Bitlocker avec code PIN
Modifier la group policy :
Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption\Operating System Drives\Require additional authentication at startup
Sélectionner :
Configure TPM Startup PIN -> Require Startup PIN with TPM
Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption\Operating System Drives\Disallow standard users from changing PIN or password
Enabled
Pour les tablettes activer :
Computer Configuration\Administrative Templates\Windows Components\Bitlocker Drive Encryption\Operating System Drives\ Enable use of Bitlocker authentication requiring preboot keyboard input on slates
Activer Bitlocker
manage-bde -protectors -add c: -TPMAndPIN