Configuration guide: BitLocker compliance

The configuration options on this page are only accessible to administrators. Refer to the Usage guide: BitLocker compliance to use library content as a standard user.

Prerequisites

This library pack contains content from the following required expansion products:

Some of these products offer default access to their respective content and can still be used without expansion products.

To learn more about default thresholds for expansion products, visit the extended documentation.

This dashboard helps you monitor and manage BitLocker encryption on Windows devices to ensure they remain secure and compliant. This page will guide you through the content structure.

Included content and dependencies

This library pack contains the following content and dependencies:

Type
Name
Description
Dependencies

BitLocker Status Monitoring

This dashboard helps monitor and manage BitLocker encryption on Windows devices to ensure they remain secure and compliant.

none

Get BitLocker information

Returns basic information on BitLocker protection status.

Required to populate specific dashboard widgets

Remote actions

Get GPO Startup Impact

Returns basic information on GPOs and EntraID configuration

Used to measure the impact of User and Computer GPOs at the point that the device is started. Also checks if the device is joined to Entra ID which means no GPOs can be present

Configuring BitLocker compliance

Adapt these suggested configuration steps to edit and customize content according to your organizational needs.

Follow these steps to install and configure content:

  • Before configuration - Install library pack content from Nexthink Library

  • Step 1 - Configure remote actions

Step 1 - Configure remote actions

  1. Review and edit your remote actions.

We recommend the following configurations for these remote actions:

Name
Trigger
Schedule query
Parameters to edit

Get BitLocker information

Scheduled, daily

devices 
| where operating_system.platform == windows and operating_system.name != "server"

none

Get GPO Startup Impact

Scheduled, daily

devices
| where operating_system.platform == windows and operating_system.name != "*server"

none

RELATED TOPICS

Last updated