cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1688
Views
5
Helpful
4
Replies

ISE and Windows Registries

jdurkin
Cisco Employee
Cisco Employee

Hi, 

 
1. Can ISE check the windows registry setting via Bitlocker for TPM?
 
2. Can ISE check the windows registry setting if Boot Password is Set? 
 
Thank you, 
Jim 
2 Accepted Solutions

Accepted Solutions

Nidhi
Cisco Employee
Cisco Employee

Hello Jim, 

 

From ISE , you can create a posture condition for registry check. however, you have to be absolutely sure about the registry check you want to perform. 

For Bitlocker, you might want to look under HKLM\Software\Microsoft\Windows\CurrentVersion\Bitlocker

Bios is not available through Windows. hence I doubt there is a registry entry for it which ISE can check.

I googled and found that wmi calls and vb scripts have been used to get this information. but again, this is out of ISE scope. 

 

Hope this helps. 

 

Thanks,

Nidhi

View solution in original post

Please reach out internally. As I understand several TME and PM have already been involved. This is a public community. Please remove customer name from the posting.

View solution in original post

4 Replies 4

Nidhi
Cisco Employee
Cisco Employee

Hello Jim, 

 

From ISE , you can create a posture condition for registry check. however, you have to be absolutely sure about the registry check you want to perform. 

For Bitlocker, you might want to look under HKLM\Software\Microsoft\Windows\CurrentVersion\Bitlocker

Bios is not available through Windows. hence I doubt there is a registry entry for it which ISE can check.

I googled and found that wmi calls and vb scripts have been used to get this information. but again, this is out of ISE scope. 

 

Hope this helps. 

 

Thanks,

Nidhi

Nidhi
Cisco Employee
Cisco Employee

Hello Jim, 

 

From ISE , you can create a posture condition for registry check. however, you have to be absolutely sure about the registry check you want to perform. 

For Bitlocker, you might want to look under HKLM\Software\Microsoft\Windows\CurrentVersion\Bitlocker

Bios is not available through Windows. hence I doubt there is a registry entry for it which ISE can check.

I googled and found that wmi calls and vb scripts have been used to get this information. but again, this is out of ISE scope. 

 

Hope this helps. 

 

Thanks,

Nidhi

Nidhi,  Are you able to get on a call to discuss?

Please reach out internally. As I understand several TME and PM have already been involved. This is a public community. Please remove customer name from the posting.