New Laptop Setup (and BitLocker)

Created by John Burton, Modified on Thu, 7 Mar, 2024 at 3:34 PM by John Burton

New Laptop setup 

Migrating users from redirected folders to One Drive and sync Edge  

  1. On AD, move user to FPL.LOCAL/Crispin Way/Users/Laptops - OneDrive Sync, which moves folders to local. Wait half an hour or so. 

  1. The sync process can be quickened by moving files from the Desktop, Documents, Pictures into a temp folder. 

  1. Reboot desktop PC and login with user. This will take longer than usual and show a message “Applying folder redirection policy”.  

  1. Verify redirected folders are back locally and ensure no important files are elsewhere. 

  1. In OneDrive, Sync and back up, Manage back up, select Documents, Pictures, Desktop, and save changes. OneDrive sync will commence 

  1. On the desktop PC, sign into Edge with Flexipol account. This backs up Edge settings, bookmarks, saved passwords, and history. 


Initialise Laptop 

  1. At the initial setup of the laptop, create a local account called Admin. 

  1. Select No to all location, data etc. request settings, and set data to Required only. 

  1. Get the serial number via “wmic bios get serialnumber” in cmd. 

  1. Rename the laptop to the serial number and join the laptop to the domain FPL.LOCAL. 


Setup BitLocker and backup recovery key 

  1. In \\fpl-dt-01\BitLockerKey$, create a folder, and name it the serial number of the laptop. 

  1. Right-click the C Drive in File Explorer, and either “Turn BitLocker On” or “Manage BitLocker”. 

  1. Save the BitLocker key to a file, in the folder created at point 10. 

  1. Via the laptop, the key can also be backed up onto the AD with PowerShell commands: PS C:\> $BLV = Get-BitLockerVolume -MountPoint "C:" and then PS C:\> Backup-BitLockerKeyProtector -MountPoint "C:" -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId. 


Install base software. 

  1. Uninstall unrequired software such as Teams for Home, any pre-installed anti-virus. 

  1. Install Office, Outlook, Teams for Work, Epicor (Save Public Cloud Folder to C Drive), Webroot, Splashtop and any others. 

  1. In Windows Update, Advanced options, check Receive updates for other Microsoft products”, check for any updates in Optional Updates, and go back Check for Updates. Complete updates. 

  1. Move the laptop on AD to Laptops – OneDrive Sync. After domain join, software uninstallations, installations and updates, restart.  

  1. Logged in as the user, do point 5 and 6 on the laptop. 


Record laptop details in IT Inventory 

  1. Get the Model, Bit, OS Version, System Name, RAM (Installed Physical Memory) from System Information 

  1. Get the serial number by tying “wmic bios get serialnumber” in cmd. 

  1. Verify Anti-Virus, Password Security, Performance BitLocker key is on and the key is backed up, and OneDrive is synching correctly. 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article