Share via

SCCM - Bitlocker Management

Carmine Panza 41 Reputation points
2021-01-16T13:14:59.873+00:00

Hello,
I will have to implement bitlocker management with SCCM 2002, the infrastructure consists of 1 Primary Site with 10 Management Point configured in HTTP, clients use self-signed certificates.
I saw that with the SCCM 2002 version it's possible to activate HTTPS only on the site hosting the bitlocker recovery service and not on the MPs, so the certificate must be installed on all 10 MPs and configured only on the recovery site? Can clients continue to use self-signed certificate and MP communication over HTTP?
Thanks

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments

Answer accepted by question author

AllenLiu-MSFT 49,441 Reputation points Microsoft External Staff
2021-01-18T07:58:07.99+00:00

@El3ttriko-5155
Thank you for posting in Microsoft Q&A forum.
If we don't have a management point with an HTTPS-enabled website, we can not use recovery service, Configuration Manager doesn't save key recovery information.

The Client connections property of the management point can be HTTP or HTTPS. If the management point is configured for HTTP, to support the BitLocker recovery service:

  1. Acquire a server authentication certificate. Bind the certificate to the IIS website on the management point that hosts the BitLocker recovery service.
  2. Configure clients to trust the server authentication certificate.

For more details about HTTPS-enable the IIS website, you may refwer to:
https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/bitlocker/encrypt-recovery-data-transit#https-enable-the-iis-website


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.