diff --git a/docs/ninjaone/automations/bitlocker-missing-key-protectors.md b/docs/ninjaone/automations/bitlocker-missing-key-protectors.md new file mode 100644 index 000000000..976c70dc6 --- /dev/null +++ b/docs/ninjaone/automations/bitlocker-missing-key-protectors.md @@ -0,0 +1,39 @@ +--- +id: '0f9279df-9d04-43ab-8db9-cc4b241c9e95' +slug: /0f9279df-9d04-43ab-8db9-cc4b241c9e95 +title: 'BitLocker - Missing Key Protectors' +title_meta: 'BitLocker - Missing Key Protectors' +keywords: ['bitlocker', 'bitlocker-status', 'recovery-key', 'bitlocker-audit', 'recovery-password'] +description: 'Detects fully encrypted BitLocker volumes with protection off and a missing key protector.' +tags: ['bitlocker', 'security', 'auditing'] +draft: false +unlisted: false +last_update: + date: 2026-07-24 +--- + +## Overview +Detects fully encrypted BitLocker volumes with protection off and a missing key protector. + +## Sample Run + +`Play Button` > `Run Automation` > `Script` +![SampleRun1](../../../static/img/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95/image1.webp) + +## Dependencies + +- [Solution: BitLocker and TPM Audit](/docs/57c787ad-8d22-4ae4-b5e5-dac34fc600fc) + +## Automation Setup/Import + +[Automation Configuration](https://github.com/ProVal-Tech/ninjarmm/blob/main/scripts/bitlocker-missing-key-protectors.ps1) + +## Output + +- Activity Details + +## Changelog + +### 2026-07-24 + +- Initial version of the document diff --git a/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-servers.md b/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-servers.md new file mode 100644 index 000000000..639d186b6 --- /dev/null +++ b/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-servers.md @@ -0,0 +1,37 @@ +--- +id: '0756ab51-5d8f-4f7e-b82e-50a51d36c641' +slug: /0756ab51-5d8f-4f7e-b82e-50a51d36c641 +title: 'Detect Bitlocker Missing KeyProtectors - Servers' +title_meta: 'Detect Bitlocker Missing KeyProtectors - Servers' +keywords: ['bitlocker', 'bitlocker-status', 'recovery-key', 'bitlocker-audit', 'recovery-password'] +description: 'Triggers BitLocker - Missing Key Protectors automation on windows Servers and creates tickets if any missing KeyProtector is detected on the machine.' +tags: ['bitlocker', 'security', 'auditing'] +draft: false +unlisted: false +last_update: + date: 2026-07-24 +--- + +## Summary +Triggers [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) automation on windows Servers and creates tickets if any missing KeyProtector is detected on the machine. + +## Details + +- **Name:** `Detect Bitlocker Missing KeyProtectors - Servers` +- **Description:** `Triggers BitLocker - Missing Key Protectors automation on windows Servers and creates tickets if any missing KeyProtector is detected on the machine.` +- **Recommended Agent Policies:** `Windows Server Policy` + +## Dependencies + +- [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) +- [Solution: BitLocker and TPM Audit](/docs/57c787ad-8d22-4ae4-b5e5-dac34fc600fc) + +## Compound Condition Creation + +- [Compound Condition Configuration](https://github.com/ProVal-Tech/ninjarmm/blob/main/compound-conditions/detect-bitlocker-missing-keyprotectors-Servers.toml) + +## Changelog + +### 2026-07-24 + +- Initial version of the document \ No newline at end of file diff --git a/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-workstations.md b/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-workstations.md new file mode 100644 index 000000000..d4001a589 --- /dev/null +++ b/docs/ninjaone/compound-conditions/detect-bitlocker-missing-keyprotectors-workstations.md @@ -0,0 +1,37 @@ +--- +id: '31e82508-7f54-40c4-97a8-6af3af24fa55' +slug: /31e82508-7f54-40c4-97a8-6af3af24fa55 +title: 'Detect Bitlocker Missing KeyProtectors - Workstations' +title_meta: 'Detect Bitlocker Missing KeyProtectors - Workstations' +keywords: ['bitlocker', 'bitlocker-status', 'recovery-key', 'bitlocker-audit', 'recovery-password'] +description: 'Triggers BitLocker - Missing Key Protectors automation on windows workstations and creates tickets if any missing KeyProtector is detected on the machine.' +tags: ['bitlocker', 'security', 'auditing'] +draft: false +unlisted: false +last_update: + date: 2026-07-24 +--- + +## Summary +Triggers [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) automation on windows workstations and creates tickets if any missing KeyProtector is detected on the machine. + +## Details + +- **Name:** `Detect Bitlocker Missing KeyProtectors - Workstations` +- **Description:** `Triggers BitLocker - Missing Key Protectors automation on windows workstations and creates tickets if any missing KeyProtector is detected on the machine.` +- **Recommended Agent Policies:** `Windows Workstation Policy` + +## Dependencies + +- [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) +- [Solution: BitLocker and TPM Audit](/docs/57c787ad-8d22-4ae4-b5e5-dac34fc600fc) + +## Compound Condition Creation + +- [Compound Condition Configuration](https://github.com/ProVal-Tech/ninjarmm/blob/main/compound-conditions/detect-bitlocker-missing-keyprotectors-workstations.toml) + +## Changelog + +### 2026-07-24 + +- Initial version of the document \ No newline at end of file diff --git a/docs/ninjaone/cw-manage-ticket-templates/missing-key-protectors.md b/docs/ninjaone/cw-manage-ticket-templates/missing-key-protectors.md new file mode 100644 index 000000000..e2383a7c2 --- /dev/null +++ b/docs/ninjaone/cw-manage-ticket-templates/missing-key-protectors.md @@ -0,0 +1,37 @@ +--- +id: 'bf16fc48-0565-4746-9ae9-a744e9363937' +slug: /bf16fc48-0565-4746-9ae9-a744e9363937 +title: 'Missing Key Protectors' +title_meta: 'FilenameMissing Key Protectors' +keywords: ['bitlocker', 'bitlocker-status', 'recovery-key', 'bitlocker-audit', 'recovery-password'] +description: 'This ticket template configures how a ConnectWise Manage ticket will be generated in response to the Detect Bitlocker Missing KeyProtectors Conditions.' +tags: ['bitlocker', 'security', 'auditing'] +draft: false +unlisted: false +last_update: + date: 2026-07-24 +--- + +## Overview +This ticket template configures how a ConnectWise Manage ticket will be generated in response to the [Compound Condition : Detect Bitlocker Missing KeyProtectors - Workstations](/docs/31e82508-7f54-40c4-97a8-6af3af24fa55) and [Compound Condition : Detect Bitlocker Missing KeyProtectors - Servers](/docs/0756ab51-5d8f-4f7e-b82e-50a51d36c641) condition. + +## Requirement + +Ensure that the ConnectWise Manage app is enabled and connected. +![Requirement](../../../static/img/docs/86a9b907-a95e-48a8-a304-2bb243c3b6a1/requirement.webp) + +## Dependencies + +- [Compound Condition : Detect Bitlocker Missing KeyProtectors - Servers](/docs/0756ab51-5d8f-4f7e-b82e-50a51d36c641) +- [Compound Condition : Detect Bitlocker Missing KeyProtectors - Workstations](/docs/31e82508-7f54-40c4-97a8-6af3af24fa55) +- [Solution: BitLocker and TPM Audit](/docs/57c787ad-8d22-4ae4-b5e5-dac34fc600fc) + +## Template Creation + +[CW Manage Ticket Template Configuration](https://github.com/ProVal-Tech/ninjarmm/blob/main/cw-manage-ticket-templates/missing-key-protectors.toml) + +## Changelog + +### 2026-07-24 + +- Initial version of the document \ No newline at end of file diff --git a/docs/solutions/bitlocker-and-tpm-audit.md b/docs/solutions/bitlocker-and-tpm-audit.md index 7645b8b52..2afa94358 100644 --- a/docs/solutions/bitlocker-and-tpm-audit.md +++ b/docs/solutions/bitlocker-and-tpm-audit.md @@ -54,6 +54,7 @@ The solution uses the **[BitLocker and TPM Audit](/docs/2d104874-ec69-4d95-b912- | Name | Function | | --- | --- | | [BitLocker and TPM Audit](/docs/2d104874-ec69-4d95-b912-7fcd240bf592) | Performs a comprehensive audit of the machine's security posture. It executes `Get-BitLockerDetail` to scan volumes and `Get-TPMDetail` to retrieve hardware security stats, populating the results into the respective Custom Fields. | +| [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) | Detects fully encrypted BitLocker volumes with protection off and a missing key protector. | ### Group @@ -67,6 +68,14 @@ The solution uses the **[BitLocker and TPM Audit](/docs/2d104874-ec69-4d95-b912- | --- | --- | | [BitLocker Audit - Workstations](/docs/368a9d6b-0f50-498b-94ba-32e95e402b66) | Performs BitLocker and TPM audit once per day on Windows workstations where auditing is enabled via the Custom Field. | | [BitLocker Audit - Servers](/docs/ee96061c-3700-44af-a10c-9f1dde32e611) | Performs BitLocker and TPM audit once per day on Windows servers where auditing is enabled via the Custom Field. **The BitLocker Drive Encryption feature must be enabled on servers to perform auditing. This script will not work without enabling this feature.** | +| [Detect Bitlocker Missing KeyProtectors - Workstations](/docs/31e82508-7f54-40c4-97a8-6af3af24fa55) | Triggers [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) automation on windows workstations and creates tickets if any missing KeyProtector is detected on the machine. | +| [Detect Bitlocker Missing KeyProtectors - Servers](/docs/0756ab51-5d8f-4f7e-b82e-50a51d36c641) | Triggers [BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) automation on windows Servers and creates tickets if any missing KeyProtector is detected on the machine. | + +### Ticket Template + +| Name | Function | +| --- | --- | +| [Missing Key Protectors](/docs/bf16fc48-0565-4746-9ae9-a744e9363937) | This ticket template configures how a ConnectWise Manage ticket will be generated in response to the [Compound Condition : Detect Bitlocker Missing KeyProtectors - Workstations](/docs/31e82508-7f54-40c4-97a8-6af3af24fa55) and [Compound Condition : Detect Bitlocker Missing KeyProtectors - Servers](/docs/0756ab51-5d8f-4f7e-b82e-50a51d36c641) condition. | ## Implementation @@ -94,6 +103,7 @@ Create the following custom fields as described in the documentation: Create the following automation as described in the documentation: * [Automation: BitLocker and TPM Audit](/docs/2d104874-ec69-4d95-b912-7fcd240bf592) +* [Automation: BitLocker - Missing Key Protectors](/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95) ### Step 3 @@ -103,10 +113,19 @@ Create the following group as described in the documentation: ### Step 4 +Create the following ticket template as described in the documentation: + +* [Ticket Template : Missing Key Protectors](/docs/bf16fc48-0565-4746-9ae9-a744e9363937) + +### Step 5 + Create the following compound conditions as described in the documentation: * [Compound Condition: BitLocker Audit - Workstations](/docs/368a9d6b-0f50-498b-94ba-32e95e402b66) * [Compound Condition: BitLocker Audit - Servers](/docs/ee96061c-3700-44af-a10c-9f1dde32e611) +* [Compound Condition : Detect Bitlocker Missing KeyProtectors - Workstations](/docs/31e82508-7f54-40c4-97a8-6af3af24fa55) +* [Compound Condition : Detect Bitlocker Missing KeyProtectors - Servers](/docs/0756ab51-5d8f-4f7e-b82e-50a51d36c641) + ## FAQs @@ -212,6 +231,14 @@ Create the following compound conditions as described in the documentation: ## Changelog +### 2026-07-24 + +- Added the below content for Bitlocker Missing KeyProtectors + - Automation : BitLocker - Missing Key Protectors + - Compound Condition : Detect Bitlocker Missing KeyProtectors - Workstations + - Compound Condition : Detect Bitlocker Missing KeyProtectors - Servers + - Ticket Template : Missing Key Protectors + ### 2026-04-15 - Added the below custom fields and group to provide a simplified and consolidated view of BitLocker and TPM details: diff --git a/static/img/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95/image1.webp b/static/img/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95/image1.webp new file mode 100644 index 000000000..f053a7f9f Binary files /dev/null and b/static/img/docs/0f9279df-9d04-43ab-8db9-cc4b241c9e95/image1.webp differ