Prip Posted June 22, 2021 Report post Posted June 22, 2021 Hi Niall, Hope you are doing great. I was following your tutorial on migrating from MBAM to SCCM Bitlocker, as i am working on a project for a customer for same. Tutorial: https://www.niallbrady.com/2019/11/13/want-to-learn-about-the-new-bitlocker-management-in-microsoft-endpoint-manager-configuration-manager/#comment-2150 Background: They are currently using SCCM version 2006, and wanted to migrate bitlocker from MBAM. They already have a PKI infrastructure (AD Certificate Service), with the SCCM client showing being in PKI mode (in the sccm client). I followed your steps to enable https mode (as they are in HTTP/HTTPS mode) and when i did that it broke the environment, and the clients (across 15 regions) stopped connecting, so I reverted back. My question to you is, i want to continue and finish the project, can i do so without changing SCCM to full https mode? Thanks in advance for taking the time out to reply and assist, as well as to the forum members Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted June 22, 2021 Report post Posted June 22, 2021 first things first, converting ConfigMgr to HTTPS shouldn't break things unless it's not done right, so were you sure that the clients had the right certs in place before making the switch? Quote Share this post Link to post Share on other sites More sharing options...
Prip Posted June 23, 2021 Report post Posted June 23, 2021 7 hours ago, anyweb said: first things first, converting ConfigMgr to HTTPS shouldn't break things unless it's not done right, so were you sure that the clients had the right certs in place before making the switch? I had checked some of the before laptops and saw the certs (SCCM and Client) in the MMC console on few of the laptops that I had checked. I was on a call with Microsoft for a different issue, I asked the engineer if the HTTPS was needed for Bitlocker in SCCM; he replied no, its not needed and can be done in the regular HTTP/HTTPS. Noting the sccm client are in PKI mode. He made note that only in the earlier version of SCCM 1910 was that a requirement, but not for SCCM 2006 version. Your take/experience? Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted June 23, 2021 Report post Posted June 23, 2021 PKI is not needed for BitLocker Management, but it's recommended, you can still use e-http, however be aware that come October 2022, http will be deprecated so the move to HTTPS should start now https://www.niallbrady.com/2021/03/12/prepare-for-http-only-client-communication-depreciation-in-configmgr-31-10-2022/ I'd recommend you fix your PKI issues and continue down that road, hire a pki consultant to assist Quote Share this post Link to post Share on other sites More sharing options...