Can't retrieve Bitlocker recovery keys

MuddyMayor-5788 260 Reputation points
2023-09-13T17:33:02.6866667+00:00

Hi all,

We have many devices installed with Windows 10 21H2 and 22H2 operating systems. The devices are joined to AAD. However, some of them don't show the Bitlocker recovery keys in Intune or AAD, other devices do have Bitlocker recovery keys. Do you know why? How can we store Bitlocker recovery keys in Intune for all the devices?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,879 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Simon Ren-MSFT 33,451 Reputation points Microsoft Vendor
    2023-09-14T01:54:07.5733333+00:00

    Hi,

    Thank you for posting in Microsoft Q&A forum.

    1,BitLocker recovery keys are only saved to AAD or AD at the time they are set (or reset). Thus, we can either rotate them (which can be done using Intune) or send a script to them to force them to save their keys to AAD. Just simply push a PowerShell script to the devices without recovery keys to force the escrow of the recovery keys to AAD. Refer to:

    How to force escrowing of Bitlocker recovery keys using Intune

    Get Intune devices with missing BitLocker keys in Azure AD

    2,If it doesn't work, please check the DeviceManagement-Enterprise-Diagnostic-Provider event log and Applications and Services Logs > Microsoft > Windows > BitLocker-API event log.

    For more information, please refer to:

    Using BitLocker recovery keys with Microsoft Endpoint Manager - Microsoft Intune

    Thanks for your time. Have a nice day!

    Best regards,

    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Simon Ren-MSFT 33,451 Reputation points Microsoft Vendor
    2023-09-19T07:44:25.3933333+00:00

    Hi,

    Hope everything goes well. Do you need any further assistance about this issue? If yes, please feel free to let us know, we will do our best to help you.

    If the response is helpful, it's appreciated that you could click "Accept Answer" and upvote it, this will help other users to search for useful information more quickly.

    Thanks for your time.

    Best regards,

    Simon

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.