Jump to content


Recommended Posts

I’ve been following the Bitlocker management tutorial here. Apart from the previous MBAM Install error over here, everything has gone as expected, apart from actual device encryption…..

I’ve configured everything as per the tutorial, I have a set of devices, I have the configuration base line to deploy the reg keys to force encryption to start, I’ve configured and deployed the policy to the machines. The clients have the MDOP client.

 

If I run “(Get-WmiObject -Class mbam_Volume -Namespace root\microsoft\mbam).ReasonsForNoncompliance” on any of the clients, I get the 3 codes returned, 1, 16 and 3. From here the error codes are as follows :

1              MBAM Policy requires this volume to be encrypted but it is not.

3              MBAM Policy requires this volume use a TPM protector, but it does not.

6              Policy requires minimum cypher strength is XTS-AES-256 bit, actual cypher strength is weaker than that.

The policy I configured in SCCM is XTS-AES-256, do I need to do something else? Configure a GPO maybe?

 

I wasn’t sure exactly what other detail to include so feel free to ask me for some logs etc.

Share this post


Link to post
Share on other sites

no GPO's needed, can you attach (or email me) the 2 bitlocker related logs in c:\windows\ccm\logs and can you do a teamviewer session so i can take a look ?

Share this post


Link to post
Share on other sites

Did you work this out? We've been encrypting with MBAM for a while now successfully, now we're having a rash of computers not encrypting because "actual cypher strength is weaker" and it's not clear what has changed.

Share this post


Link to post
Share on other sites

Hi Niall,

I have used your guides to implement SCCM MBAM 1910 and it went in successfully.  I am however facing an issue where the clients - even though they receive the policies and the registry change to encrypt without user action - I find that nothing happen until I manually run MBAMClientUI.exe.

I've even changed the MBAM Registry to implement "NoStartupDelay" and no joy.  I've had one or two successful when the MDOP client pops up but the rest just sit there.

Any advice is greatly appreciated and I look forward to hearing from you

Regards

Carl Davis

P.S - AMAZING GUIDES BTW - Thank you for taking the time to write and video

,

 

  • Like 1

Share this post


Link to post
Share on other sites
On 2/6/2020 at 3:06 PM, APd said:

Did you work this out? We've been encrypting with MBAM for a while now successfully, now we're having a rash of computers not encrypting because "actual cypher strength is weaker" and it's not clear what has changed.

My problems was/is that the SCCM Bitlocker policy could not be enforced...

What do the event logs say on both server and clients?

Share this post


Link to post
Share on other sites
6 minutes ago, Carl Davis said:

Hi Niall,

I have used your guides to implement SCCM MBAM 1910 and it went in successfully.  I am however facing an issue where the clients - even though they receive the policies and the registry change to encrypt without user action - I find that nothing happen until I manually run MBAMClientUI.exe.

I've even changed the MBAM Registry to implement "NoStartupDelay" and no joy.  I've had one or two successful when the MDOP client pops up but the rest just sit there.

Any advice is greatly appreciated and I look forward to hearing from you

Regards

Carl Davis

P.S - AMAZING GUIDES BTW - Thank you for taking the time to write and video

,

 

What do the event logs say on both server and clients?

Share this post


Link to post
Share on other sites
45 minutes ago, ukg_matt said:

 

Hi Matt, 

The MBAM logs on the event viewer keep repeating "Volume Enactment Successful and CoreService Up

Please see the attached from the clients....

 

Which event logs from the server do you need?  This is a site with multiple roles on multiple servers 🙂

 

Thank you

Capture.PNG

BitlockerManagement_GroupPolicyHandler.log

Share this post


Link to post
Share on other sites
19 minutes ago, Carl Davis said:

Hi Matt, 

The MBAM logs on the event viewer keep repeating "Volume Enactment Successful and CoreService Up

Please see the attached from the clients....

 

Which event logs from the server do you need?  This is a site with multiple roles on multiple servers 🙂

 

Thank you

Capture.PNG

BitlockerManagement_GroupPolicyHandler.log 24.65 kB · 0 downloads

What does the MBAM > Admin client log show?

The server event logs are 

Application and Service Logs > Microsoft > Windows > MBAM-Web > Admin

Application and Service Logs > Microsoft > Windows > MBAM-Web > Operational 

Share this post


Link to post
Share on other sites

what policy settings have you configured and have you verified the client is indeed in the collection where you deployed it ?

Share this post


Link to post
Share on other sites

Good day Niall and everyone, I just replied since its the same topic as what I'm getting but different error msg (not error msg actually). I just got some machines that is not compliant but this machines has the same specs as any compliant machines I have. 

image.thumb.png.9d29b4782483409120d90fcc8e382c41.png

Share this post


Link to post
Share on other sites

are you saying they are reporting as non compliant but are in fact, compliant ? if so have you installed the hotfix available for 1910 in the console ?

Share this post


Link to post
Share on other sites

I have just resolved something like this in my environment. I looked in the BitlockerManagement_GroupPolicyHandler.log and I found errors ' Failed to open GPO (0x80004005)', I googled and found this, although it’s not an identical issue I thought it was worth a shot so I deleted C:\Windows\System32\GroupPolicy\Machine\Registry.pol after that I refreshed the policy on the machine a few time and the devices began to encrypt. 

I hope this helps!

Share this post


Link to post
Share on other sites
On 2/26/2020 at 4:30 AM, ukg_matt said:

I have just resolved something like this in my environment. I looked in the BitlockerManagement_GroupPolicyHandler.log and I found errors ' Failed to open GPO (0x80004005)', I googled and found this, although it’s not an identical issue I thought it was worth a shot so I deleted C:\Windows\System32\GroupPolicy\Machine\Registry.pol after that I refreshed the policy on the machine a few time and the devices began to encrypt. 

 

 

I hope this helps!

This works. Thanks.

Share this post


Link to post
Share on other sites

Hi Guys,

 

I have two problems with new SCCM Bitlocker solution.

We have succesfully deployed new SCCM 1910 Bitlocker Policy. Also we`ve deployed Configuration Baseline to Enforce Bitlocker Encryption.

For some stations all looks good for another unfortunatelly no.

We use XTS-AES-128 bit

All workstations have Windows 10

Some workstations have a problem with MBAMClientUI.exe. It is not popup for the local user

The same stations have a problem with encryption enforcement. It is not starts in the background...

 

I`ve tried to delete C:\Windows\System32\GroupPolicy\Machine\Registry.pol but nothing happens. It was just recreated after policies evaluation time.

But still the same result. Encryption is not starting

 

Do you have any ideas how we can resolve this issue? 

If we start MBAMClientUI.exe manually it works. We can click Postpone or Start. 

image.png.77d576fb66e21806db749bd8bbb09cf3.png

image.png.ef50f58fd0175db7638a3f9ef615efa3.png 

image.png.4f60b72eefaa796312c455a50b698a56.png

image.png.239e7a848880c7d46a82aaae551e3da2.png

image.png.e94e9edea09df1bfd65321397450443a.png

 

image.thumb.png.774e419ab1eaee71bd9088f5a350479c.png

 

image.thumb.png.2fadbe77557823897b70ed1e3028127c.png

image.png.7636b87757899019c29266f10348c8da.png

Share this post


Link to post
Share on other sites

@Kirill_L
I have the exact same issue, the only difference is the Windows 10 build.  We are using 1809.  But other than that, everything is the same.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...

×
×
  • Create New...