Store BitLocker key in AD
hello,
i'm admin office ou, means have delegation rights ou i'm not domain admin.
i configured bitlocker gp should store key in ad in computer object within ou, set gp if computer cannot store key should continue encryption. encrypted computer (win7 64bit) shows no error in event log after encryption.
does mean computer able store key in ds? mean, there entry in event log?
i guess no domain admin right cannot recover bitlocker key bitlocker passwort recovery tool.
thanks,
edy
edy switzerland
hi,
q: there event log entry recorded on client computer indicate success or failure of active directory backup?
a: yes, event log entry indicates success or failure of active directory backup recorded on client computer. however, if event log entry says "success," information have been subsequently removed ad ds, or bitlocker have been reconfigured in such way active directory information can no longer unlock drive (such removing recovery password key protector). in addition, possible log entry spoofed.
ultimately, determining whether legitimate backup exists in ad ds requires querying ad ds domain administrator credentials using bitlocker password viewer tool.
i suggest you follow below articles store bitlocker keys in ad ds:
how backup recovery information in ad after bitlocker turned on in windows 7
backing bitlocker , tpm recovery information ad ds
http://technet.microsoft.com/en-us/library/dd875529(v=ws.10).aspx
requirements save bitlocker recovery key ad using mdt
yan li
if are technet subscription user , have feedback on our support quality, please send feedback here.
cataleya li
technet community support
Windows Server > Security
Comments
Post a Comment