2019 and you can still use this with 2008 DCs as mentioned in the article but struggling to understand why it still doesnt work. 

 

I have tried the implementation on both a desktop and laptop, the laptop doesn't have an onboard network card (as most new thin laptops) and has to use an ethernet adapter, all the requirements on client side have been met such as TPM, native mode etc so should still work and is able to PXE boot successfully for OSD build.

 

Any suggestions would be greatly appreciated. 

www.000webhost.com