Backup BitLocker Keys to Azure AD

JADR_KT 21 Reputation points
2021-10-06T07:30:40.5+00:00

Is it possible to backup BitLocker recovery keys to Azure AD without an elevated privilege? Because right now, we have several devices that do not have recovery keys uploaded.

There is a Powershell script to upload this but it still requires to run as administrator. I want to deploy a script to a group of devices. I don't want to go to each one and backup their recovery keys manually.

Microsoft Security Intune Enrollment
{count} votes

2 answers

Sort by: Most helpful
  1. Reinout Dorreboom 106 Reputation points
    2021-10-06T11:51:14.973+00:00

    You can also use the Endpoint protection template for that I think.

    Configuration settings > Windows Encryption

    138128-image.png

    2 people found this answer helpful.

  2. Paul van Berlo 826 Reputation points
    2021-10-06T07:35:23.56+00:00

    Uploading the recovery keys is done as part of having the device (Hybrid) Azure AD Joined and managed in Microsoft Endpoint Manager (Intune), and should not require any additional permissions. I found a blog which may contain some more information that could be helpful.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.