BitLocker key not saving at azure ad account

Eyal Tzaig 20 Reputation points
2024-10-07T06:22:38.5966667+00:00

Hey,

There are two Windows machines in my organization that do not have their bitlocker keys saved in their AD accounts.

When they click on the option to save it to the ad account, it appears as though it is saved, but I cannot find it in the portal.

Is there anyone who knows why this is happening?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,079 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 48,746 Reputation points Microsoft Vendor
    2024-10-07T07:41:13.24+00:00

    @Eyal Tzaig, Thanks for posting in Q&A. For the two affected devices, please ensure the following policy setting is enabled when deploy BitLocker policy from Intune to them.

    User's image

    Sync on the device side, Settings-> Accounts->Access work or school, the account, info, click sync to see if it can appear on Microsoft Entra ID (AAD) device record after some time.

    On the other hand, you can try "BackupToAAD-BitLockerKeyProtector" to manually save recovery key to AAD device record.

    https://learn.microsoft.com/en-us/powershell/module/bitlocker/backuptoaad-bitlockerkeyprotector?view=windowsserver2022-ps

    Or you can also consider this script to do this.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.