Advanced Business Features for Windows 10 Security
Advanced Business Features for Windows 10 Security
Hey there, I see you're tackling a big project with your team. You have around 3,500 Windows 10 machines, all connected via AD and SCCM. You're thinking about adding BitLocker and multi-factor authentication for Windows logins. It sounds like you're aiming for something secure but practical. I'm not aware of any specific solutions that match exactly what you're describing, but there are a few options worth exploring—like integrating YubiKey or Duo for stronger authentication, or looking into Windows Defender Multi-Factor Authentication. Have a look at those and let me know what you find!
Your W10 devices with a TPM support Bitlocker effectively. If not, you can still implement it using a flash drive, though this isn't the most convenient setup. You can add PIN prompts at startup (it seems to be set to ask only when disconnected or every time), and store recovery keys and related data in your Active Directory with group policies. For more details, refer to the official guide: https://docs.microsoft.com/en-us/windows...r-overview
The administrators possess recovery keys that allow them to reinitialize BitLocker.
Backup codes for early BitLocker were difficult to manage and often inconsistent, with each method varying. TPM chips helped resolve many of these issues. It was entirely feasible to lock a device without being able to unlock it at that time, which is why we chose not to include this feature then.
Do you have any insights or practical experience with Sophos Safeguard Encryption?