IT Consultant Everyday Notes

Just some problems/solutions storage

Bitlocker: Disable protection of system drive during Microsoft updates

 

Here is an elegant technique to automate Bitlocker protectors disable while Microsoft updates are installing.

This was shared by one of Microsoft Support Engineers.

 

Sometimes Microsoft updates can introduces changes locking the machine. To avoid that you can disable protectors for update time and re-enable them after.

To do that you can use Scheduler and monitor for Windows Updates event.

We need to create two scheduled tasks (either locally or using GPO):

image

First one is Suspend Bitlocker

SNAGHTML5837d2f

It will start on Event

image

When MSInstaller starts Windows Updates it generates Event ID 1040

image

At that event we want to run a command to suspend protectors on C:

image

image

The second Scheduled Task is similar except Event ID we monitor and action.

When updates are installed an Event ID 1042 is issued

image

We are going to resume protectors at that event:

image

 

Note: The machine will have protectors in suspended state during Microsoft updates (they will be resumed after installation finish or after reboot), so it is a potential breach in your security. Use it on your own risk!

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: