By implementing , 探花大神庐 admins automate much of their system security management across their Windows庐, Mac庐, and Linux庐 fleets. Two specific Policies, BitLocker and FileVault 2, are key for enforcing full disk encryption (FDE) at scale across an organization鈥檚 Windows and Mac systems.
What are the BitLocker and FileVault 2 Policies?
The BitLocker (Windows) and FileVault 2 (Mac) Policies enable full disk encryption for their respective operating systems. More on full disk encryption in just a bit.
Both policies leverage native settings accessed via the to enable FDE on a system. Once enabled, the BitLocker and FileVault 2 Policies also collect the associated recovery key (a necessary backup for FDE) and store it in escrow for safe keeping.
Why Use These Policies?
FDE is a practice that encrypts a system鈥檚 hard drive while at rest. That way, in the unfortunate event that a system is stolen or otherwise physically compromised, the data stored on its hard drive is rendered inaccessible to anyone who doesn鈥檛 have the unique recovery key or the user鈥檚 password. In this manner, FDE is one of the most powerful ways to defend a system鈥檚 data if the hard drive is compromised.
Unfortunately, there are many examples of physical theft of a laptop or other workstation that have led to a data breach, especially among healthcare organizations. As such, many compliance regulations require some sort of disk encryption for certification.
Many IT organizations, however, have found it difficult to enforce FDE across both Windows and Mac system fleets automatically at scale without leveraging several solutions to do so. Beyond that, very few FDE solutions on the market feature recovery key escrow, which is crucial to retrieving data on an encrypted drive should the end user forget their password or get locked out.
By leveraging the BitLocker and FileVault 2 Policies from 探花大神, organizations can apply FDE en masse with just a couple clicks. 探花大神 also stores individual recovery keys so IT organizations can still unlock encrypted drives if a hard drive is removed or an end user forgets their password and can鈥檛 unlock their computer.
How to Use the FDE Policies
IT admins can enable all 探花大神 Policies directly from the Directory-as-a-Service Admin Portal by going to the Policies tab and applying them either to individual systems or Groups of systems. You can watch the video above for a more detailed tutorial.
Not a 探花大神 Customer?
Interested in fleetwide policy management for FDE and other security features at scale? Try 探花大神 Directory-as-a-Service庐, the first cloud directory service, absolutely free. Just , which includes 10 complimentary users to get you started.