Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSO Safeguard 8

 Hello,

 

I have setup Sophos Safeguard successfully and having issues setting up Single Sign On. The clients workstations are Windows 10 with Bitlocker enabled. Is there a way to allow SSO without having to enter Bitlocker password at boot?



This thread was automatically locked due to age.
Parents
  • Hi Matt,

    You have to make the required changes in the following Group Policy, either in Active Directory or locally on computers:

    1. Require additional authentication at startup

    2. Allow BitLocker without a compatible TPM

    Please go to these Group Policy objects and you can enable or disable the settings according to your requirement. Let me know if this helps resolve your issue.

  • Sorry for the late response. I will give this a try in Group Policy. Also I am having an issue when installing Safeguard clients using a default policy, some machines are grabbing the correct policy and others are not. All computers are in the same OU in AD and I have the Management Console to sync. Any ideas?

  • Hi Matt,

    Please help me the following questions:

    1. What is the Operating System on the machines?

    2. Do you see all the machines report to the Management Console?

  • 1. Windows 10 Pro 64bit

     

    2. I now see the machines responding to the Management Console. What I did was made changes to the policy and re-create a new Machine Client install. Once I installed the updated .msi All PC's were communicating and receiving the correct policy. 

     

    Will I have to re-create a new manged client .msi everytime I make changes to the polices?

Reply
  • 1. Windows 10 Pro 64bit

     

    2. I now see the machines responding to the Management Console. What I did was made changes to the policy and re-create a new Machine Client install. Once I installed the updated .msi All PC's were communicating and receiving the correct policy. 

     

    Will I have to re-create a new manged client .msi everytime I make changes to the polices?

Children