COnfignoobie
-
Total Posts
:
218
- Scores: 4
-
Reward points
:
27070
- Joined: 1/19/2010
- Location: Denver, Co
-
Status: offline
|
Bitlocker MBAM question
Wednesday, July 18, 2012 9:34 PM
( permalink)
Silly question.. but I've never done it before. I've got to install Microsoft BitLocker Administration and Monitoring and get it running. I'm sure someone here has done it before. I'm curious about the security required. When I'm running the installer, I assume that while installing the servers, I will need to be a local admin on the servers. But what rights might I need in AD? For example, when a policy is defined on the template system, does the user need to be a domain admin? How does the MBAM system get the policies to apply to AD? I just wasn't sure what rights the person running the installers needs to have. But I'm guessing he/she needs domain admin. Many thanks!
|
|
|
|
rtruss
-
Total Posts
:
505
- Scores: 35
-
Reward points
:
31950
- Joined: 11/4/2004
- Location: Oshkosh, WI
-
Status: offline
|
Re:Bitlocker MBAM question
Thursday, July 19, 2012 9:12 AM
( permalink)
Roger Truss Windows Administrator SCCM Admin MDT Admin Kaspersky Admin :( If you find someones post helpful please let them know by rating them. ;)
|
|
|
|
COnfignoobie
-
Total Posts
:
218
- Scores: 4
-
Reward points
:
27070
- Joined: 1/19/2010
- Location: Denver, Co
-
Status: offline
|
Re:Bitlocker MBAM question
Thursday, July 19, 2012 1:39 PM
( permalink)
Yeah, I've already seen that one. Since you've installed this.. let me ask this. If I understand that architecture right, having the MBAM servers on a 'high availability' status isn't that important. If my servers go down for a bit my MBAM Client will just sit and wait until it can reach the mbam admin site and update it's policies. It looks like the mbam client works not unlike the sccm client in that it needs to reach the mbam admin systems prior to executing any changes. Am I correct? (for example, if the MBAM servers are down, but the machine is on AD and GPO says to encrypt, will it still encrypt immediately or will it wait for the MBAM server to come back up to verify hardware etc is approved?) Also, have you had any problems with people on the road with a MBAM implementation? (bit locker to go)
|
|
|
|
jeffgilb
-
Total Posts
:
4
- Scores: 2
-
Reward points
:
5810
- Joined: 7/31/2012
- Location: Boston, MA
-
Status: offline
|
Re:Bitlocker MBAM question
Tuesday, July 31, 2012 1:56 PM
( permalink)
MBAM was designed to be fault tolerant when a server is down so when that happens, users aren't prompted for action. You can also configure the Administration and Monitoring server to use a network load balancing cluster for additional fault tolerance to ensure the web services are available to provide recovery keys in case one needs to be offline.
|
|
|
|
rtruss
-
Total Posts
:
505
- Scores: 35
-
Reward points
:
31950
- Joined: 11/4/2004
- Location: Oshkosh, WI
-
Status: offline
|
Re:Bitlocker MBAM question
Tuesday, July 31, 2012 2:11 PM
( permalink)
That is a good question. We have not run into that yet, we have only just begun to deploy this. As to the people on the road, most of the ones we are deploying too are laptops and thus I have not heard of report where it fails in that regard. The bitlocker to go is for USB removable drives and has no bearing on whether a system is internal or external and we are not implementing that.
Roger Truss Windows Administrator SCCM Admin MDT Admin Kaspersky Admin :( If you find someones post helpful please let them know by rating them. ;)
|
|
|
|
rtruss
-
Total Posts
:
505
- Scores: 35
-
Reward points
:
31950
- Joined: 11/4/2004
- Location: Oshkosh, WI
-
Status: offline
|
Re:Bitlocker MBAM question
Tuesday, July 31, 2012 2:11 PM
( permalink)
Ugh..this was a dupe sorry. WIN8 and IE 10 hiccup there.
Roger Truss Windows Administrator SCCM Admin MDT Admin Kaspersky Admin :( If you find someones post helpful please let them know by rating them. ;)
|
|
|
|
dhedges
-
Total Posts
:
15
- Scores: 4
-
Reward points
:
20000
- Joined: 9/30/2009
- Location: Austin, TX
-
Status: online
|
Re:Bitlocker MBAM question
Tuesday, September 18, 2012 12:54 PM
( permalink)
Hi Jeff, Are there any specific instructions/configurations needed for using a NLB? I've got everything setup on a single server already but want to move to a NLB setup. Thanks, Dustin
|
|
|
|
jeffgilb
-
Total Posts
:
4
- Scores: 2
-
Reward points
:
5810
- Joined: 7/31/2012
- Location: Boston, MA
-
Status: offline
|
Re:Bitlocker MBAM question
Thursday, September 20, 2012 2:40 PM
( permalink)
Hi Dustin, There are no specific instructions on this out there (yet), but the process is pretty straightforward. You just install the administration and monitoring server bits on the servers that will be in the NLB, configure them to work in an NLB, and then modify the GPO settings to point clients to the NLB name for the MBAM services endpoint. I'm actually planning to blog this process in my lab, but haven't finished it yet. I'll link to that from this series when I'm finished though: myitforum.com/myitforumwp/2012/08/16/how-to-configure-an-nlb-in-hyper-v-part-1/ .
<message edited by jeffgilb on Thursday, September 20, 2012 2:42 PM>
|
|
|
|