Kace Script to set PIN on boot for Bitlocker
I am looking for a script to enable a boot PIN on a computer that has Biltlocker enabled. I think this would be useful to use in conjunction with KACE to lock down a laptop that may be off site. Over the years I have had a couple of instances where some employees "forgot" they still had a company laptop at home when they left and we would like to make sure no company data can be accessed.
Answers (1)
Top Answer
$pass = ConvertTo-SecureString "Password" -AsPlainText -Force
Enable-BitLocker -MountPoint C: -Password $pass -PasswordProtector -SkipHardwareTest
Add-BitLockerKeyProtector -RecoveryPasswordProtector -MountPoint C:
I use this for my Startup Password to Automate from the KACE SDA.
I think you can just change from password to -TpmAndPinAndStartupKeyProtector
$PIN = ConvertTo-SecureString "PIN" -AsPlainText -Force
Enable-BitLocker -MountPoint C: -TpmAndPinAndStartupKeyProtector $PIN
Add-BitLockerKeyProtector -RecoveryPasswordProtector -MountPoint C:
This should help ^
Comments:
-
Enable-Bitlocker line still prompts for PIN - JordanNolan 5 years ago