On-Prem joined domain PCs does not have option to save Bitlocker Recovery Key to Azure AD Account

DR_DR 1 Reputation point
2022-03-16T15:10:58.877+00:00

Hi,

Registered AD Joined PCs(On-Prem AD joined domain), I do not have way to save Bitlocker Recovery Key to Azure AD Account.
When I dis-join from the On-Prem AD, I have options to save them to Azure AD but as soon as joined back to the On-Prem AD domain, I do not have the option to save Azure AD account.

Is there any GPO that is blocking or enable that we can save bitlocker recovery key to Azure AD account?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,326 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 33,801 Reputation points Microsoft Employee
    2022-03-21T21:54:25.11+00:00

    Hi @DR_DR ,

    I understand that you are having trouble saving a Bitlocker Recovery Key to an Azure AD account.

    The recovery keys are uploaded when the device is hybrid Azure AD Joined and managed in Microsoft Endpoint Manager (Intune) via Autopilot.

    If the devices were already Bitlockered, you need to use an Endpoint protection template to save the Bitlocker recovery information to Azure AD under Admin center > Devices > Configuration Profiles > Create Profile > Templates > Endpoint protection >Configuration settings > Windows Encryption > Save BitLocker recovery information to Azure Active Directory

    185385-image.png

    See also:
    Store BitLocker Recovery Keys in Azure AD for Devices Already Encrypted
    Backup BitLocker Keys to Azure AD
    Powershell script for Backing up Bitlocker key to Azure AD

    0 comments No comments