Windows 10: How to config WDS in a way that bitlocker network unlock work properly?

Discus and support How to config WDS in a way that bitlocker network unlock work properly? in AntiVirus, Firewalls and System Security to solve the problem; Hi Pals, I have client system with UEFI enabled dhcp, system drive encrypted with PIN+TPM and network protector certificate is deployed! At boot... Discussion in 'AntiVirus, Firewalls and System Security' started by alirazmkhah, Jul 31, 2019.

  1. How to config WDS in a way that bitlocker network unlock work properly?


    Hi Pals,

    I have client system with UEFI enabled dhcp, system drive encrypted with PIN+TPM and network protector certificate is deployed!


    At boot time, valid ip obtained by dhcp but no drive key acquired! and bit-locker blue screen appeared to enter key manually!


    any one can help me about correct configuration of WDS?


    Best Regards!

    :)
     
    alirazmkhah, Jul 31, 2019
    #1
  2. Gardien01 Win User

    BitLocker Network Unlock

    Everything is straight forward in setting up and configuring this. However we have a question pertaining to the set up with the WDS server for the 'bypass'.

    Our concern:

    * the WDS server is essentially the single point of failure. If it ever went down all of the network workstations would prompt our users for the PIN to unlock the drive

    Our question

    * Is there any way to set up a secondary WDS server or some form of failover to build resilency? If our concern ever manifested itself, all of our workstation users would be locked out because they wouldn't have the PIN and this would result in a flood
    of support calls.

    Alternative

    * As far as I'm aware this is not possible but I'll ask anyways - can Bitlocker employ the AD password to unlock similar Symantec PGP disk encryption?
     
    Gardien01, Jul 31, 2019
    #2
  3. SJMP Win User
    Bitlocker Network Unlock - DHCP/PXE Question

    We are rolling out Network Unlock for Bitlocker on Win10 Enterprise machines.

    Clients are on VLAN1

    DHCP Server is on VLAN10

    WDS Server is on VLAN10

    WDS and DHCP are on different servers.

    Everything looks correct. Clients are getting the Certificate from GPO. Subnet BDE file has been created.

    Clients are UEFI and correct - protectors TPMandPIN have been installed.

    From WDS we can verify the cert in the cert store "certutil.exe -verifystore FVENKP"

    From client we can verify the cert and protectors "manage-bde -protectors -get C:"

    Our switching fabric uses IP helpers for DHCP which is working correctly.

    But we still get the prompt for PIN.

    I have enabled Debug logging for WDS Server. I am getting an error,

    [WDSServer] [base\eco\wds\wdsmgmt\src\wdsdirectoryservicesusepolicy.cpp:306] Expression: , Win32 Error=0x2

    Have not found what this error means.

    Do I need to configure anything on DHCP server clients to communicate w. WDS server during boot to bypass PIN?

    or

    Do I need to configure anything on WDS server for DHCP?

    Client can communicate w/ DHCP and WDS server -> network access is good.

    From MS Docs on Bitlocker Network Unlock. I am assuming the issues is on phase 3&4 of the unlock process.

    Any help on troubleshooting to ID the issue would be appreciated.

    Thanks,
     
  4. Viruzz Win User

    How to config WDS in a way that bitlocker network unlock work properly?

    HELP: Automatic BitLocker Unlock.

    Thank you sir, ill try your solution.

    Windows Auto unlock ONLY works in case you have Bitlocker on your system drive, because if your system drive is not encrypted auto unlocking other drives means loss of security.
    But in my case my system drive is Encrypted with hardware encryption that i password unlock during boot. So auto unlocking Bitlocker drives will do fine for me.
     
    Viruzz, Jul 31, 2019
    #4
Thema:

How to config WDS in a way that bitlocker network unlock work properly?

Loading...
  1. How to config WDS in a way that bitlocker network unlock work properly? - Similar Threads - config WDS bitlocker

  2. Bitlocker unlock prompt not displaying properly at 1440P

    in Windows 10 Gaming
    Bitlocker unlock prompt not displaying properly at 1440P: I recently got a 1440P monitor. I have it hooked up to my laptop via HDMI. This laptop also has a 2nd monitor hooked up though a docking station via USB-C and has Display Port Alt Mode, so should be able to natively display from there. By default, the laptop is closed, though...
  3. Bitlocker unlock prompt not displaying properly at 1440P

    in Windows 10 Software and Apps
    Bitlocker unlock prompt not displaying properly at 1440P: I recently got a 1440P monitor. I have it hooked up to my laptop via HDMI. This laptop also has a 2nd monitor hooked up though a docking station via USB-C and has Display Port Alt Mode, so should be able to natively display from there. By default, the laptop is closed, though...
  4. How does Bitlocker unlocking work?

    in Windows 10 Gaming
    How does Bitlocker unlocking work?: I'm trying to understand how Bitlocker works, when encrypting the main drive.From my understanding, it encrypts the whole drive, so once the system is shutdown, one would need the decryption key to unlock it.However, when starting the PC, even before entering the user data,...
  5. How does Bitlocker unlocking work?

    in Windows 10 Software and Apps
    How does Bitlocker unlocking work?: I'm trying to understand how Bitlocker works, when encrypting the main drive.From my understanding, it encrypts the whole drive, so once the system is shutdown, one would need the decryption key to unlock it.However, when starting the PC, even before entering the user data,...
  6. how to unlock bitlocker

    in Windows 10 BSOD Crashes and Debugging
    how to unlock bitlocker: hi, I reinstalled windows 10 pro 64 bit on system. unfortunately, now I can't open one of my drive that was locked by bitlocker. I don't more about cmd and powershell. anyone in the foroum if can guide me to solve my problem. regards...
  7. there is way to unlock the bitlocker drive

    in AntiVirus, Firewalls and System Security
    there is way to unlock the bitlocker drive: hello i reset my bios setting then i re enter the internal drive (g) to open iitit as i save my documents inside but i think i forget my password or the reset bios mybe do some thing to my pass because i was not use my pc scince 1 year so i forget what is the problem *Sad i...
  8. there is way to unlock the bitlocker drive

    in Windows 10 Support
    there is way to unlock the bitlocker drive: hello i reset my bios setting then i re enter the internal drive (g) to open iitit as i save my documents inside but i think i forget my password or the reset bios mybe do some thing to my pass because i was not use my pc scince 1 year so i forget what is the problem *Sad i...
  9. Bitlocker Not Work Properly

    in AntiVirus, Firewalls and System Security
    Bitlocker Not Work Properly: Hi.I have 2TB Transcend external hard disk.I put bitlocker to unlock it. It work properly with bitlocker. two days ago i removed bitlocker password in my device. But i not sure it removed success. All those process doing in my laptop.After removing password my friends use...
  10. Bitlocker Auto Unlock: activated but not working

    in AntiVirus, Firewalls and System Security
    Bitlocker Auto Unlock: activated but not working: I have 2 storage hdd encrypted w/ bitlocker, in addition to the encrypted OS volume C:. I activated auto unlock expecting the storage volumes to automatically unlock with the unlocking of C: (I enter the psw during boot since I don't have TPM). However they stay locked...

Users found this page by searching for:

  1. FVE_NKP store

    ,
  2. bitlocker network unlock not working