does bitlocker AD unlock from server 2008 schema continue if server updated to 2012r2?

Randy Morris 20 Reputation points
2023-02-07T18:26:06.3633333+00:00

We have some OU's with enforced BitLocker and a 48-ch unlock password stored in AD. Does that password still work if AD schema is upgraded from 08 to 12r2 or higher?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,932 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,586 Reputation points
    2023-02-07T22:17:38.4933333+00:00

    Hi @Randy Morris

    Based on my experience ,I confirm there is no impact on bitloker password stored in domain. I have already done this upgrade without any issue . It's even recommended to perform this upgrade in order to let your domain controllers 2008 R2 support AD DS backup of TPM information from Windows 8 clients or higher as mentioned in the microsft article:

    Schema Extensions for Windows Server 2008 R2 to support AD DS backup of TPM information from Windows 8 clients

    Please don't forget to mark helpful answer as accepted

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2023-02-07T20:47:44.34+00:00

    Looks like it should not be a problem.

    https://theitbros.com/config-active-directory-store-bitlocker-recovery-keys/

     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.