bitlocker recovery key location question

HK G 516 Reputation points
2023-06-27T18:30:18.7733333+00:00

We use Intune policy for Bitlocker for clients. And we obviously can see the key in the Azure portal. However, I am also see the same recovery in our on-premise AD which we do not have any GPO for Bitlocker. Can someone explain why the same keys shows up in both directory even though we only use Intune for the setup?

Thanks

Windows for business Windows Client for IT Pros Directory services Active Directory
Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Intune Other
{count} votes

Accepted answer
  1. Limitless Technology 44,751 Reputation points
    2023-06-28T12:00:00.4933333+00:00

    Hello HK G,

    Thank you for your question and for reaching out with your question today.

    If you are seeing BitLocker recovery keys in both the Azure portal and your on-premises Active Directory (AD), it's likely because of the integration between Azure Active Directory (Azure AD) and on-premises AD using Azure AD Connect.

    When you use Intune to enforce BitLocker encryption on client devices, the recovery keys are stored in Azure AD. Azure AD Connect is a tool that synchronizes user accounts and device information between on-premises AD and Azure AD. As part of this synchronization, the BitLocker recovery keys from Azure AD can also be synchronized to the on-premises AD.

    By default, Azure AD Connect syncs several attributes, including BitLocker recovery information, from Azure AD to the on-premises AD. This synchronization helps maintain a consistent and centralized view of user and device information across both environments.

    The synchronization of BitLocker recovery keys to the on-premises AD allows organizations to have a backup and recovery option in case of any issues with Azure AD or when accessing the on-premises environment is necessary. It provides an additional layer of redundancy and ensures that the recovery keys are available locally in your on-premises infrastructure.

    It's important to note that the synchronization of BitLocker recovery keys is a default behavior of Azure AD Connect. If you don't want the recovery keys to be synchronized to your on-premises AD, you can modify the synchronization rules in Azure AD Connect to exclude certain attributes from being synchronized.

    In summary, the presence of BitLocker recovery keys in both Azure AD and your on-premises AD is a result of the synchronization process facilitated by Azure AD Connect, providing redundancy and backup options for recovery key management.

    I used AI provided by ChatGPT to formulate part of this response. I have verified that the information is accurate before sharing it with you.

    If the reply was helpful, please don’t forget to upvote or accept as answer.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.