<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Suspend POA for Bitlocker</title><link>https://community.sophos.com/encryption/f/discussion/123425/suspend-poa-for-bitlocker</link><description>Hi, 
 We are currently looking into setting up GPO for Windows Updates, as the feature updates require multiple reboots, every reboot will require the enter of the Bitlocker PIN. 
 Is there a way to suspend Bitlocker so this can happen? Not sure if it</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/450443?ContentTypeID=1</link><pubDate>Wed, 21 Oct 2020 14:40:35 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f349a875-aa24-4b88-9ecc-b66758b31271</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;Is the auto suspend for BitLocker just on features updates? Or can it be done on normal updates?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449706?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:28:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3c6cce24-8003-4752-9ee3-b649c880f7d6</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;OK thanks, sorry I got confused, so our Windows Updates are going to be rolled out via Group Policy every Tuesday which is Microsoft&amp;#39;s &amp;quot;Patch Tuesday&amp;quot;, the feature updates we are going to delay a month, so assuming they are Secure Boot enabled, and are on 1803 onwards, they should automatically suspend without and new policies added on SSG?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449705?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:25:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8b0dc3f7-55bb-4149-be86-243272266e61</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;I&amp;#39;m not sure how you intend to roll out the update (and from what from to versions) but it&amp;#39;s just an additional command/string on setup? Yes this would be Windows Bitlocker management - but its the same thing. There is no Sophos SafeGuard Bitlocker as such.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449704?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:22:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:adf65802-1903-48bc-bf01-12bc51007b67</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;Yes all of ours are Secure Boot enabled, but is that using Windows Bitlocker and not Bitlocker through SSG?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449703?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:21:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:36cbe3c7-588c-4689-b764-fc14a6a47653</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;I&amp;#39;d also add Dan - 1803 onwards is 100% BL aware. Link here for more details...&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.microsoft.com/en-gb/archive/blogs/mniehaus/new-upgrade-to-windows-10-1803-without-suspending-bitlocker"&gt;https://docs.microsoft.com/en-gb/archive/blogs/mniehaus/new-upgrade-to-windows-10-1803-without-suspending-bitlocker&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Note this DOES need the correct config though - like secure boot enabled?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449702?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:19:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c8eee28a-2ea0-4618-8257-b3f361ef13c0</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;No not yet, so in theory I shouldn&amp;#39;t have to create a separate policy in SSG if the Feature Updates are BL aware?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449701?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:18:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4219d18a-508a-489a-a90f-96f13c31ca3c</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;I have not run into this issue with mine yet, as the Window updates SHOULD be BL aware. Some (ironically) MS Surface updates have not been, and that&amp;#39;s been a bit of an issue. The update should check for BL, then suspend. If a further update requires another reboot - again it should be aware and suspend for you. Have you put any devices into a test pool to check?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449700?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:11:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d3e7fd56-2e88-4c77-8c23-589382900e32</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;Would prefer the SSG route as all our devices (250+) are on SSG, so that would make it difficult if a new PIN is required every time there is a feature update.&lt;/p&gt;
&lt;p&gt;Most Feature updates require a couple of reboots.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449699?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:05:23 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:c6f79219-0c85-42fa-b27f-049262380c57</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;Yes, remove the policy - and sadly that might mean a new PIN. Unless you want to try the non-SSG route but how supported that would be would be a guess?!&lt;/p&gt;
&lt;p&gt;How many PC&amp;#39;s do you need to do Dan and how many reboots?&lt;/p&gt;
&lt;p&gt;Some updates ARE Bitlocker aware and will suspend the computer automatically. I&amp;#39;ve had no need to unlock yet and have around 3500 Bitlockered laptops (not all on SSG)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449697?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 09:02:07 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e0d89405-8ee8-412a-80db-223923ad31ac</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;Thanks, that helps, so would that mean we would have to remove them once the updates have been completed?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449696?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 08:59:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:64cf7fe9-9567-443b-83fb-2b19fe812308</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;I&amp;#39;d keep it all &amp;quot;in-house&amp;quot; and use SSG to create the policy. Assign it to a select group, wait until your resync kicks in (or manually kick it off on the client) and you should be good.&lt;/p&gt;
&lt;p&gt;You policy would look a little like this -&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/640x480/__key/communityserver-discussions-components-files/6/pastedimage1602665861807v1.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Note your current policy will probably say TPM + PIN. I wouldn&amp;#39;t advise changing your default policy. Create a new one - create a new group (_WIndows_Update)&amp;nbsp; - putting a _ at the front will ensure it remains top of the list to find! and then assign the policy to this group. Move a PC into this group (or add it manually).&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Hope this helps Dan?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449694?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 08:50:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d9d10b45-fb79-499f-8a70-bb9f42dd5c94</guid><dc:creator>Dan Petford</dc:creator><description>&lt;p&gt;Thanks for the info, so would the new policy be a Group Policy? How would this be achieved?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Suspend POA for Bitlocker</title><link>https://community.sophos.com/thread/449692?ContentTypeID=1</link><pubDate>Wed, 14 Oct 2020 08:48:36 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e93031da-5a41-448f-8308-a8819efae05f</guid><dc:creator>MichaelMcLannahan</dc:creator><description>&lt;p&gt;MBAM supports network unlock/suspend, and it&amp;#39;s possible I believe to setup network unlock without MBAM too.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-how-to-enable-network-unlock"&gt;https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-how-to-enable-network-unlock&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;MBAM would conflict with SSG though.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;What about creating a new policy group for this update - TPM only? Assign it to the batches of PC&amp;#39;s you intend to do update, make sure they receive the policy and then reboots should work a treat without a PIN?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>