Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Prevent Local Administrators from managing BitLocker with the manage-bde command
  • img 5c0128ea77f3f
    Systeminfo switches: How to use Systeminfo command-line tool switches Windows
  • Featured image 2
    Microsoft Account Password Reset via Web and Windows Windows
  • images 4 1
    How to export passwords from KeePass Database to Pleasant Password Server Password Manager
  • Trellix Native Encryption
    Manage BitLocker and FileVault with Trellix Native Encryption Mac
  • image 11
    Setting Up your Amazon S3 Glacier and FastGlacier for Your Online Vault AWS/Azure/OpenShift
  • hyper v 1
    How to fix unable to create a new VM on HyperV Virtualization
  • ssl
    SSL Encrypted Communications explained Web Server
  • Allow and Disallow Simultaneous Connection to Domain and Non Domain network
    Allow and Disallow Simultaneous Connection to Domain and Non-Domain network Network | Monitoring

Prevent Local Administrators from managing BitLocker with the manage-bde command

Posted on 16/01/202406/12/2024 Christian By Christian 2 Comments on Prevent Local Administrators from managing BitLocker with the manage-bde command
Prevent-Local-Administrators-from-turning-off-BitLocker-1

BitLocker is the Windows encryption technology that protects your data from unauthorized access by encrypting your drive and requiring one or more factors of authentication before it will unlock it. In this blog post, we shall discuss how to Prevent Local Admins from managing BitLocker with manage-bde command. Please see how to correctly disable BitLocker on Windows Server, How to Set up an Amazon Web Services (AWS) Account, and Hide Windows Updates: How to Hide or Fix HP Printer Windows Updates Error 0x800f020b.

As you can see below. I just recently enabled BitLocker on this server just to show you the steps. Also, it is possible to turn off BotLocker now as a Local Administrator. When we are done creating the AppLocker rules, this will no longer be possible.

Program blocked

Why Should I Prevent Local Administrators From Disabling BitLocker?

Preventing local administrators from disabling BitLocker is crucial to maintaining robust security measures. Disabling BitLocker, if in the hands of local administrators, poses a significant risk by potentially exposing sensitive data to unauthorized access or tampering.

Restricting this capability ensures the consistent enforcement of encryption protocols, safeguarding the integrity and confidentiality of the system’s contents against potential threats or breaches.

Please see how to fix this computer is a domain controller: The snap-in cannot be used on a domain controller, how to save and stop modification to Microsoft Management Console, and how to Disable BitLocker on Windows 10.

Disallow Administrators from Turning Off BitLocker

To restrict Administrators from disabling BitLocker in your domain environment. You will have to implement a group policy that explicitly denies the “Manage BitLocker” right to local administrators. This will prevent them from altering BitLocker settings.

Group Policy is a hierarchical infrastructure that allows a network administrator in charge of Microsoft’s Active Directory to implement specific configurations for users and computers. Group Policy is primarily a security tool, and can be used to apply security settings to users and computers.

Below are the steps to do this locally on your Windows Client PC or Windows server. Remember, BitLocker is not available by default on a Windows Server. You have to enable BitLocker via the Server Manager (Add Roles and Features), and how to Change BitLocker Password in Windows.

What is AppLocker?

AppLocker is an application allowlisting technology introduced with Microsoft’s Windows 7 operating system. It helps you control which apps and files users can run. These include executable files, scripts, Windows Installer files, and dynamic-link.

What is Manage-BDE Command?

The manage-bde-status provides information about all drives on your windows computer. Whether or not they are BitLocker-protected, including the, Size, BitLocker version, Conversion status, Percentage encrypted, Encryption method, Protection status, Lock status, identification field, and Key protectors

Step 1: Access the Services Manager

Open Services snap-in by running services.msc command. In Services snap-in, ensure the Application Identity service is running. You can right-click on this service and select Start if it isn’t running.

Start Application Identity service

The service is running now.

Identity service

Sep 2: Security Policy Policy

You will have to launch the secpol. You can do this by pressing Win + R and enter secpol.msc in Run dialog box to open the Security Policy snap-in. Or from the Windows search button. Click OK.

secpol.msc

Next, in the Security Policy snap-in window, navigate to Security Settings > Application Control Policies > AppLocker > Executable Rules.

Right click on Executable Rules, select Create New Rule.
Create-New-Rule

Click Next to continue

Before you begin - AppLocker

On the Permissions tab, select Action Deny.

AppLocker-Deny Action

Select the administrator accounts or users which you want to prevent turning off BitLocker. Click Next. Select Applicable users or groups to block

See this video showing the steps to Disable Touchpad on Windows 11, and the video on how to use the Reliability Monitor in Windows

Check Names

Object found

Click Next

Permission-Applocker

 On the next section, select Publisher and click Next.

Publishers-AppLocker

Under Publisher, select browse

Reference file

browse to C:\Windows\System32 and select manage-bde.exe file.

Manage BitLocker

Click Next to continue with the rule set up.

Publisher settings for BitLocker

 On the Exception Tab, I will have to click Next as I do not want to add an exception.

Exception AppLocker

Under Name, provide a description and click Create.

Create AppLockewr Rule for Blogpost

On the AppLocker warning prompt, click Yes.

warning AppLocker prompt

Here are the created rules to prevent administrators from turning off BitLocker.

Rues to prevent admins from disabling BitLocker

Close the Security Policy snap-in and run gpupdate /force command to update machine policies on the client PC. You may want to learn about Group Policy GPUpdate Commands.

GP update

Now let’s test. Run “manage-bde -status, you will see the program has been blocked.

Cannot enable or disable BitLocker via th manage-bde command

If you wish to do this also for the BitLocker Drive Encryption Wizard. Please create a rule to deny these executables.

BitLocker Drive Encryption

FAQs

What Steps Can I Take to Ensure BitLocker Persistence Against Local Administrator Disabling?

Configure BitLocker policies through Group Policy Objects (GPOs) to enforce specific settings, ensuring that even local administrators cannot easily disable BitLocker protection.

How Can I Secure BitLocker Settings to Resist Local Administrator Changes?

With the above solution via GPOs or use the Microsoft Endpoint Manager Configuration Manager to deploy and enforce BitLocker policies to safeguarde against unauthorized changes by local administrators

What Measures Should I Take to Harden BitLocker Against Local Administrator Tampering?

Regularly audit and monitor BitLocker settings using tools such as PowerShell scripts or security information and event management (SIEM) solutions, promptly identifying and rectifying any unauthorized changes.

Are There Specific Group Policy Configurations to Prevent Local Administrators from Disabling BitLocker?

Leveraging the Group Policy settings such as “Deny write access to removable drives not protected by BitLocker” to restrict local administrators from disabling BitLocker on removable drives, bolstering overall security.

I hope you found this blog post on how to Prevent Local Admins from managing BitLocker with manage-bde command useful. Please feel free to leave a comment below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:Bitlocker, Microsoft Windows, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to Set up an Amazon Web Services (AWS) Account
Next Post: Various ways to copy files from host to VMware Workstation VM

Related Posts

  • Windows11
    Windows 11 System Requirements Windows
  • download9
    Change the default Save and Download Location in Windows Windows
  • remote video disconnected
    Video Remoting was disconnected on Hyper V Windows Server
  • WinRM set up for specific IP
    Configure WinRM to accept connection from a specific IP Address Windows
  • FQWD
    Logoff or Restart or Shutdown Windows PC remotely Windows
  • microsoft warns windows 10 cumulative update kb4494441 breaks down some websites 526066 2
    Launch an application automatically during startup on Windows Windows

More Related Articles

Windows11 Windows 11 System Requirements Windows
download9 Change the default Save and Download Location in Windows Windows
remote video disconnected Video Remoting was disconnected on Hyper V Windows Server
WinRM set up for specific IP Configure WinRM to accept connection from a specific IP Address Windows
FQWD Logoff or Restart or Shutdown Windows PC remotely Windows
microsoft warns windows 10 cumulative update kb4494441 breaks down some websites 526066 2 Launch an application automatically during startup on Windows Windows

Comments (2) on “Prevent Local Administrators from managing BitLocker with the manage-bde command”

  1. Avatar photo Gman says:
    16/01/2024 at 8:49 AM

    Great info! Thank you.

    Log in to Reply
    1. Avatar photo Christian says:
      16/01/2024 at 9:19 AM

      You are welcome, Gman

      Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • img 5c0128ea77f3f
    Systeminfo switches: How to use Systeminfo command-line tool switches Windows
  • Featured image 2
    Microsoft Account Password Reset via Web and Windows Windows
  • images 4 1
    How to export passwords from KeePass Database to Pleasant Password Server Password Manager
  • Trellix Native Encryption
    Manage BitLocker and FileVault with Trellix Native Encryption Mac
  • image 11
    Setting Up your Amazon S3 Glacier and FastGlacier for Your Online Vault AWS/Azure/OpenShift
  • hyper v 1
    How to fix unable to create a new VM on HyperV Virtualization
  • ssl
    SSL Encrypted Communications explained Web Server
  • Allow and Disallow Simultaneous Connection to Domain and Non Domain network
    Allow and Disallow Simultaneous Connection to Domain and Non-Domain network Network | Monitoring

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,836 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.