Bitlocker key not syncronized to AD.

Attila Bolvári 1 Reputation point
2021-06-07T10:37:17.55+00:00

Hy!

I have a problem with one of my laptops.
On the laptops i use bitlocker, and i forced to sync the keys from gpo to the AD.
But one laptop now prompting to get the recovery key but it isnt synced to the AD.
Is there any solution for this?
Thanks for the help!
bolvar

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,937 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,371 Reputation points Microsoft External Staff
    2021-06-08T00:35:50.633+00:00

    Hi,
    Based on my understanding, there is only one laptop that is not working correctly, right?

    Did the machine apply the GPO correctly?
    Please run the CMD as administrator and run the command: Gpresult /h c:\report.html on this machine and check if the Bitlocker GPO was applied.

    If possible, please share a screenshot here! (Please hide the private information)

    Best Regards,


  2. Salman Ahmed 1 Reputation point
    2021-06-10T08:38:00.443+00:00

    @Attila Bolvári

    Hi,

    I had the same issue with one of laptop (Windows 10 version 1709), where all the policies were updated properly, but still unable to send Bit Locker keys to AD. I have done the below steps to send it manually to AD, luckily its worked for me.

    Open CMD in elevated mode and type below:

    manage-bde -protectors -get X:   
    

    X is the drive letter for encrypted drive, you will get below:

    Password:
    ID: {B3DF5FBF-XXXX-XXXX-XXXX-XXXXXXXX4EA6}

    Numerical Password:
    ID: {01CA195D-XXXX-XXXX-XXXX-XXXXXXXXD731}

    Password: (You will see this, if encrypted drive is unlocked, and you have to unlock in order to manually sync to the AD)
    171171-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XX7466

    manage-bde -protectors -adbackup -id '{01CA195D-XXXX-XXXX-XXXX-XXXXXXXXD731}' e:  
    

    If you drive is unlocked; and there is group policy configured to allow the storage of recovery information to AD, your keys will be stored to AD.

    Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.