Ideas
What features would you like to see?
All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Configuration Manager, though we can’t promise to reply to all posts.
If you require assisted support, please see https://aka.ms/cmcbsupport for more details.
-
Include the MBAM Administration Service in CM's BitLocker Management
The one component from MBAM which has not so far been included in CM BitLocker Management is the Administration Service. This web service is used as the api entry point for 3rd party systems and custom automation activities for things like retrieving recovery keys.
7 votes -
Add time based policys
For policies, especially related to content filtering, it would be great to have much more strict enforcement during business hours than during non-business hours on company equipment.
Alternately this would be a good tool to help enforce usage policies for hourly employees who should not be accessing certain equipment after business hours to ensure there are no labor law violations.
1 vote -
Enhance Web Content Reporting For Time of Day
When reporting it would be great to see time of day for activity. For example, I may care less about social media or YouTube usage in evenings on company equipment than during the day.
1 vote -
Manage Controlled Folder Access on Windows Server 2019
Be able to manage Controlled Folder Access on Windows Server 2019 from Microsoft Endpoint Configuration Manager
3 votes -
Allow the use of BitLockers management Self-Service\Help Desk portals when using non-standard SQL ports
Would like to be able to use BitLocker Management portals when using non-standard SQL ports. Currently the install script\configuration requires standard ports in order to be able to install.
2 votes -
Defender ATP onboarding policy shows error when successful
Defender ATP onboarding policy shows error when successful.
0 votes -
Deploy Microsoft Defender ATP Policy to user collection
It should be possible to deploy a Microsoft Defender ATP Policy to a User collection, not just a Device collection.
1 vote -
MBAM Policy configurations for different drives
It would be good if we could set different policy configurations for OS Drive, Fix Data Drive & Removable Data Drive.
Currently We are not able to configure only OS Drive only2 votes -
Bitlocker exception for USB only
Currently with MBAM integration, the only exception is for the whole device to be excluded. We have certain USB devices (scanners/cameras/medical equipment) that is seen as USB mass storage and therefore encryption is required along with some users who have legitimit business reasons to not need to encrypt USB devices. We still require the HDD to be encrypted but allow the USB to be excluded.
We have our current GPO based bitlocker set with the USB encryption in a seperate policy so it can be excluded by devices in an AD group to allow these scenarios. Currently this prohibits moving…1 vote -
Provide Support for BitLocker Management with IBCM
Currently, internet-based clients are able to receive BitLocker Management Policies via IBCM but are unable to contact the Recovery Service. I have found that this is due to the MBAM Agent looking for the CurrentManagementPoint in WMI at ROOT\ccm:SMS_Authority.Name="SMS:<SiteCode>".
It is possible to trick” the MBAM Agent into using the internet-based MP by adding the IBCM FQDN into the MP property at ROOT\ccm\LocationServices:SMS_MPInformation.MP="<IBCM FQDN>". This allows the agent to successfully find the Recovery Service MP and communicate!
I am aware that there may be more to it than just facilitating this communication but wanted to at least share that achieving…
25 votes -
Impliment RBAC control settings for Bitlocker management
Currently only a Full Administrator can create or deploy a bit locker management policy. Please enable these rights to be delegated.
6 votes -
bitlocker computer compliance
Bitlocker computer compliance report does not show the C: drive compliance information if there is an extra drive in the machine (D: for example)
1 vote -
Support MBAM / Bitlocker Management IIS roles on CMG
Seeing how the Recovery Service endpoint only requires IIS and a Management Point role, would it be feasible to have the endpoint run on CMG?
Internet-based clients in a co-management environment cannot reach the internal MP URL. Unless they use a VPN connection. We could leverage the BitLocker CSP policies available in Intune but that doesn't offer integration with recovery keys stored in the SQL DB, or the Helpdesk and Self-Service portals.
Supporting the MBAM role through CMG could be a quick win.
46 votes -
Include all ASR Rules in Windows Defender Exploit Guard
Some Attack Surface Reduction Rules are missing in the Windows Defender Exploit Guard settings.
Please include the following Rules:
Block Office communication application from creating child processes
Block Adobe Reader from creating child processes
Block persistence through WMI event subscription44 votes -
Make "Manage TPM" in CM MBAM BitLocker HelpDesk Portal truely to manage TPM
With CM 1910 MBAM BitLocker upgrade, MBAM BitLocker Helpdesk portal (BitLocker Administration and Monitoring) is available. "Manage TPM" is list one of available option, however, if you take a close look, it is actually alterative to unlock machine.
It would be nice that "Manage TPM" indeed to have manage TPM actions, select a action and submit to act on the target machine, such as, clear TPM, reset TPM, etc.
The feature can be helpful to force a machine lockout at the next reboot in case there is a need and helpdesk professional can help.
1 vote -
Add the ability to unlock a bitlockered drive in WinPE via MBAM
for refresh/reinstall scenarios in WinPE where you have an already MBAM managed/Bitlockered client, and you want to reinstall it or refresh to a new os, the OS drive is bitlockered and therefore you cannot read it or pull data from it (USMT), we've used various versions of this for MBAM https://www.windows-noob.com/forums/topic/4173-how-can-i-retrieve-my-bitlocker-recovery-key-from-mbam-in-windows-pe/ but it would be nice if this ability was integrated within ConfigMgr now that MBAM is integrated too and to do it securely via https
10 votes -
MBAM fully integrated in 1910 does not have enforcement option
Great to see MBAM fully integrated in CM 1910, but the policy does not have any option to enforce the encryption. User can always postpone it.
For more info, see this: https://www.youtube.com/watch?v=kRkyx_-l9QU
57 votes -
The Defender (EP) messages in ConfigMgr should be accessible to a SIEM system
at the moment all the AV messages are in ConfigMgr, but if there is an outbreak there is only one way, via mail about alerting in CM, or we can configure StatusMessage rules to start something. Can we have a option to grab that infos to a SIEM like sentinel to get faster response about an outbreak? We need also reporting (very slow) and other mechanism in ConfigMgr that are very slow, but alerts in this case should be faster, like CM-Pivot automation to send some info's directly to a SIEM system, to get more possibility's.
0 votes -
can we have the Naming of Defender (EP) the same as in intune and MDATP
In some cases, the naming is different in Intune, MDATP and ConfigManager, but in the background it is the same setting, this is not only for Defender, it is for all Defender tools, like expoit guard, Microsoft Active Protection Service (MAPS) and so one. That would be nice...
3 votes -
Give full controll over Windows Defender Controlled Folder Access
The default configuration in Windows defender controlled access folder blocks folders like pictures, documents, desktop etc. and you can't turn it off. It was difficult to deploy applications so we decided to not use this feature anymore and it's a shame because it's a such a great idea. We would like to have an option to disable this default behavior. At our company We want only to protect network drives/folders and don't care about pictures folders etc.
6 votes
- Don't see your idea?