Dynamic Collection filter issue

Comments

2 comments

  • Stephen Reece

    I realize this is very old, but I'm having the same issue. Were you ever able to resolve this? Media Type and Bitlocker Protection don't see to exclude hosts that have external USB drives.

    0
    Comment actions Permalink
  • Stephen Reece

    Just wanted to circle back and post my solution. In the end, I used a PowerShell scanner that I run every 4 hours to place hosts in a dynamic group if Bitlocker is not enabled on local drives. Here's the script for the scanner:

    Get-Disk | Where-Object {$_.bustype -ne 'USB'} | Get-Partition | Where-Object { $_.DriveLetter} | Select-Object -ExpandProperty DriveLetter | Get-BitLockerVolume | Select MountPoint,ProtectionStatus,EncryptionPercentage,VolumeStatus | Sort-Object MountPoint

    That eliminates all USB drives that show up as Fixed.

    From there, I could create dynamic groups for Bitlocker Not Enabled or Suspended:
    Bitlocker Scanner Name, ProtectionStatus, Does Not Equal, On

    And then separate out the groups into Not Enabled:
    ALL ->
        Bitlocker Scanner Name, ProtectionStatus, Equals, Off
        Bitlocker Scanner Name, VolumeStatus, Equals, FullyDecrypted

    And into a group for Suspended (as is the case with fresh Windows installs or where Bitlocker has been manually suspended for firmware updates):
    ALL ->
        Bitlocker Scanner Name, ProtectionStatus, Equals, Off
        Bitlocker Scanner Name, VolumeStatus, Equals, FullyEncrypted

    Hope this helps someone.

    0
    Comment actions Permalink

Please sign in to leave a comment.