
If your organization is planning to use the Trusted Platform Module (TPM) protector or the TPM + PIN protector options in BitLocker, you must activate the TPM chip before the initial deployment of MBAM. To encrypt a computer as part of Windows deployment Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Using Registry Editor incorrectly can cause serious problems that may require you to reinstall Windows. The procedure in this topic describes modifying the Windows registry. It also ensures that every computer that is deployed already has BitLocker running and is configured correctly. To review the Microsoft BitLocker Administration and Monitoring Client system requirements, see MBAM 2.0 Supported Configurations.Įncrypting client computers with BitLocker during the initial imaging stage of a Windows deployment can lower the administrative overhead necessary for implementing MBAM in an organization. If computers that have a Trusted Platform Module (TPM) chip, the BitLocker client can be integrated into an organization by enabling BitLocker management and encryption on client computers as part of the imaging and Windows deployment process. The Microsoft BitLocker Administration and Monitoring (MBAM) Client enables administrators to enforce and monitor BitLocker drive encryption on computers in the enterprise.

Deploying the MBAM 1.0 Language Release Update.Deploying MBAM 1.0 Group Policy Objects.Deploying the MBAM 1.0 Server Infrastructure.Preparing your Environment for MBAM 1.0.

In addition, you can access recovery key information when users forget their PIN or password, or when their BIOS or boot record changes. You can also report on the encryption status of an individual computer and on the entire enterprise. With MBAM, you can select BitLocker encryption policy options that are appropriate to your enterprise and then use them to monitor client compliance with those policies. Microsoft BitLocker Administration and Monitoring (MBAM) provides a simplified administrative interface that you can use to manage BitLocker drive encryption.
