solution to enable BitLocker and save credentials to on-perm active directory?

Eaven HUANG 2,196 Reputation points
2022-09-01T03:03:12.327+00:00

Dear expert,

We are exploring the possibility to enable BitLocker to encrypt our users' drives.
BitLocker seems to be a good solution but

  1. Can we save the credentials to local AD?
  2. Do we need to have all the computers have physical TPM in place first?
  3. Can AD admins unlock the drives when needed?

Thanks a lot in advance.

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. T. Kujala 8,796 Reputation points
    2022-09-01T04:02:54.243+00:00

    Hi @Eaven HUANG ,

    We have done this with GPO.

    Here is a quite good guide for that.

    Can we save the credentials to local AD?

    Yes.

    Do we need to have all the computers have physical TPM in place first?

    Without TPM it's hard.

    Can AD admins unlock the drives when needed?

    Yes.


  2. Limitless Technology 40,076 Reputation points
    2022-09-02T07:40:11.657+00:00

    Hello there,

    You need physical TPM for BitLocker to work

    In a domain network, you can store the BitLocker recovery keys for encrypted drives in the Active Directory Domain Services (AD DS). This is one of the greatest features of the BitLocker Drive Encryption technology for corporate users.

    You should verify if your AD schema version has attributes required to store BitLocker recovery keys in Active Directory.

    ------------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.