Bitlocker can be used to encrypt your drives from PowerShell, leaving you unable to access them after a reboot.
Stop PowerShell from interating with the Bitlocker Application
Through our Suggested Policies, you can prevent PowerShell from calling the Bitlocker Application.
Navigate to Application Control > Policies
data:image/s3,"s3://crabby-images/1d135/1d135b64fa2f0536c21d73f7b849ee6cc254d9ac" alt="undefined"
Select the desired level from the Applies To dropdown menu on the top right.
data:image/s3,"s3://crabby-images/af3e7/af3e77a508ad708f262093546ed042a34bd767ed" alt="undefined"
Select the 'Add Suggested Policies' button.
data:image/s3,"s3://crabby-images/064e7/064e790a796d6e022308ecb81d8691c20370b531" alt="undefined"
data:image/s3,"s3://crabby-images/88952/88952f24b7b4df4e6c664f6f26606880180d533e" alt="undefined"
Click to Deploy Policies.
data:image/s3,"s3://crabby-images/87d4b/87d4b9699996ab3ac9827a600321b5e9edbca584" alt="undefined"
This will prevent PowerShell from calling the Application and running the manage-bde.exe commands.
Removing PowerShell's access to the Bitlocker Module
In addition to the above Ringfencing policy, you need to create a Storage Policy to remove access to the Bitlocker PowerShell module and the Enable-Bitlocker commands.
Navigate to Storage Control > Policies
data:image/s3,"s3://crabby-images/7c0d5/7c0d5e2e933be7cf64e99ccd2c3470e4fd59bfeb" alt="undefined"
Select the desired group from the Applies To dropdown menu on the top right.
data:image/s3,"s3://crabby-images/609f2/609f237f73083d71d37990ce8bc866aef9ca0558" alt="undefined"
Select 'New Storage Policy'.
data:image/s3,"s3://crabby-images/e2bed/e2bed1c4d26003ad8388aeb2e4e3265d8e8f11b6" alt="undefined"
Enter a name for the Policy and change 'Permit' to 'Deny Read & Write'.
data:image/s3,"s3://crabby-images/8d416/8d41682e39bc448a7a9dfc08899f1830235d993d" alt="undefined"
Under the 'What paths should this apply to (e.g. '\\server1\share\*", "*.jpg" or "regex:[0-9]abc")? ' section, check 'Let me select file paths', then input the following into the text box and select 'Add':
c:\windows\system32\windowspowershell\v1.0\modules\bitlocker\*
data:image/s3,"s3://crabby-images/8ea51/8ea51c32ffd8b7890e9636aba6a6b5724d58c304" alt="undefined"
Select 'Save'.
data:image/s3,"s3://crabby-images/63b08/63b0819ddbab488f5068297580eec7eead3bd0a1" alt="undefined"
Then Click to Deploy Policies.
data:image/s3,"s3://crabby-images/a5d83/a5d835c341c8f7e12c2442ff9ac721a3bc37497a" alt="undefined"