PowerShell脚本启用BitLocker(无TPM、无启动验证)时遇组策略错误的求助
PowerShell脚本启用BitLocker(无TPM、无启动验证)时遇组策略错误的求助
我正在开发一个PowerShell脚本,目的是给公司所有终端(包括未加入域但能访问私有网络的设备)启用BitLocker。考虑到部分终端可能没有TPM模块,而且我也不想启用启动验证,只打算用恢复密码来完成BitLocker的启用配置。
我写了下面的脚本,但运行时一直弹出错误提示:Group Policy settings do not permit the creation of a password。
奇怪的是,我在组策略的Computer Configuration->Windows Components->BitLocker Drive Encryption->Operating System Drives路径下,根本找不到任何限制创建BitLocker密码的相关设置,实在摸不着头绪,有没有大佬能帮忙排查解决这个问题?
我的脚本代码片段如下:
$outputFile = "C:\bitlocker_output.txt" Get-TPM | Out-File -FilePath $outputFile -Append $bitlockerStatus = Get-BitLockerVolume -MountPoint "C:" if ($bitlockerStatus.ProtectionStatus -eq "On") { Write-Host "BitLocker is already enabled on drive C:" } # 注:原脚本后续启用BitLocker的代码未完整展示
备注:内容来源于stack exchange,提问作者Nani
相关产品推荐
相关产品推荐

