Q. How can I force Windows 7 clients to use BitLocker To Go before writing to USB devices?

A. Windows 7 includes the BitLocker To Go functionality, which allows removable devices to be encrypted. Many organizations mandate the use of BitLocker on laptops to protect the content in case the laptop is stolen. Removable devices can be an even bigger risk, with users copying large amounts of data to small devices. If these devices are lost, they can pose a huge risk.

You can now use a Group Policy that restricts a user from writing to a USB device unless the device is encrypted with BitLocker To Go.

  1. Open the Group Policy Management Editor and edit a Group Policy Object that's linked to an organizational unit or domain that contains the Windows clients.
  2. Navigate to Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives.
  3. Double-click Deny write access to removable drives not protected by BitLocker
  4. Set this policy to Enabled. You can also configure whether users can write to devices that aren't from the local organization.

    Click to expand.

  5. Click OK.
  6. Close the Group Policy Management Editor.

This updates the registry value HKEY_LOCAL_MACHINE\System\CurrentControlSet\Policies\Microsoft\FVE\RDVDenyWriteAccess.

Related Reading:

Check out hundreds more useful Q&As like this in John Savill's FAQ for Windows. Also, watch instructional videos made by John at ITTV.net.

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• The Microsoft
Technology Roadmap
• Office 365 Implementation
• Hyper-V Optimizing
• Windows 8 Deployment
and much more!

Come See Paul Thurrott & Rod Trent in Person!

Early Registration Now Open

Upcoming Training

Mastering System Center 2012

During over 6 hours of training you can join John Savill from your computer as he will walk you through the key components and capabilities of System Center 2012, what’s involved in using the components, and the benefit they can bring to your environment.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.