Hi,
I seem to be getting mixed results on encrypting windows 10 machines with safeguard easy and im struggling because there is no documentation or guides from Sophos. The issues I am receiving vary but I have tried to outline them below. I have logged this with support however the documentation they sent me only goes up to windows 8.1.
The process I am following is to change the group policy locally on each machine before installation. The entries are “Enable use of bitlocker authentication requiring preboot keyboard input on slates” & “Require additional authentication at startup”. Once these have been enabled I continue to install the pre-install file, the redistributable and then the client before the policy. I select "Bitlocker challenge/response" for the custom installation so we can use the challenge response with our service desk. The policy I have setup has been created correctly and I have had a representative named Sampson remote in and check this over. The results of each device are below:
Toshiba Portege z30-c TPM 1.2:
No challenge response screen, can only recover when locked via bitlocker.
Toshiba Tecra z50-c TPM 2.0:
No challenge response screen, can only recover when locked via bitlocker.
Microsoft Surface Pro 4 TPM 2.0:
Challenge response available however when locking the surface out (after 30 or so attempts despite what I set in the policy) I can recover the surface via Sophos recovery challenge response but the TPM remains locked out. This is something I have got Sophos looking into on case ID 6299217. I can reset the TPM lockout manually by going to tpm.msc however shouldn't Sophos manage this and unlock it when recovered? otherwise what would be the point in using Sophos?
Apologies for war and peace, just wondering if anyone can help & if there are any guides out there for Sophos safeguard easy installation on windows 10?
Thanks,
This thread was automatically locked due to age.