Dell Wyse 5070 Windows 10 IoT Enterprise for Wyse Thin Clients Administrator s - Page 25

Initialize TPM and enable BitLocker manually

Page 25 highlights

7. Click Apply and then click OK. 8. Open gpupdate /force using the run command. 9. Restart the thin client to apply the group policies. Steps 1. Log in to the administrator account. 2. Disable Unified Write Filter. The thin client restarts. 3. Log in to the administrator account again. 4. Uncomment the following lines and update the pin-minimum of six characters-for TPM encryption: • If you are using Wyse Management Suite or USB Imaging tool-Go to C:\Windows\Setup\CustomSysprep\Modules \Post_CustomSysprep.psm1 and uncomment the following lines: • #cd C:\Windows\setup\Tools\TPM\ • #.\TPM_enable.ps1 -pin TC#1234 • If you are using System Center Configuration Manager-Go to C:\Windows\Setup\ConfigMgrSysprep\Modules \Admin_ConfigMgrSysprep.psm1 and uncomment the following lines: • #cd C:\Windows\setup\Tools\TPM\ • #.\TPM_enable.ps1 -pin TC#1234 5. Change the password to an alphanumeric format. 6. Go to C:\Windows\Setup. 7. Run Build_master. 8. Run Custom Sysprep if you are using Wyse Management Suite or USB Imaging tool or ConfigMgr Sysprep if you are using System Center Configuration Manager. The thin client automatically turns off. 9. Turn on the thin client and pull the image from the thin client. 10. After the image pull is complete, push the image to the target client. Wait for the execution of first boot scripts and BitLocker encryption to complete. When the Sysprep is completed the target thin client reboots and the TPM is enabled. 11. Enter the BitLocker password and verify the new alphanumeric password. 12. Log in to the administrator account and verify the encryption of the C drive. NOTE: To update the BIOS in BitLocker encryption do the following: a. Copy the BIOS executable file to the USB drive. b. Connect the USB to the respective thin client. c. Right-click the BIOS executable and select Run as administrator. d. Select the Suspend BitLocker Drive Encryption checkbox and then click Update. Thin client reboots and the BIOS is updated. Also the BitLocker is suspended for one reboot. e. Reboot the thin client to ensure that the BitLocker is active. Initialize TPM and enable BitLocker manually Steps 1. Log in to the administrator account. 2. Disable Unified Write Filter. The thin client restarts. 3. Log in to the administrator account again. 4. Open tpm.msc using the run command menu. 5. Verify the TPM status in Trusted Platform Module Management on the thin client. The status should be displayed as The TPM is ready for use. 6. Click Close in Trusted Platform Module Management on the thin client. 7. Open gpedit.msc using the run command menu. Administrative features 25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58

7.
Click
Apply
and then click
OK
.
8.
Open
gpupdate /force
using the run command.
9.
Restart the thin client to apply the group policies.
Steps
1.
Log in to the administrator account.
2.
Disable Unified Write Filter.
The thin client restarts.
3.
Log in to the administrator account again.
4.
Uncomment the following lines and update the pin—minimum of six characters—for TPM encryption:
If you are using Wyse Management Suite or USB Imaging tool—Go to
C:\Windows\Setup\CustomSysprep\Modules
\Post_CustomSysprep.psm1
and uncomment the following lines:
#cd C:\Windows\setup\Tools\TPM\
#.\TPM_enable.ps1 -pin TC#1234
If you are using System Center Configuration Manager—Go to
C:\Windows\Setup\ConfigMgrSysprep\Modules
\Admin_ConfigMgrSysprep.psm1
and uncomment the following lines:
#cd C:\Windows\setup\Tools\TPM\
#.\TPM_enable.ps1 -pin TC#1234
5.
Change the password to an alphanumeric format.
6.
Go to
C:\Windows\Setup
.
7.
Run
Build_master
.
8.
Run
Custom Sysprep
if you are using Wyse Management Suite or USB Imaging tool or
ConfigMgr Sysprep
if you are using System
Center Configuration Manager.
The thin client automatically turns off.
9.
Turn on the thin client and pull the image from the thin client.
10.
After the image pull is complete, push the image to the target client. Wait for the execution of first boot scripts and BitLocker
encryption to complete.
When the Sysprep is completed the target thin client reboots and the
TPM
is enabled.
11.
Enter the BitLocker password and verify the new alphanumeric password.
12.
Log in to the administrator account and verify the encryption of the C drive.
NOTE:
To update the BIOS in BitLocker encryption do the following:
a.
Copy the BIOS executable file to the USB drive.
b.
Connect the USB to the respective thin client.
c.
Right-click the BIOS executable and select Run as administrator.
d.
Select the Suspend BitLocker Drive Encryption checkbox and then click Update. Thin client reboots and the BIOS
is updated. Also the BitLocker is suspended for one reboot.
e.
Reboot the thin client to ensure that the BitLocker is active.
Initialize TPM and enable BitLocker manually
Steps
1.
Log in to the administrator account.
2.
Disable Unified Write Filter.
The thin client restarts.
3.
Log in to the administrator account again.
4.
Open
tpm.msc
using the run command menu.
5.
Verify the TPM status in
Trusted Platform Module Management
on the thin client.
The status should be displayed as
The TPM is ready for use
.
6.
Click
Close
in
Trusted Platform Module Management
on the thin client.
7.
Open
gpedit.msc
using the run command menu.
Administrative features
25