MBAM Fixed drive encryption problem

Ortac Demirel 1 Reputation point
2020-11-08T10:15:14.107+00:00

Hello,

I use MBAM server.

client version mbam 2.5 sp1 and os are windows 10 1909 enterprise.

OS drive successfully encrypted automatically . I have problem with fixed drive. Fixed drive encryption can not start automatically.

My fixed drive GPO:

choose how BitLocker-protected fixed drives can be recovered Enabled
Allow data recovery agent Enabled
Omit recovery options from the BitLocker setup wizard Enabled
Save BitLocker recovery information to AD DS for fixed data drives Enabled
Configure storage of BitLocker recovery information to AD DS: Backup recovery passwords and key packages
Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives Disabled

Configure use of passwords for fixed data drives Disabled

Encryption Policy Enforcement Settings Enabled
Configure the number of noncompliance grace period days for fixed drives. This grace period begins only after the operating system drive compliance is detected: 0

Fixed data drive encryption settings Enabled

Configure Auto-Unlock for fixed data drive: Allow Auto-Unlock

When I check gpo from client , I can see only "choose how BitLocker-protected fixed drives can be recovered" and "Configure Auto-Unlock for fixed data drive:" settings .

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,752 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dale Kudusi 3,206 Reputation points
    2020-11-09T07:30:40.643+00:00

    Hi,
    Might try using the following command in the elevated command prompt to refresh client GPO settings so they can be applied on clients:
    gpupdate /force

    then reboot.

    Best regards.

    **
    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Christian 21 Reputation points MVP
    2021-03-18T00:26:56.257+00:00

    Hello,

    If the policies are correctly configured and linked, it should not take so long to start encrypting. Also, try to compliance the report to determine the encryption status by using any of these commands.

    • manage-bde -status or
    • Get-BitLockerVolume

    Please check to ensure that the PCs are part of the OU and the BitLocker and MBAM policies are configured correctly.

    Saw you also configured auto-unlock. Double-check with these links for your needed BitLocker policies

    This last link will also help you in ensuring your policies are correctly configured and aligned.

    If these procedures helped you in any way, please click on "It solved my problem" and also mark it as an answer, so you can help other users.


  3. Christian 21 Reputation points MVP
    2021-03-19T02:56:54.31+00:00

    Hi OrtacDemirel-7821,

    I had to set up MBAM in order to outline the steps for your deployment. I hope this guide helps.

    0 comments No comments

  4. Pavel yannara Mirochnitchenko 11,711 Reputation points
    2021-04-13T20:14:41.8+00:00

    Remember to check MBAM client logs in Event Viewer / Applications. If your GPO is set right, but there is a some problem, you should understand it from those logs.