This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SafeGuard - Volumne Encrypting in AES128 instead of AES256

We have created a device protection policy to encrypt volumes using AES256. When the policy is applied to any device, the root volume is encrypted using AES128 algorithm.

This is the policy definition:

This is the final result:

Any idea why?

Thanks in advance.



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hey SuscripcionesEM,

    Michael is spot on, there's probably a GPO overriding the setting.

     

    Go to Start > Rungpedit.msc > to open the Local Group Policy Editor.

    Browse to Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption.

    Double click "Choose drive encryption method and cipher strength" and select Enabled.

    Click the drop-down box > select AES 256-bit > Click OK.

    BitLocker should now use 256-bit AES encryption when creating new volumes, but it's worth noting that this setting only applies to new volumes you enable BitLocker on.
    Any existing BitLocker volumes will continue to use 128-bit AES.

Reply
  • FormerMember
    0 FormerMember

    Hey SuscripcionesEM,

    Michael is spot on, there's probably a GPO overriding the setting.

     

    Go to Start > Rungpedit.msc > to open the Local Group Policy Editor.

    Browse to Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption.

    Double click "Choose drive encryption method and cipher strength" and select Enabled.

    Click the drop-down box > select AES 256-bit > Click OK.

    BitLocker should now use 256-bit AES encryption when creating new volumes, but it's worth noting that this setting only applies to new volumes you enable BitLocker on.
    Any existing BitLocker volumes will continue to use 128-bit AES.

Children
No Data