Reference Guide
Security Management Server v10.2.7 AdminHelp
161
Fixed Data Drives
from Earlier
Versions of
Windows
When Selected, fixed data drives with the FAT file system can be unlocked
and viewed on computers running Windows Server 2008. This policy does
not apply to drives that are formatted with the NTFS file system.
Set this policy to Selected and the Do Not Install BitLocker to Go Reader on
FAT formatted Fixed Drives policy to Not Selected to allow BitLocker to Go
Reader to be installed on the fixed drive.
Do Not Install
BitLocker to Go
Reader on FAT
Formatted Fixed
Drives
Not Selected
Selected
Not Selected
If this policy is Not Selected, BitLocker to Go Reader is installed on the fixed
drive to enable users to unlock the drive on computers running Windows
Server 2008.
Set this policy to Not Selected and the Allow Access to BitLocker Protected
Fixed Data Drives from Earlier Versions of Windows policy to Not Selected
to allow BitLocker to Go Reader to be installed on the fixed drive.
Configure Use of
Passwords for Fi
xed
Data Drives
Allow
Allow
Require
Disallow
When set to Require, a connection to a domain controller is necessary to
validate the complexity of the password. When set to Allow, a connection
to a domain controller is attempted to validate complexity, but if no
domain controller is found, the password will still be accepted. When set
to Do Not Allow, no password complexity validation is done.
To use this policy, Configure Use of Passwords for Fixed Data Drives must
be set to Allow or Require.
Configure Pass
word
Complexity for
Fixed Data Drives
Allow
Do Not Allow
Require
Allow
When set to Require, a connection to a domain controller is necessary to
validate the complexity of the password. When set to Allow, a connection
to a domain controller is attempted to validate complexity, but if no
domain controller is found, the password will still be accepted. When set
to Do Not Allow, no password complexity validation is done.
To use this policy, Configure Use of Passwords for Fixed Data Drives must
be set to Allow or Require.
Minimum Password
Length for Fixed
Data Drives
8
8 min
20 max
Passwords must be at least 8 characters. To configure a greater minimum
length for the password enter the desired number of characters.
To use this policy, Configure Use of Passwords for Fixed Data Drives must
be set to Allow or Require.
Encryption Type for
Fixed Data Drives
Full Encryption
Full Encryption
Used Space Only Encryption
Select the type of encryption to use for Fixed Data Drives.
Choose How
BitLocker-
protected
Fixed Drives Can be
Recovered
Not Selected
Selected
Not Selected
BitLocker drives can always be recovered with BitLocker Manager, even if
this value is Not Selected. This policy allows for the control of how
BitLocker protected fixed data drives are recovered in the absence of the
required credentials.
More...
This policy is the parent policy to:
Allow Data Recovery Agent for Protected Fixed Data Drives
Config User Storage of BitLocker 48-digit Recovery Password
Config User Storage of BitLocker 256-bit Recovery Key
Omit Recovery Options from the BitLocker Setup Wizard
Save BitLocker Recovery Info to AD DS for Fixed Data Drives
BitLocker Recovery Info to Store in AD DS