MBAM, Bitlocker and Compliance

A couple of months ago I was involved in a divestiture project where we used MBAM from the MDOP suite to manage the Bitlocker disk encryption deployment across the company laptops.

It’s a great product that has gotten less attention than it deserves due to it being bundled and buried deep inside the MDOP suite but there are two thorns that stick out like rusty nails in it.

  1. Cumbersome initial installation requiring a lot of manual steps
  2. Limited options for filtering out specific types of machines (i.e. portables vs. non-portables when you’re only interested in the portables)

#1 – Redmond, please!! Do better, don’t be evil 🙂

#2 Fortunately, one of my colleagues is a Reporting Services wizard and we were able to modify the compliance reports to include some more useful fields for filtering than the defaults – as seen below where we added a Computer Type field and filter out everything but laptops (Portable/Non-Portable, Non-TPM).

mbam

With these additional hacks the MBAM product works wonders and would be worth a separate purchase but consider that with the MDOP package you get AGPMC, DART and Med-V and you have a killer deal. Did I mention that it also has a Self-Service portal for Helpdesk and Users?

The one remaining concern is that MBAM doesn’t have any automatic pruning of stale records. That concern is however addressed by the add-on MBAM Data Compliance Cleanup Tool. The latest update to the tool makes it compatible with MBAM 2.5.

See http://blogs.windows.com/itpro/2014/05/01/mdop-2014-delivers-improved-bitlocker-management-with-mbam-2-5/

4 thoughts on “MBAM, Bitlocker and Compliance

  1. #2 Fortunately, one of my colleagues is a Reporting Services wizard and we were able to modify the compliance reports to include some more useful fields for filtering than the defaults – as seen below where we added a Computer Type field and filter out everything but laptops (Portable/Non-Portable, Non-TPM).

    This is something I really need! Unfortunately I am not a Reporting Services wizard. Could you please pass along some more info on this? Examples? Samples? Just being able to filter portable vs non-portable would be huge.
    Thanks

  2. Hi, I am also looking for steps to edit the default Enterprise Compliance Report.

    Could you share the steps with screenshots, it would be really helpful.

    • It’s been a long time, I don’t have any current MBAM setup for screenshots.
      The required changes are all on the SQL side, MBAM comes with a pre-defined set of reports that can be copied and edited to fit your needs.

Leave a Reply

Your email address will not be published.