Microsoft BitLocker Administration and Monitoring (MBAM) is part of Microsoft Desktop Optimization Pack suite (MDOP) which contain other important and business enabling tools available for Software Assurance Customers. MBAM is used to simplify and control the Bitlocker implementation (Windows 7 Machine encryption), deployment, help desk support as well as providing rich compliance reports. In this article I would like to share some of the best practices that I passed by recently while implementing MBAM.
MBAM is implemented via Group Policies on your specified Windows 7 Laptops OU under Computer configuration - Policies - Administrative Templates - Windows Components - MDOP MBAM. This folder contain 4 main categories (check below image)
Normally we would enable the Client services and enforce the Fixed drive and OS drive encryption (PIN+Password). Depending on your Company policy you may enable or disable the Removable drive encryption (USB thumb drive). Under the Client Management category you can enable Hardware compatibility checking, this feature can be used to identify BitLocker-capable computers and exclude specific hardware that you don’t want encrypted. Only Laptops that are approved and turned to compatible (Hardware TAB in the MBAM admin site) will get encrypted.
The Key steps for successful Bitlocker/MBAM client implementation are as follows:
For more details please check http://itcalls.blogspot.com/2012/05/microsoft-mbam-client-implementation.html
MBAM Technical Documents:
Microsoft BitLocker Administration and Monitoring (MBAM) Documentation Resources Download Page
http://www.microsoft.com/download/en/details.aspx?id=27555
MBAM Videos and Tutorials: http://technet.microsoft.com/en-us/windows/ff383366.aspx#MBAM Please check my blog for more details http://itcalls.blogspot.com/