Editing the MBAM 2.5 Group Policy Settings

To successfully deploy Microsoft BitLocker Administration and Monitoring (MBAM), you have to:

Task More information

Copy the MBAM 2.5 Group Policy Templates.

Copying the MBAM 2.5 Group Policy Templates

Determine which Group Policy Objects (GPOs) you want to use in your MBAM implementation. Based on the needs of your organization, you might have to configure additional Group Policy settings.

Planning for MBAM 2.5 Group Policy Requirements – contains descriptions of the GPOs

Set the Group Policy settings for your organization.

Important   Do not change the Group Policy settings in the BitLocker Drive Encryption node, or MBAM will not work correctly. When you configure the Group Policy settings in the MDOP MBAM (BitLocker Management) node, MBAM automatically configures the BitLocker Drive Encryption settings for you.

To edit MBAM Client Group Policy settings

  1. On a computer that has the MBAM Group Policy Templates installed, make sure that MBAM Services are enabled.

  2. Using the Group Policy Management Console (GPMC.msc) or the Microsoft Advanced Group Policy Management MDOP product on a computer with the MBAM Group Policy Templates installed, select Computer configuration > Policies > Administrative Templates > Windows Components > MDOP MBAM (BitLocker Management).

  3. Edit the Group Policy settings that are required to enable MBAM Client services on client computers. For each policy in the following table, select Policy Group, click the Policy you want, and then configure the settings.

    Policy Group Policy

    Client Management

    Configure MBAM Services

    Operating System Drive

    Operating system drive encryption settings

    Removable Drive

    Control use of BitLocker on removable drives

    Fixed Drive

    Control use of BitLocker on fixed drives

Planning for MBAM 2.5 Group Policy Requirements

Copying the MBAM 2.5 Group Policy Templates

Got a suggestion for MBAM?

For MBAM issues, use the MBAM TechNet Forum.