BitLocker Recovery Key does not show for some users in AD

AM 0 Reputation points
2024-07-25T05:19:29.3+00:00

Hi

Hopefully, you can help with settings i can look at. We have Bitlocker GPO which stores recovery passwords into AD and full admins can see it however Read Only members can't view it , it's shows as blank for them. Where are the security settings in AD I can check to enable Bitlocker recovery password info visible for those users in a particular group?

Admin's view

AUser's image

RO users view

User's image

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,655 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hania Lian 17,601 Reputation points Microsoft Vendor
    2024-07-25T06:26:14.3133333+00:00

    Hello.

    By default, read-only members don't have permission to view BitLocker recovery passwords. This is because BitLocker recovery information is sensitive data and generally requires higher permissions to access. If you want a specific read-only member to be able to view the BitLocker recovery password, you'll need to assign the appropriate permissions to that member in AD.

    Here are the steps you can follow:

    Open Active Directory Users and Computers (ADUC):

    Go to the "View" menu and make sure "Advanced Features" is checked.

    Navigate to the BitLocker recovery information container: This is typically located under the computer object where the BitLocker recovery information is stored.

    Modify Permissions:

    Right-click the BitLocker Recovery Information container and select Properties.

    Go to the "Security" tab and click on "Advanced".

    Click Add to add a new permission entry.

    Select the Read-only group or the specific user you want to grant access to.

    In the Permissions section, check the Read all properties box.

    Click OK to apply the changes and save.

    Hope this helps.

    Best Regards,

    Hania Lian

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.