F5F Stay Refreshed Software Operating Systems Advanced Business Features for Windows 10 Security

Advanced Business Features for Windows 10 Security

Advanced Business Features for Windows 10 Security

Pages (2): 1 2 Next
L
LuisJavierMc
Member
71
06-18-2016, 05:44 PM
#1
Hey there, I see you're tackling a big project with your team. You have around 3,500 Windows 10 machines, all connected via AD and SCCM. You're thinking about adding BitLocker and multi-factor authentication for Windows logins. It sounds like you're aiming for something secure but practical. I'm not aware of any specific solutions that match exactly what you're describing, but there are a few options worth exploring—like integrating YubiKey or Duo for stronger authentication, or looking into Windows Defender Multi-Factor Authentication. Have a look at those and let me know what you find!
L
LuisJavierMc
06-18-2016, 05:44 PM #1

Hey there, I see you're tackling a big project with your team. You have around 3,500 Windows 10 machines, all connected via AD and SCCM. You're thinking about adding BitLocker and multi-factor authentication for Windows logins. It sounds like you're aiming for something secure but practical. I'm not aware of any specific solutions that match exactly what you're describing, but there are a few options worth exploring—like integrating YubiKey or Duo for stronger authentication, or looking into Windows Defender Multi-Factor Authentication. Have a look at those and let me know what you find!

B
BJ_Cobble
Junior Member
15
06-18-2016, 11:51 PM
#2
They implement that method in a Dutch bank. You need to enter the password and insert the card.
B
BJ_Cobble
06-18-2016, 11:51 PM #2

They implement that method in a Dutch bank. You need to enter the password and insert the card.

L
LOLMASTER12359
Junior Member
12
06-19-2016, 02:10 PM
#3
Your W10 devices with a TPM support Bitlocker effectively. If not, you can still implement it using a flash drive, though this isn't the most convenient setup. You can add PIN prompts at startup (it seems to be set to ask only when disconnected or every time), and store recovery keys and related data in your Active Directory with group policies. For more details, refer to the official guide: https://docs.microsoft.com/en-us/windows...r-overview
L
LOLMASTER12359
06-19-2016, 02:10 PM #3

Your W10 devices with a TPM support Bitlocker effectively. If not, you can still implement it using a flash drive, though this isn't the most convenient setup. You can add PIN prompts at startup (it seems to be set to ask only when disconnected or every time), and store recovery keys and related data in your Active Directory with group policies. For more details, refer to the official guide: https://docs.microsoft.com/en-us/windows...r-overview

S
Skyguy_
Member
228
06-19-2016, 03:58 PM
#4
Not familiar with BitLocker currently, but we used it around 2012—it was really bad. I’ve heard some improvements have been made, but be sure to do thorough testing, especially careful checks (I don’t remember much now, my laptop is locked).
S
Skyguy_
06-19-2016, 03:58 PM #4

Not familiar with BitLocker currently, but we used it around 2012—it was really bad. I’ve heard some improvements have been made, but be sure to do thorough testing, especially careful checks (I don’t remember much now, my laptop is locked).

Q
QueenLittle
Junior Member
18
06-23-2016, 06:16 AM
#5
The administrators possess recovery keys that allow them to reinitialize BitLocker.
Q
QueenLittle
06-23-2016, 06:16 AM #5

The administrators possess recovery keys that allow them to reinitialize BitLocker.

Z
Zacherino5900
Member
120
06-23-2016, 07:28 AM
#6
Backup codes for early BitLocker were difficult to manage and often inconsistent, with each method varying. TPM chips helped resolve many of these issues. It was entirely feasible to lock a device without being able to unlock it at that time, which is why we chose not to include this feature then.
Z
Zacherino5900
06-23-2016, 07:28 AM #6

Backup codes for early BitLocker were difficult to manage and often inconsistent, with each method varying. TPM chips helped resolve many of these issues. It was entirely feasible to lock a device without being able to unlock it at that time, which is why we chose not to include this feature then.

F
FLARE524
Junior Member
16
06-23-2016, 11:01 AM
#7
Recovery keys can be saved automatically to your AD, and it seems we also keep their PIN somewhere in that system.
F
FLARE524
06-23-2016, 11:01 AM #7

Recovery keys can be saved automatically to your AD, and it seems we also keep their PIN somewhere in that system.

U
UndeadRainbowz
Junior Member
1
06-25-2016, 05:46 AM
#8
Do you have any insights or practical experience with Sophos Safeguard Encryption?
U
UndeadRainbowz
06-25-2016, 05:46 AM #8

Do you have any insights or practical experience with Sophos Safeguard Encryption?

R
raphiez
Junior Member
19
07-02-2016, 12:38 AM
#9
Also checking if you want to strengthen the networking aspects? Consider adding RADIUS/Wired Auth/802.1x to restrict computer or device access until proper authentication is completed.
R
raphiez
07-02-2016, 12:38 AM #9

Also checking if you want to strengthen the networking aspects? Consider adding RADIUS/Wired Auth/802.1x to restrict computer or device access until proper authentication is completed.

M
Markok
Junior Member
20
07-05-2016, 05:58 AM
#10
I don't have any connection with the networking team. I focus exclusively on the desktop environment side. Appreciate the assistance!
M
Markok
07-05-2016, 05:58 AM #10

I don't have any connection with the networking team. I focus exclusively on the desktop environment side. Appreciate the assistance!

Pages (2): 1 2 Next