Backup BitLocker Key to Intune (EntraID) for non-admin users

Mountain Pond 1,391 Reputation points
2024-05-31T15:20:53.1433333+00:00

Hello, devices in the organization are encrypted with BitLocker. However, in Entra I do not see the recovery key for all machines.

I could give users instructions on how to make a backup in Azure. However, they are not administrators and cannot perform such actions, including retrieving the key.

I haven't found a way to delegate control to BitLocker. There is an option that allows you to interact with the user during encryption, but I am not sure that it allows you to make a copy of the key.

Perhaps someone knows how to save current keys in Azure? A PowerShell script is welcome, or rather, perhaps someone knows a command that initiates a backup copy of a key? I'll write the script myself :)

Thank you.

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,744 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,644 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,281 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Carlos Solís Salazar 17,536 Reputation points MVP
    2024-06-06T15:41:54.0066667+00:00

    Hi @Mountain Pond

    With the May (2405) service release of Microsoft Intune, users can access their BitLocker recovery keys via the Intune Company Portal website. More info here

    I hope this helps!

    Remember to accept the answer if it is helpful.

    0 comments No comments