Microsoft

System Center Configuration Manager Feedback

Suggestion box powered by UserVoice

How can we improve Configuration Manager?

Bitlocker aware updating - Suspend bitlocker automatically

Now that Surface drivers and firmware are available to download as software updates it would be great to be able to deploy them without worrying about Bitlocker and having our users locked out.

So far it seems that we have to do a lot of testing to see whether or not a driver or firmware will lockout bitlocker, and then give up and deploy them using a TS, so we can suspend Bitlocker, update, reboot and reenabled bitlocker.

Could all drivers/firmware from the Surface update category automatically have bitlocker suspended when deployed as an update? or give us a tick box in the deployment options to suspend for x number of reboots (some of the firmware reboots a few times).

13 votes
Vote
Sign in
(thinking…)
Sign in with: Facebook Google
Signed in as (Sign out)
You have left! (?) (thinking…)
Tom M shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →

1 comment

Sign in
(thinking…)
Sign in with: Facebook Google
Signed in as (Sign out)
Submitting...
  • Oneil1476 commented  ·   ·  Flag as inappropriate

    I am in the same situation right now. I have SCUP in place in my environment and I have limited capabilities in injecting detection and unfortunately, suspending BitLocker is one of that limitation. We tried creating an application but there are criteria that need to be met and can not or hard to script it. A Checkmark to "suspend BitLocker" in the deployment wizard is a very big help. We are even considering replacing our client management (SCCM) and go to WS one of Dell\VMWare because of this issue.

Feedback and Knowledge Base