ukg_matt Posted January 23, 2020 Report post Posted January 23, 2020 I’ve been following the Bitlocker management tutorial here. Apart from the previous MBAM Install error over here, everything has gone as expected, apart from actual device encryption….. I’ve configured everything as per the tutorial, I have a set of devices, I have the configuration base line to deploy the reg keys to force encryption to start, I’ve configured and deployed the policy to the machines. The clients have the MDOP client. If I run “(Get-WmiObject -Class mbam_Volume -Namespace root\microsoft\mbam).ReasonsForNoncompliance” on any of the clients, I get the 3 codes returned, 1, 16 and 3. From here the error codes are as follows : 1 MBAM Policy requires this volume to be encrypted but it is not. 3 MBAM Policy requires this volume use a TPM protector, but it does not. 6 Policy requires minimum cypher strength is XTS-AES-256 bit, actual cypher strength is weaker than that. The policy I configured in SCCM is XTS-AES-256, do I need to do something else? Configure a GPO maybe? I wasn’t sure exactly what other detail to include so feel free to ask me for some logs etc. Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted January 23, 2020 Report post Posted January 23, 2020 no GPO's needed, can you attach (or email me) the 2 bitlocker related logs in c:\windows\ccm\logs and can you do a teamviewer session so i can take a look ? Quote Share this post Link to post Share on other sites More sharing options...
APd Posted February 6, 2020 Report post Posted February 6, 2020 Did you work this out? We've been encrypting with MBAM for a while now successfully, now we're having a rash of computers not encrypting because "actual cypher strength is weaker" and it's not clear what has changed. Quote Share this post Link to post Share on other sites More sharing options...
Carl Davis Posted February 11, 2020 Report post Posted February 11, 2020 Hi Niall, I have used your guides to implement SCCM MBAM 1910 and it went in successfully. I am however facing an issue where the clients - even though they receive the policies and the registry change to encrypt without user action - I find that nothing happen until I manually run MBAMClientUI.exe. I've even changed the MBAM Registry to implement "NoStartupDelay" and no joy. I've had one or two successful when the MDOP client pops up but the rest just sit there. Any advice is greatly appreciated and I look forward to hearing from you Regards Carl Davis P.S - AMAZING GUIDES BTW - Thank you for taking the time to write and video , 1 Quote Share this post Link to post Share on other sites More sharing options...
ukg_matt Posted February 11, 2020 Report post Posted February 11, 2020 Edited Quote Share this post Link to post Share on other sites More sharing options...
ukg_matt Posted February 11, 2020 Report post Posted February 11, 2020 On 2/6/2020 at 3:06 PM, APd said: Did you work this out? We've been encrypting with MBAM for a while now successfully, now we're having a rash of computers not encrypting because "actual cypher strength is weaker" and it's not clear what has changed. My problems was/is that the SCCM Bitlocker policy could not be enforced... What do the event logs say on both server and clients? Quote Share this post Link to post Share on other sites More sharing options...
ukg_matt Posted February 11, 2020 Report post Posted February 11, 2020 6 minutes ago, Carl Davis said: Hi Niall, I have used your guides to implement SCCM MBAM 1910 and it went in successfully. I am however facing an issue where the clients - even though they receive the policies and the registry change to encrypt without user action - I find that nothing happen until I manually run MBAMClientUI.exe. I've even changed the MBAM Registry to implement "NoStartupDelay" and no joy. I've had one or two successful when the MDOP client pops up but the rest just sit there. Any advice is greatly appreciated and I look forward to hearing from you Regards Carl Davis P.S - AMAZING GUIDES BTW - Thank you for taking the time to write and video , What do the event logs say on both server and clients? Quote Share this post Link to post Share on other sites More sharing options...
Carl Davis Posted February 11, 2020 Report post Posted February 11, 2020 45 minutes ago, ukg_matt said: Hi Matt, The MBAM logs on the event viewer keep repeating "Volume Enactment Successful and CoreService Up Please see the attached from the clients.... Which event logs from the server do you need? This is a site with multiple roles on multiple servers 🙂 Thank you BitlockerManagement_GroupPolicyHandler.log Quote Share this post Link to post Share on other sites More sharing options...
ukg_matt Posted February 11, 2020 Report post Posted February 11, 2020 19 minutes ago, Carl Davis said: Hi Matt, The MBAM logs on the event viewer keep repeating "Volume Enactment Successful and CoreService Up Please see the attached from the clients.... Which event logs from the server do you need? This is a site with multiple roles on multiple servers 🙂 Thank you BitlockerManagement_GroupPolicyHandler.log 24.65 kB · 0 downloads What does the MBAM > Admin client log show? The server event logs are Application and Service Logs > Microsoft > Windows > MBAM-Web > Admin Application and Service Logs > Microsoft > Windows > MBAM-Web > Operational Quote Share this post Link to post Share on other sites More sharing options...
Carl Davis Posted February 11, 2020 Report post Posted February 11, 2020 Hi Ya, MBAM-WEB empty on site Servers and MBAM > Admin client - no events.... Thank you Carl Quote Share this post Link to post Share on other sites More sharing options...