Bitlocker MBAM question

Author Message
COnfignoobie

  • Total Posts : 218
  • Scores: 4
  • Reward points : 27070
  • Joined: 1/19/2010
  • Location: Denver, Co
  • Status: offline
Bitlocker MBAM question Wednesday, July 18, 2012 9:34 PM (permalink)
0
Silly question.. but I've never done it before.
 
I've got to install Microsoft BitLocker Administration and Monitoring and get it running.  I'm sure someone here has done it before.  I'm curious about the security required.
 
When I'm running the installer, I assume that while installing the servers, I will need to be a local admin on the servers.  But what rights might I need in AD?  For example, when a policy is defined on the template system, does the user need to be a domain admin?  How does the MBAM system get the policies to apply to AD?  I just wasn't sure what rights the person running the installers needs to have.  But I'm guessing he/she needs domain admin.
 
Many thanks!
 
 
 
#1
    rtruss

    • Total Posts : 505
    • Scores: 35
    • Reward points : 31950
    • Joined: 11/4/2004
    • Location: Oshkosh, WI
    • Status: offline
    Re:Bitlocker MBAM question Thursday, July 19, 2012 9:12 AM (permalink)
    0
    When creating a policy you simply need the appropriate rights to create and assign policy.  I am not a domain admin but I am a GPO admin and MBAM admin (we are just now expanding our MBAM POC).  You will need to import the appropriate MBAM policies to AD for the clients t oget MBAM to work properly.
     
    Here is a good resource for MBAM, ifyou have not seen it already.
    http://technet.microsoft.com/en-us/video/microsoft-bitlocker-administration-and-monitoring-mbam.aspx
    Roger Truss
    Windows Administrator
    SCCM Admin
    MDT Admin
    Kaspersky Admin :( 

    If you find someones post helpful please let them know by rating them. ;)
     
    #2
      COnfignoobie

      • Total Posts : 218
      • Scores: 4
      • Reward points : 27070
      • Joined: 1/19/2010
      • Location: Denver, Co
      • Status: offline
      Re:Bitlocker MBAM question Thursday, July 19, 2012 1:39 PM (permalink)
      0
      Yeah, I've already seen that one.
      Since you've installed this.. let me ask this.  If I understand that architecture right, having the MBAM servers on a 'high availability' status isn't that important.  If my servers go down for a bit my MBAM Client will just sit and wait until it can reach the mbam admin site and update it's policies.  It looks like the mbam client works not unlike the sccm client in that it needs to reach the mbam admin systems prior to executing any changes.  Am I correct?  (for example, if the MBAM servers are down, but the machine is on AD and GPO says to encrypt, will it still encrypt immediately or will it wait for the MBAM server to come back up to verify hardware etc is approved?)
       
      Also, have you had any problems with people on the road with a MBAM implementation?  (bit locker to go)
       
      #3
        jeffgilb

        • Total Posts : 4
        • Scores: 2
        • Reward points : 5810
        • Joined: 7/31/2012
        • Location: Boston, MA
        • Status: offline
        Re:Bitlocker MBAM question Tuesday, July 31, 2012 1:56 PM (permalink)
        0
        MBAM was designed to be fault tolerant when a server is down so when that happens, users aren't prompted for action. 
         
        You can also configure the Administration and Monitoring server to use a network load balancing cluster for additional fault tolerance to ensure the web services are available to provide recovery keys in case one needs to be offline. 
         
        #4
          rtruss

          • Total Posts : 505
          • Scores: 35
          • Reward points : 31950
          • Joined: 11/4/2004
          • Location: Oshkosh, WI
          • Status: offline
          Re:Bitlocker MBAM question Tuesday, July 31, 2012 2:11 PM (permalink)
          0
          That is a good question.  We have not run into that yet, we have only just begun to deploy this.  As to the people on the road, most of the ones we are deploying too are laptops and thus I have not heard of report where it fails in that regard.  The bitlocker to go is for USB removable drives and has no bearing on whether a system is internal or external and we are not implementing that.
          Roger Truss
          Windows Administrator
          SCCM Admin
          MDT Admin
          Kaspersky Admin :( 

          If you find someones post helpful please let them know by rating them. ;)
           
          #5
            rtruss

            • Total Posts : 505
            • Scores: 35
            • Reward points : 31950
            • Joined: 11/4/2004
            • Location: Oshkosh, WI
            • Status: offline
            Re:Bitlocker MBAM question Tuesday, July 31, 2012 2:11 PM (permalink)
            0
            Ugh..this was a dupe sorry.  WIN8 and IE 10 hiccup there.
            Roger Truss
            Windows Administrator
            SCCM Admin
            MDT Admin
            Kaspersky Admin :( 

            If you find someones post helpful please let them know by rating them. ;)
             
            #6
              dhedges

              • Total Posts : 15
              • Scores: 4
              • Reward points : 20000
              • Joined: 9/30/2009
              • Location: Austin, TX
              • Status: online
              Re:Bitlocker MBAM question Tuesday, September 18, 2012 12:54 PM (permalink)
              0
              Hi Jeff, 
               
              Are there any specific instructions/configurations needed for using a NLB?  I've got everything setup on a single server already but want to move to a NLB setup.  
               
              Thanks, 
               
              Dustin
               
              #7
                jeffgilb

                • Total Posts : 4
                • Scores: 2
                • Reward points : 5810
                • Joined: 7/31/2012
                • Location: Boston, MA
                • Status: offline
                Re:Bitlocker MBAM question Thursday, September 20, 2012 2:40 PM (permalink)
                0
                Hi Dustin,
                 
                There are no specific instructions on this out there (yet), but the process is pretty straightforward. You just install the administration and monitoring server bits on the servers that will be in the NLB, configure them to work in an NLB, and then modify the GPO settings to point clients to the NLB name for the MBAM services endpoint. I'm actually planning to blog this process in my lab, but haven't finished it yet. I'll link to that from this series when I'm finished though: myitforum.com/myitforumwp/2012/08/16/how-to-configure-an-nlb-in-hyper-v-part-1/ .
                <message edited by jeffgilb on Thursday, September 20, 2012 2:42 PM>
                 
                Hope this helps,
                ~Jeff
                 
                #8
                  Online Bookmarks Sharing: Share/Bookmark

                  Jump to:

                  Current active users

                  There are 0 members and 2 guests.

                  Icon Legend and Permission

                  • New Messages
                  • No New Messages
                  • Hot Topic w/ New Messages
                  • Hot Topic w/o New Messages
                  • Locked w/ New Messages
                  • Locked w/o New Messages
                  • Read Message
                  • Post New Thread
                  • Reply to message
                  • Post New Poll
                  • Submit Vote
                  • Post reward post
                  • Delete my own posts
                  • Delete my own threads
                  • Rate post

                  2000-2013 ASPPlayground.NET Forum Version 3.9