Quantcast
Channel: Configuration Manager 2012 - Operating System Deployment forum
Viewing all articles
Browse latest Browse all 9126

BitLocker steps and backing up to AD

$
0
0

Hello all, 

I am running SCCM2012 R2 CU2. Scenario is a new computer (no AD or SCCM objects) in WinPe with UDI. Running TPM Bitlocker. My issue is that the recovery keys are not being backed up to AD when the Enable Bitlocker step occurs in the State Restore group. Manually running manage-bde to backup from within Windows works as expected. Domain is 2008 R2. Laptop is Latitude 7240.

As per the Technote I can confirm all settings and permissions are correct: http://technet.microsoft.com/en-us/library/dd875529(v=WS.10).aspx. I have read various articles here and think that maybe this is similar to my issue, but I'm not sure: https://social.technet.microsoft.com/Forums/en-US/59346b4e-b8c0-4dae-9699-8fdf9ff8f8d0/deploying-bitlocker-w-mdtudi?forum=configmanagerosd. 

I also checked the status before the Enable Bitlocker step was executed and after:

C: (OS DISK) - BEFORE
Size:118.32gb
Bitlocker Version: Windows 7
Conversion Status: Fully Encrypted
Percent Encrypted:100%
Encryption Method: AES 128
Protection Status: Protection Off
Lock Status: Unlocked
I
dentification Field: None
Key Protectors: None Found

C: (OS DISK) - AFTER
Size:118.32gb
Bitlocker Version: Windows 7
Conversion Status: Fully Encrypted
Percent Encrypted:100%
Encryption Method: AES 128
Protection Status: Protection On
Lock Status: Unlocked
I
dentification Field: None
Key Protectors: TPM, Numerical Password

ZTIBde.log Log that might help is attached. Happy to add more...any help gratefully received. Thank you.

ZTIBde.log: 

Property UDI is now =
ZTIBde11/12/2014 11:57:15 AM0 (0x0000)

Microsoft Deployment Toolkit version: 6.2.5019.0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The task sequencer log is located at C:\WINDOWS\CCM\Logs\SMSTSLog\SMSTS.LOG.  For task sequence failures, please consult this log.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
System drive is: C:ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The deployment method is using ConfigMgr.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Property BdeInstallSuppress is now = NOZTIBde11/12/2014 11:57:15 AM0 (0x0000)
This script is not currently running in Windows PE ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
We are running a OS that supports BitLocker ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
OSDBitLockerTargetDrive= , OSDBdeTargetDriveLetter= , sOSDBitLockerTargetDrive= C:ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
About to perform variable rationalization.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BitLocker Mode set to: TPMZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Starting search for removable driveZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The search for a USB drive failedZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BitLocker Startup Key Drive Value set to: C: ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BitLocker Create Recovery P@ssword Status: AD ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BitLocker Wait For Encryption Status set to: FALSE ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BitLocker Recovery P@ssword set.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The current autorun setting is - ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Disabling AutorunZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Find the boot drive (if any) [False] [0.0.0.0] [False]ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDisk : \\UKH114414\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
No boot drives found. None.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Reverting autorun setting to - 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Setting BDE Drive letter to nothing as we are unable to get the boot drive.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Property BdeDriveLetter is now = ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Running first pass..ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDisk : \\UKH114414\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
   Partition Count: 3ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
ZTIDiskUtility!GetDiskFreeSpace should be deprecated, does not handle avaible space for a new partitionZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDisk : \\UKH114414\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
GetPartitions: 3ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDiskPartition : \\UKH114414\root\cimv2:Win32_DiskPartition.DeviceID="Disk #0, Partition #2"    \\UKH114414\root\cimv2:Win32_LogicalDisk.DeviceID="C:"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
   Free Disk Space: 128ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Existing Bitlocker: ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The current autorun setting is - 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Disabling AutorunZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Find the boot drive (if any) [False] [0.0.0.0] [False]ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDisk : \\UKH114414\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
No boot drives found. None.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Reverting autorun setting to - 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Existing Boot Drive: 1ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
The current autorun setting is - 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Disabling AutorunZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Find the boot drive (if any) [False] [0.0.0.0] [False]ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
New ZTIDisk : \\UKH114414\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
No boot drives found. None.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Reverting autorun setting to - 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Windows has a hidden system partition, no disk actions are necessaryZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Configuring protectors.ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Success TPM EnabledZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Success TPM Is ActivatedZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Success TPM Is OwnedZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Success TPM Ownership AllowedZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Check for Ensorsement Key Pair Present = 0ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
TpmEnabled: TrueZTIBde11/12/2014 11:57:15 AM0 (0x0000)
TpmActivated: TrueZTIBde11/12/2014 11:57:15 AM0 (0x0000)
TpmOwned: TrueZTIBde11/12/2014 11:57:15 AM0 (0x0000)
TpmOwnershipAllowed: TrueZTIBde11/12/2014 11:57:15 AM0 (0x0000)
EndorsementKeyPairPresent: TrueZTIBde11/12/2014 11:57:15 AM0 (0x0000)
TPM Validation CompleteZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Encryptable Volume Count:2ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Attempting to bind to: C:ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Success setting oBdeVol ZTIBde11/12/2014 11:57:15 AM0 (0x0000)
BDE Instance Bind CompleteZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Performing ProtectKeyWithTpm InstallationZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Attempting to enable BitLocker TPMZTIBde11/12/2014 11:57:15 AM0 (0x0000)
Recovery P@ssword being saved to C:\UKH114414-{42A7FC55-DD28-40B8-9C6A-9C3013B75E03}.txtZTIBde11/12/2014 11:57:16 AM0 (0x0000)
Attempting to intiate ProtectKeyWithNumericalP@sswordZTIBde11/12/2014 11:57:16 AM0 (0x0000)
Success protecting Key with numerical p@ssword ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Attempting to retrieve numerical p@sswordZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Saving numerical p@ssword to file.ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Success P@ssword Key file writtenZTIBde11/12/2014 11:57:17 AM0 (0x0000)
ProtectKeyWithNumericalP@ssword successZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Begining drive encryptionZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Attempting to start BDE encryptionZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Success starting encryptionZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Enabling protectors.ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Encryptable Volume Count:2ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Attempting to bind to: C:ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Success setting oBdeVol ZTIBde11/12/2014 11:57:17 AM0 (0x0000)
BDE Instance Bind CompleteZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Attempting to enable BDE ProtectorsZTIBde11/12/2014 11:57:17 AM0 (0x0000)
Success enabling protectors.ZTIBde11/12/2014 11:57:18 AM0 (0x0000)
ZTIBde processing completed successfully.ZTIBde11/12/2014 11:57:18 AM0 (0x0000)


Viewing all articles
Browse latest Browse all 9126

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>