<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Turn on Bitlocker? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/571897#M5840</link>
    <description>&lt;P&gt;Hi Everyone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the &lt;SPAN&gt;ADDS role on the endpoints still a requirement? It's not listed in the pre-requisites (anymore?):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Disk-Encryption" target="_blank"&gt;Disk Encryption • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Best Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2024 09:35:30 GMT</pubDate>
    <dc:creator>Rocky-25</dc:creator>
    <dc:date>2024-01-05T09:35:30Z</dc:date>
    <item>
      <title>Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325052#M73</link>
      <description>&lt;P&gt;We are in the process of rolling out Cortex XDR to our organization. I saw the new BItlocker status screen/policies.&lt;BR /&gt;&lt;BR /&gt;I'm struggling to understand if I can enable Bitlocker with this policy, or if this is just a way to ensure the devices are complaint with the way we want Bitlocker configured? We were previously using our AV company's encryption product so we will be switching to Bitlocker, so I wasn't sure if I can enable it through Cortex or if I need to use Intune or GPO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325052#M73</guid>
      <dc:creator>pkawula</dc:creator>
      <dc:date>2020-04-27T19:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325054#M74</link>
      <description>&lt;P&gt;Hi there-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can enable this through Cortex XDR. You could also use GPO - Either method will work.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325054#M74</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-04-27T19:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325058#M75</link>
      <description>&lt;P&gt;Hmmm, That is what I thought, but even with the policy set to encrypt the disk, bitlocker still reports it is off.&lt;BR /&gt;&lt;BR /&gt;TPM is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any thing else I need to do to get Cortex to turn on Bitlocker?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:18:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325058#M75</guid>
      <dc:creator>pkawula</dc:creator>
      <dc:date>2020-04-27T19:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325067#M76</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42440"&gt;@pkawula&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before digging deeper, just want to confirm that you have gone through the steps on page 156 of the admin guide (linked below) and that all pre-requisites have been met.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-pro-admin.pdf" target="_blank" rel="noopener"&gt;Admin Guide - https://docs.paloaltonetworks.com/content/dam/techdocs/en_US/pdf/cortex/cortex-xdr/cortex-xdr-pro-admin/cortex-xdr-pro-admin.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325067#M76</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-04-27T19:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325072#M77</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WIndows 10 1909&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TPM enabled.&lt;/P&gt;&lt;P&gt;It is an AD connected endpoint. But the ADDS role is not installed there on the endpoint directly. I've never heard of ADDS being run on a workstation...&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 20:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325072#M77</guid>
      <dc:creator>pkawula</dc:creator>
      <dc:date>2020-04-27T20:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325367#M80</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42440"&gt;@pkawula&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not tried to enable this yet.&amp;nbsp; I will try to get access to a lab to verify; however, it is my understanding that this is needed to&amp;nbsp;allow the agent to access the encryption recovery key backup.&amp;nbsp; Please give me through the end of the week to secure an environment to test.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 15:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325367#M80</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-04-29T15:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325971#M82</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42440"&gt;@pkawula&lt;/a&gt;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I spoke with the Product Manager responsible for the Bitlocker feature this morning.&amp;nbsp; The prerequisite list is accurate and anything listed must be set up / enabled before taking advantage of the feature.&amp;nbsp; The PM also recommended that two profiles (as well as two policy rules) be created to use this feature.&amp;nbsp; The first one is an encrypt profile to encrypt the drive(s).&amp;nbsp; The second profile should be a decrypt profile to decrypt the drives.&amp;nbsp; If you need to decrypt an encrypted drive, you would then add that machine to a policy with decrypt profile.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalcon_0-1588603264763.png" style="width: 683px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25403i9FAA7696E1188CAA/image-dimensions/683x439/is-moderation-mode/true?v=v2" width="683" height="439" role="button" title="dfalcon_0-1588603264763.png" alt="dfalcon_0-1588603264763.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the policy list (under extensions), you would place the decrypt policy above the encrypt policy since the rule set is a top-down match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 14:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325971#M82</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-05-04T14:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325975#M83</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will likely just manage Bitlocker with Intune then and just use Cortex as a monitoring dashboard. I am not sure why Cortex needs that feature turned on when GPO and/or Intune can manage Bitlocker without it. Seems odd. Maybe I am missing something? Or maybe just because it is a third party software. Not a huge deal as we weren't expecting to control encryption from Cortex when we purchased anyway.&lt;BR /&gt;&lt;BR /&gt;If I just wanted to test, I am assuming adding the RSAT ADDS and Lightweight Directory Tools feature in Win10 1909 will fulfill the requirements?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 14:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/325975#M83</guid>
      <dc:creator>pkawula</dc:creator>
      <dc:date>2020-05-04T14:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/329192#M123</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42440"&gt;@pkawula&lt;/a&gt;&amp;nbsp;that is what we do. We implement Bitlocker via GPO and monitor through the Cortex XDR console. Using the Cortex XDR console alerted us to the fact that we were only using 128-bit encryption. We have since used GPO to enable 256-bit encryption going forward. Prior to Cortex XDR we had no visibility into this.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 14:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/329192#M123</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-05-21T14:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Turn on Bitlocker?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/571897#M5840</link>
      <description>&lt;P&gt;Hi Everyone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the &lt;SPAN&gt;ADDS role on the endpoints still a requirement? It's not listed in the pre-requisites (anymore?):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Disk-Encryption" target="_blank"&gt;Disk Encryption • Cortex XDR Pro Administrator Guide • Reader • Palo Alto Networks documentation portal&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Best Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 09:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/turn-on-bitlocker/m-p/571897#M5840</guid>
      <dc:creator>Rocky-25</dc:creator>
      <dc:date>2024-01-05T09:35:30Z</dc:date>
    </item>
  </channel>
</rss>

