automate backup of bitlocker recovery key

satya mahapatra 6 Reputation points

i have bitlocker running and its recovery key getting backup. few are mssing.
I want some script \batch file so recovery key can be backed up to ad
manage-bde -protectors -get c:
manage-bde -protectors -adbackup c: -id {DFB478E6-8B3F-4DCA-9576-C1905B49C71E}
here in ID will be dynamic as pc to pc.
if any batch or script can do this?

Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
4,628 questions
No comments
{count} votes

2 answers

Sort by: Most helpful
  1. MTG 911 Reputation points
    for /f "tokens=1,2" %%a in ('manage-bde -protectors -get C: -Type recoverypassword ^| findstr ID') do manage-bde -protectors -adbackup c: -id %%b  
    No comments

  2. Limitless Technology 37,351 Reputation points


    Thank you for your question and reaching out. I can understand you are having query related to Bitlocker recovery saving to AD.

    Mehod 1:
    You can also only set the configuration in the GPO:

    Computer configuration\Windows Components\Bitlocker drive Encryption\OS Drive\Save Bitlocker Key in AD DS

    Method 2:

    PowerShell script (Copy and save as .ps1) so that it can be used in group policy or SCCM

    $BLV = Get-BitLockerVolume -MountPoint $env:SystemDrive
    foreach($keyProtector in $BLV.KeyProtector){
    if($keyProtector.KeyProtectorType -eq “RecoveryPassword”){
    }$result = Backup-BitLockerKeyProtector -MountPoint “$($env:SystemDrive)” -KeyProtectorId $KeyProtectorID
    return $true
    return $


    --If the reply is helpful, please Upvote and Accept as answer--

    No comments