Delegate Access to BitLocker Recovery Keys in Active Directory

Bernard Rizkallah 5 Reputation points
2023-02-10T08:40:18.3866667+00:00

Good Day,

i have applied the Delegate Access on a specific group in my AD but it is not affecting the users permission even if i apply on a specific user.

purpose that i want the support team to be able to only see the BitLocker Key stored in the AD, which is pulled by a GPO from the client side.

msFVE-RecoveryInformation objects with Full Control Permissions.

Could anyone support?

User's image

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
{count} vote

1 answer

Sort by: Most helpful
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2023-02-13T10:38:09.03+00:00

    Hi @Bernard Rizkallah

    You can follow the link below , to delegate a group to read biloker attributs :

    Delegate Access to BitLocker Recovery Keys in Active Directory

    How to Delegate BitLocker Recovery Information in AD (properly) - Step by Ste

    In DSA.msc GUI , ask support team to click on advanced Features and go to Attribut Editor to check if they are able to read Bitlocker attribut:

    enable Advanced Features in ADUC snap-in

    Please don't forget to mark helpful answer as accepted


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.