Last modified by Sabrina V. on 2024/10/23 06:31

Hide last authors
Jannis Klein 1.1 1 {{aagon.priorisierung}}
2 160
3 {{/aagon.priorisierung}}
4
5 {{aagon.floatingbox/}}
6
Sabrina V. 17.1 7 = Initial situation =
Jannis Klein 1.1 8
Sabrina V. 17.1 9 If you have already encrypted Clients with BitLocker, for example because you previously used a different management system, you can migrate the existing BitLocker encryptions and manage them with ACMP. To do this, follow these steps:
Jannis Klein 1.1 10
Sabrina V. 17.1 11 == Disable the previous management system ==
Jannis Klein 1.1 12
Sabrina V. 17.1 13 1. Make sure that the old management system is no longer actively managing BitLocker.
Jannis Klein 1.1 14
Sabrina V. 17.1 15 == Create Configuration Profiles ==
Jannis Klein 1.1 16
Sabrina V. 17.1 17 1. Create a new [[Configuration Profile>>doc:ACMP.67.ACMP-Solutions.Security.BitLocker Management.Konfigurationsprofile.WebHome]] or open an existing one.
Jannis Klein 1.1 18
19 {{aagon.warnungsbox}}
Sabrina V. 17.1 20 The settings related to encryption (such as encryption method or encryption mode) cannot be easily adjusted if encryption is already in place. This is because ACMP does not automatically decrypt drives that are already encrypted. If there are differences between the target state and the actual state at the Client, these settings will not be adjusted automatically.
Jannis Klein 1.1 21 {{/aagon.warnungsbox}}
22
Sabrina V. 17.1 23 == Assign Configuration Profile ==
Jannis Klein 1.1 24
Sabrina V. 17.1 25 1. Assign the appropriate [[Configuration Profile>>doc:ACMP.67.ACMP-Solutions.Security.BitLocker Management.Konfigurationsprofile.WebHome||anchor="HAssigningConfigurationProfilestoClients"]].
Jannis Klein 1.1 26
27 {{aagon.warnungsbox}}
Sabrina V. 17.1 28 If there are differences between the target and actual state for the [[key protectors>>doc:ACMP.67.ACMP-Solutions.Security.BitLocker Management.Konfigurationsprofile.WebHome||anchor="HKeyprotectorforoperatingsystemdrive"]] (e.g. system start PIN), the settings will be adjusted by ACMP in this case.
29 However, if there is no difference, existing key protectors will not be changed.
Jannis Klein 1.1 30 {{/aagon.warnungsbox}}
31
Sabrina V. 17.1 32 Once you have assigned a configuration profile to the Client, the existing recovery password will be scanned. This requires the hard drives to be unlocked. The operating system disks are always unlocked when the system is running, so the recovery password can be scanned directly for them.
33
34 Please note that fixed data drives sometimes need to be unlocked by the user first. This may take some time before the recovery password for the fixed data drives can be read.
© Aagon GmbH 2025
Besuchen Sie unsere neue Aagon-Community