Deploy and Manage BitLocker using MBAM

Slides:



Advertisements
Similar presentations
Free, online, technical courses Take a free online course. Microsoft Virtual Academy.
Advertisements

Troubleshooting Windows Vista Security Chapter 4.
Secure Windows App Development. Authentication.
Windows 10 Device Health Attestation (DHA)
UNM Encryption Services in Development
News in ConfigMgr EWUG 1610.
Manage Office 365 more effectively: what’s new in Office 365 admin?
Deploy and get started with Microsoft Advanced Threat Analytics
5/21/2018 9:40 PM BRK3021 Learn about modern infrastructure roles in RDS: Next generation Windows desktop & app virtualization Clark Nicholson - Principal.
5/22/2018 1:39 AM BRK2156 Power BI Report Server: Self-service BI and enterprise reporting on-premises Christopher Finlan Senior Program Manager © Microsoft.
5/31/2018 3:40 PM BRK3113 How Microsoft IT builds Privileged Access Workstation using Windows 10 and Windows Server 2016 Jian (Jane) Yan Sr. Program Manager.
Microsoft Virtual Academy
Windows 10 and the cloud: Why the future needs hybrid solutions
6/19/2018 2:57 AM THR3092 Monitor and investigate actions on your user and data with alerts, insights and reports Binyan Chen Program Manager II, Office.
Modernizing your Remote Access
TFS Database Import Service for Visual Studio Team Services
6/25/ :13 PM BRK1076 Make Windows devices more secure by taking them out of your existing infrastructure Chris Rhodes & Andrew Bettany MCTs & MVPs.
Optimizing Microsoft OneDrive for the enterprise
The power of common identity across any cloud
Microsoft Ignite /17/ :54 PM BRK2092
Microsoft Ignite /18/2018 8:30 PM BRK2065
A Fast Track into Device Guard
Microsoft Ignite /31/ :08 AM
Migrate SharePoint to the cloud the Microsoft IT way
Expert-level Windows 10 deployment
Troubleshooting Windows 10 Deployment: Top 10 Tips and Tricks
9/18/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
9/18/2018 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Device Guard: AppLocker on steroids
Windows Store for Business
SharePoint Online Management and Control
Windows 10 Deployment Expert Level Johan Arwidmark
11/11/2018 Desktop Virtualization Corey Hynes Kyle Rosenthal President Technical Lead HynesITe Inc Spider Consulting @windowspcguy.
Microsoft /12/2018 8:06 AM BRK2103 Deliver more features faster with a modern development and test solution Claude Remillard Group Program Manager.
Microsoft Virtual Academy
Building hardware-based security with a Trusted Platform Module (TPM)
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Laura A. Robinson July 10, June 30, /15/2018 4:19 PM
Customize and Tune Microsoft Office 365 Data Loss Prevention
Seamless Office Migrations with Add-ins and Macros
Microsoft Ignite /20/2018 2:21 PM
TechEd /21/2018 5:20 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
TechEd /23/ :44 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
Microsoft Virtual Academy
SPC2012 – IT-Pro 11/30/2018 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Disaster Recovery as a Service
TechEd /2/2018 5:42 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
TechEd /4/2018 3:19 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
TechEd /7/ :16 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
12/9/2018 Desktop Virtualization Corey Hynes Kyle Rosenthal President Technical Lead HynesITe Inc Spider Consulting @windowspcguy.
TechEd /11/ :54 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered.
Enabling the hybrid cloud with remote access appliances
Overview: Dynamics 365 for Project Service Automation
Surviving identity management in a hybrid world
TechEd /25/2019 9:58 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
TechEd /28/2019 3:22 PM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Learn how to leverage the Microsoft Store for Education in your school
System Center Marketing
4/15/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
“Hey Mom, I’ll Fix Your Computer”
Ask the Experts: Windows 10 deployment and servicing
Diagnostics and troubleshooting in Azure App Service Support Center
Day 2, Session 2 Connecting System Center to the Public Cloud
Microsoft Virtual Academy
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Microsoft Virtual Academy
Managing your infrastructure with System Center
Azure AD Simon May Technical Evangelist.
Microsoft Virtual Academy
Presentation transcript:

Deploy and Manage BitLocker using MBAM Microsoft Ignite 2016 4/21/2018 5:12 AM BRK3100 Deploy and Manage BitLocker using MBAM Tanner Slayton Sr. Consultant – Cyber Security © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM TPM 101 © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

TPM 101 Beginning Current Time Main Function Physical Device Only 4/21/2018 5:12 AM TPM 101 Beginning Physical Device Only Disabled by default Current Time Still physical but also Virtual Enabled by default Main Function Protect sensitive cryptographic key material Maintain boot measurements, virtual smartcard private key, fingerprint authentication, credentials © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Trusted Computing Windows Investments 4/21/2018 Trusted Computing Windows Investments BitLocker Measured Boot Virtual Smartcards BitLocker Health Attestation Microsoft Passport Credential Guard Device Guard Measured Boot Virtual Smartcards BitLocker Windows 7 Windows 8.1 Windows 10 © 2015 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM BITLOCKER 101 © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Bitlocker 101 New in Windows 10 Data at rest encryption 4/21/2018 5:12 AM Bitlocker 101 New in Windows 10 Build 1511 - XTS encryption Customize recovery screen message Data at rest encryption With MBAM can have TPM, TPM+PIN, and Password Without can have all the above plus Smartcard, AD Group, AD User (Data Drives only) USB startup key © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM MBAM 101 © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

MBAM 101 Microsoft Bitlocker Administration and Monitoring What it can do Enforce encryption of domain joined systems Ensure protectors are correct Backup recovery key Give compliance status and reports for client devices What it can’t do Force users to change PIN at XX days Force a change to the recovery key at XX days Decrypt systems and re-encrypt with correct algorithm © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM Future of MBAM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What to expect short-term 4/21/2018 5:12 AM What to expect short-term Hotfix release for client to support XTS encryption September 2016 Rollup for MDOP Suite – Released 27-Sept (3168628) What will the hotfix enable? Client side only Escrow, Compliance Reporting, and Enactment will work Have to have same encryption strength for OS and Data Drives Compliance flag will be calculated properly What the hotfix will not fix Encryption strength on the reports will be blank © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What to expect long-term 4/21/2018 5:12 AM What to expect long-term We want your feedback blignite2016@Microsoft.com © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM Setup of MBAM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Server Setup Two server setup Order of installation 4/21/2018 5:12 AM Server Setup Two server setup SSRS / SQL on one server (can be shared) Web portal (IIS) on another Order of installation AD Users & Groups (Including PKI SSL certificates) Databases and Reports Web Portal Group Policies Client Deployment © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

PowerShell Scripts 4/21/2018 5:12 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Client Setup Deploy via SCCM / MDT Deploy via GPO Manual installation 4/21/2018 5:12 AM Client Setup Deploy via SCCM / MDT Deployment method (Altiris, etc…) Most preferred Deploy via GPO Can accomplish the task if desired Ideally do not install software via GPO Manual installation Least preferred © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Client Deployment - Scripts 4/21/2018 5:12 AM Client Deployment - Scripts Microsoft designed PowerShell and Scripts https://www.microsoft.com/en-us/download/details.aspx?id=48698 Invoke-MBAMClientDeployment.ps1 Used for MDT or SCCM deployment to start encryption SaveWinPETpmOwnerAuth.wsf Only works if TPM is not previously owned and ownership is taken via WinPE Log File: %TEMP%\SaveWinPETpmOwnerAuth.log Key Name: OwnerAuthFull © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Troubleshooting MBAM 4/21/2018 5:12 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Client and Server Troubleshooting 4/21/2018 5:12 AM Client and Server Troubleshooting How to determine if a client is having a problem Windows Event Forwarding Monitor – Microsoft-Windows-MBAM/Admin SCCM – Configuration Baselines Custom script How can to determine if manage-bde is executed AppLocker – Audit Mode – Deny for manage-bde.exe Event Logs Microsoft / Windows / MBAM (Operational and Admin) Bitlocker Event Logs © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Client and Server Troubleshooting 4/21/2018 5:12 AM Client and Server Troubleshooting Can you talk to the Web Services Recycle AppPool and check for errors (MBAM-Web) Client able to talk to recovery and compliance web portals Group policy applied Registry Key (HKLM\Policies\Microsoft\FVE) WMI namespace Win32_EncryptableVolume Query with WMI Explorer © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Client and Server Troubleshooting 4/21/2018 5:12 AM Client and Server Troubleshooting Lots of places to look Not an expert on SSRS or SQL And….. I wrote a script for that too  (At least on the client side) © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Demo

4/21/2018 5:12 AM TPM 201 © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What is Health Attestation? Health Attestation is a Windows security feature that was released as part of Windows 8 release: -TPM creates a tamper resistant audit log (as it is measuring/monitoring the boot) - It can be validated locally and remotely Windows Kernel & Boot Drivers Early Launch Anti-Malware Boot Loaders UEFI Secure Boot OS Loader TPM Boot Log Platform Configuration Registers (PCRs) EK Cert AIK Cert TPM

TPM Secrets & Certificates 4/21/2018 5:12 AM TPM Secrets & Certificates 8- Device sends the EK_CERT and EK_PUB to AIK provisioning service 9- AIK Provisioning service issues a challenge: Verifies the EK_CERT Issues a challenge: Generates a random value Encrypts it with EK_PUB Sends the encrypted challenge to the device 1- Fuse EK Seed 2- Generate EK Key Pairs (EK_PRIV, EK_PUB) and AIK key Pairs 7- User purchases the device, turns the device on 3- Send EK_PUB to signing server 10- Device decrypts the challenge with EK_PRIV, forward the following to the AIK provisioning service - Challenge data in clear format - Hash of AIK_PUB to 4- Sign the EK_PUB, issue an EK_CERT 5- Store the EK_CERT on the device 11- AIK provision service, gets the data: - validates if the challenge data are correct - Issues a 6- Ship the device © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows 10 Device Health Attestation (DHA) 4/21/2018 5:12 AM Windows 10 Device Health Attestation (DHA) Device Health Attestation (DHA) is a new Windows 10 feature that was released in June 2015 as part of the initial Windows 10 RTM release: Integrates with Windows 10 Mobile Device Management (MDM) framework Designed to work on devices that support Trusted Module Platform (TPM) in firmware or discrete formats (TPM 2.0 and 1.2 in Redstone release) Enables enterprises to raise the security bar of their organization to hardware monitored and attested security © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows 10 Device Health Attestation (DHA) 4/21/2018 5:12 AM Windows 10 Device Health Attestation (DHA) Before Windows 10 DHA release: Device health was assumed © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows 10 Device Health Attestation (DHA) 4/21/2018 5:12 AM Windows 10 Device Health Attestation (DHA) After Windows 10 DHA release: Device health assessed based on hardware measured state © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Windows 10 Device Health Attestation (DHA) 4/21/2018 5:12 AM Windows 10 Device Health Attestation (DHA) Sample use case scenarios: Data Collection (i.e. Anomaly analysis, Audit) Compliance Reporting ( i.e. On demand, Scheduled) Live Monitoring (i.e. Continuous diagnostics) Zero Day Incident Response (Incident Response Agility) Online Enforcement (i.e. Conditional Access) Out of band enforcement (i.e. Alert, notification, expiring access tokens..) © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Lessons learned from the Field 4/21/2018 5:12 AM Lessons learned from the Field © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

What to do and not to do in a deployment 4/21/2018 5:12 AM What to do and not to do in a deployment Customer with HIPAA requirements Deployed SCCM Integration Deleted computer objects within SCCM removed compliance data Faced a failed audit for compliance data Customer with hardening requirements Deployed with HTTPS on the web server HTTP on SSRS / SQL Clients getting access denied on endpoint (SPN Registration) Customer without a mature deployment infrastructure Tried to deploy to computers with local policy Inconsistent environment and compliance status Unable to sustain long term © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Previous questions emailed to me 4/21/2018 5:12 AM Previous questions emailed to me Any changes between 2012 R2 / 2016 to hold off deployment Internal versus External access for the SSP How secure are the keys in the DB When should I use TPM or TPM+PIN © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Please evaluate this session 4/21/2018 5:12 AM Please evaluate this session Your feedback is important to us! From your PC or Tablet visit MyIgnite at http://myignite.microsoft.com From your phone download and use the Ignite Mobile App by scanning the QR code above or visiting https://aka.ms/ignite.mobileapp © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4/21/2018 5:12 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.