mirror of
https://github.com/TommyTran732/Windows-Setup.git
synced 2025-02-20 20:21:45 -05:00
Move Bitlocker to its own GPO
Signed-off-by: Tommy <contact@tommytran.io>
This commit is contained in:
parent
71198a64ef
commit
a2ada1ba15
Group Policies Objects
Bitlocker Drive Encryption.md
Computer Configuration
Control Panel
Printers.mdStart Menu and Taskbar.mdSystem
Credentials Delegation.mdDevice Guard.mdDevice Health Attestation Service.mdEarly Launch Antimalware.mdInternet Communication settings.mdKernel DMA Protection.mdMitigation Options.mdOS Policies.mdRemote Assistance.mdService Control Manager Settings.mdUser Profiles.mdWindows Time Service.md
User Account Control.mdWindows Components
App Privacy.mdApplication Compatibility.mdAutoPlay Policies.mdCloud Content.mdControlled Folder Access.mdData Collection and Preview Builds.mdFile Explorer.mdFind My Device.mdLocation and Sensors.mdMAPS.mdMDM.mdMessaging.mdMicrosoft Edge.mdMicrosoft account.mdNetwork Protection.mdSearch.mdSoftware Protection Platform.mdSync your settings.mdText Input.mdWidgets.mdWindows Calendar.mdWindows Defender SmartScreen.mdWindows Error Reporting.mdWindows Game Recording and Broadcasting.mdWindows Media Digital Rights Management.mdWindows Messenger.mdWindows Update.md
User Configuration
@ -2,9 +2,9 @@
|
|||||||
|
|
||||||
`Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption`
|
`Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption`
|
||||||
|
|
||||||
Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later) -> Enable -> XTS-AES 256-bit for operating system, fixed data, and removable drives.
|
Choose drive encryption method and cipher strength-> Enable -> XTS-AES 256-bit for operating system, fixed data, and removable drives.
|
||||||
|
|
||||||
**The disable new DMA devices when computer is locked should only be enabled if your computer does not support kernel DMA protection.**
|
**The disable new DMA devices when computer is locked should only be enabled if the specific computer does not support kernel DMA protection.**
|
||||||
|
|
||||||
## Operating System Drives
|
## Operating System Drives
|
||||||
|
|
Loading…
Reference in New Issue
Block a user