How to Use the Administration and Monitoring Website

The Administration and Monitoring Website, also referred to as the Help Desk, is an administrative interface for BitLocker Drive Encryption. Use the website to review reports, recover end users’ drives, and manage end users’ TPMs, as described in the following sections.

Note   If you are using MBAM in the Stand-alone topology, you view all reports from the Administration and Monitoring Website. If you are using the Configuration Manager Integration topology, you view all reports in Configuration Manager, except the Recovery Audit report, which you continue to view from the Administration and Monitoring Website. For more information about reports, see Monitoring and Reporting BitLocker Compliance with MBAM 2.5.

Required roles for using the Administration and Monitoring Website

To access specific areas of the Administration and Monitoring Website, you must have one of the following roles, which are groups that you create in Active Directory. You can use any name for these groups.

Account Description

MBAM Advanced Helpdesk Users

Provides access to all areas of the Administration and Monitoring Website. Users who have this role enter only the recovery key, and not the end user’s domain and user name, when helping end users recover their drives. If a user is a member of both the MBAM Helpdesk Users group and the MBAM Advanced Helpdesk Users group, the MBAM Advanced Helpdesk Users group permissions override the MBAM Helpdesk Users Group permissions.

MBAM Helpdesk Users

Provides access to the Manage TPM and Drive Recovery areas of the Administration and Monitoring Website. Individuals who have this role must fill in all fields, including the end-user’s domain and account name, when they use either area.

If a user is a member of both the MBAM Helpdesk Users group and the MBAM Advanced Helpdesk Users group, the MBAM Advanced Helpdesk Users group permissions override the MBAM Helpdesk Users Group permissions.

MBAM Report Users

Provides access to the reports in the Reports area of the Administration and Monitoring Website.

Tasks you can perform on the Administration and Monitoring Website

The following table summarizes the tasks you can perform on the Administration and Monitoring Website and provides links to more information about each task.

Task Area of the Website where you access the task Description For more information

View reports

Reports

Enables you to run reports to monitor BitLocker usage, compliance, and key recovery activity. Reports provide data about enterprise compliance, individual computers, and who requested recovery keys or the TPM OwnerAuth package for a specific computer.

Viewing MBAM 2.5 Reports for the Stand-alone Topology

Determine the BitLocker encryption status of lost or stolen computers

Reports

Determine if a volume was encrypted if the computer is lost or stolen.

How to Determine BitLocker Encryption State of Lost Computers

Recover lost drives

Drive Recovery

Recover drives that are:

  • In recovery mode

  • Have been moved

  • Are corrupted

Reset a TPM lockout

Manage TPM

Provides access to TPM data that has been collected by the MBAM Client. In a TPM lockout, use the Administration and Monitoring Website to retrieve the necessary password file to unlock the TPM.

How to Reset a TPM Lockout

Performing BitLocker Management with MBAM 2.5

Got a suggestion for MBAM?

For MBAM issues, use the MBAM TechNet Forum