Bitlocker (2024)

This document has an overview of Bitlocker, explains how to enable storage of bitlocker recovery keys to the NETID domain via group policy, and how to recover those recovery keys when needed.

Introduction to Bitlocker

Using Bitlocker on systems in a Delegated OU is recommended for any system which is regularly used to interact with restricted or confidential data. Bitlocker provides at-rest volume-level data encryption.

To be secure, Bitlocker requires a Trusted Platforms Module (TPM) 1.2 or newer chip. Bitlocker can be used without a TPM, but this is not as secure.

The TPM chip allows the volume based encryption to check whether the computer has been tampered with, and trigger a recovery mode if it detects that it has been tampered with.

Bitlocker recovery mode can be triggered by a number of situations, including:

  • A malicious attempt by a person or software to change the startup environment. Rootkits are one example.
  • Moving the BitLocker-protected drive into a new computer.
  • Installing a new motherboard with a new TPM.
  • Turning off, disabling, or clearing the TPM.
  • Updating the BIOS.
  • Upgrading critical early boot components that cause system integrity validation to fail.
  • Forgetting the PIN when PIN authentication has been enabled.
  • Losing the USB flash drive containing the startup key when startup key authentication has been enabled.
  • Having a USB drive in at startup (this can be fixed by removing the USB drive at bootup).

When Bitlocker recovery mode is triggered, you must provide the recovery keys to get access to the Bitlocker enabled volumes on the computer. The recovery keys are provided to the user enabling Bitlocker, and can optionally also be written to AD.

It is a good idea to write Bitlocker recovery keys to AD, because users can often have a hard time keeping track of the recovery keys for when they later need them; it enables IT support personnel to help users when they run into Bitlocker recovery mode. When the recovery keys are written to AD, only users who have full permissions to your computer objects can read them. By default, this is your OU Admins, the NETID domain admins, and whoever created the computer account.

Microsoft’s BitLocker Drive Encryption documentation provides a good introduction and background material for Windows 7 that you might want to review. See BitLocker for the equivalent Windows 8 documentation and BitLocker for the equivalent Windows 10 documentation.

How to Enable AD-based Storage of Recovery Keys

To enable AD-based storage of your Bitlocker recovery keys, you’ll need to do the following:

Create a GPO linked to your delegated OU which enables the following settings:

  1. Computer Configuration\Policies\Administrative Templates\Windows Components\MDOP MBAM (Bitlocker Management)\Operating System Drive\Choose how BitLocker-protected operating system drives can be recovered = Enabled
  2. Under options set the following:
    1. Save BitLocker recovery information to AD DS for operating system drives: Box checked
    2. (Recommended) Do not enable BitLocker until recovery information is stored to AD DS for operating system drives: Box checked
  3. There are similar settings for Fixed and Removable Data Drives

The setting “Do not enable BitLocker until recovery information is stored to AD DS for operating system drives” is not technically required in order to store your keys in Active Directory. However,We recommend that you enable this setting, because if you don’t, you’ve lost your assurance that this information will be available for recovery when needed. For more information, see the Microsoft BitLocker Group Policy Settings document.

What to do when Bitlocker Drive Enable happened BEFORE joining the NETID domain

    1. Ensure that you’ve enabled AD-based Storage of Recovery Keys as described above.

Method 1

  1. If you have a current PowerShell environment, these two lines will back up the recovery key for a volume called “C:” to AD:

$BLV = Get-BitLockerVolume -MountPoint “C:”

Backup-BitLockerKeyProtector -MountPoint “C:” -KeyProtectorId $BLV.KeyProtector[1].KeyProtectorId

Method 2

  1. Open an elevated command prompt on the system.
  2. Run the command:
    manage-bde -protectors c: -get
  3. You will receive output similar to this:

    BitLocker Drive Encryption: Configuration Tool version 6.1.7600
    Copyright (C) Microsoft Corporation. All rights reserved.
    Volume C: [Windows]
    All Key ProtectorsNumerical Password:
    ID: {9557D616-0BD0-4B2A-8A2A-9DD4C5C21CCC}
    Password:
    527560-068585-114378-134288-010131-496430-662706-631224TPM:
    ID: {5EB69F42-4ABC-4D6B-87C5-C894A3840FC4}
    What you are looking for is the Numerical Password ID.
  4. In this example to backup the password to AD you would type the following command: manage-bde -protectors c: -adbackup -id {9557D616-0BD0-4B2A-8A2A-9DD4C5C21CCC}
  5. When that completes you will receive the message: Recovery information was successfully backed up to Active Directory.

    The documentation for manage-bde states you do not have to specify the ID but, in fact, you do.

How To Recover AD-based Storage of Recovery Keys

For Windows 8 and Later

Send an email to help@uw.edu to request assistance in obtaining a computer’s recovery key.

For Windows 7 and Earlier

To obtain the Bitlocker recovery key for a computer which has stored it in AD, run the Get-BitLockerRecoveryInfo.vbs script.

You will only be able to obtain a recovery password from AD for computers in your delegated OU. Domain admins are capable of recovering any recovery password in AD, if for some reason your OU admins are unavailable.

Usage: Get-BitLockerRecoveryInfo.vbs [computername]

If [computername] is omitted, the script assumes the local computer.

For example:

C:\bin>Get-BitLockerRecoveryInfo.vbs naboo
Microsoft (R) Windows Script Host Version 5.8
Copyright (C) Microsoft Corporation. All rights reserved.

Accessing object: LDAP://CN=NABOO,OU=pottery,DC=netid,DC=washington,DC=edu

name: 2007-10-23T13:44:12-08:00{62E83AE2-DB9F-4B4E-BC7C-2ED057E13FC4}
msFVE-RecoveryGuid: {62E83AE2-DB9F-4B4E-BC7C-2ED057E13FC4}
msFVE-RecoveryPassword: 327679-031823-308099-108900-464640-385660-335214-476806

Bitlocker (2024)

FAQs

How to solve BitLocker issue? ›

Steps to Troubleshoot BitLocker Issues
  1. Step 1: Identifying the issue. ...
  2. Step 2: Gathering information about the issue. ...
  3. Step 3: Verifying the TPM and BitLocker Configuration. ...
  4. Step 4: Checking for updates and applying fixes. ...
  5. Step 5: Testing the solution. ...
  6. BitLocker Encryption Failure. ...
  7. BitLocker Suspension.
Sep 27, 2023

How do I break BitLocker recovery loop? ›

How to bypass BitLocker recovery screen on startup?
  1. Method 1: Suspend BitLocker protection and resume it.
  2. Method 2: Remove the protectors from the boot drive.
  3. Method 3: Enable the secure boot.
  4. Method 4: Update your BIOS.
  5. Method 5: Disable the secure boot.
  6. Method 6: Use legacy boot.

Why is my PC asking for BitLocker recovery key? ›

Whenever you connect a drive to your PC and it is detected in the boot list, BitLocker will ask for the recovery key. If you're not connecting any devices and it keeps asking for the recovery key, it is because the boot support for Preboot for TBT and USB-C/TBT is turned on by default.

Why is my computer not accepting BitLocker recovery key? ›

If you encounter the correct BitLocker recovery key not working, try getting out of the BitLocker recovery screen via the manage-bde command. It can be used to unlock the drive and disable BitLocker. Many users have proven that the “BitLocker not accepting recovery key” issue can be solved in this way.

How do I override BitLocker? ›

Click Start, click Control Panel, click System and Security, and then click BitLocker Drive Encryption. Look for the drive on which you want BitLocker Drive Encryption turned off, and click Turn Off BitLocker. A message will be displayed, stating that the drive will be decrypted and that decryption may take some time.

How do I force BitLocker off? ›

Press Windows Start button. Type bitlocker. Click Manage BitLocker to enter the BitLocker Drive Encryption menu. Select Turn off BitLocker to proceed with decryption.

How to get out of BitLocker recovery without a key? ›

If you are unable to locate the BitLocker recovery key and can't revert any configuration change that might have caused it to be required, you'll need to reset your device using one of the Windows recovery options. Resetting your device will remove all of your files.

How do I get my BitLocker recovery key when locked out? ›

If you get a message saying You are locked out. Enter the recovery key to get going again, you will need to use another device with internet to continue. Select your name, then select profile to show a list of your linked devices. Select Get BitLocker keys and you will see two key codes.

How to unlock BitLocker? ›

To unlock their drives, users must open “This PC” (or “My Computer”, depending on the version of Windows), right-click on the encrypted drive icons with the locked yellow padlock icon, click "Unlock Drive" and provide the Password.

How to stop BitLocker recovery key prompt? ›

Fix 7: Disable Auto-Unlock Option

This can cause the BitLocker to keep asking for a recovery key. So this is how you can turn it off. Step 1: Go to the Start button, then to the control panel > Bitlocker drive encryption. Step 2: Then click on the "turn off auto-unlock" option given next to the C drive.

How do I find my 48 digit recovery key? ›

Go to the Microsoft "Bitlocker Recovery Key" site. http://go.microsoft.com/fwlink/?LinkId=237614 When you sign in with your personal Microsoft account, the Bitlocker Recovery Key screen appears. Keep that recovery key (a 48 digit number), for example, by writing it down on a note.

How to get out of BitLocker recovery loop? ›

To terminate this BitLocker recovery loop, BitLocker must be suspended from within WinRE. To do so, follow these steps: On the page where you are asked to enter the recovery key, select the Skip this drive link at the bottom. You should be presented with a menu that will let you get to a command prompt.

How to fix BitLocker issues? ›

Check the BitLocker prerequisites
  1. The TPM must be unlocked. Check the output of the get-tpm PowerShell cmdlet command for the status of the TPM.
  2. Windows RE must be enabled. Check the output of the reagentc.exe command for the status of WindowsRE.
  3. The system-reserved partition must use the correct format.
Dec 26, 2023

Does the BitLocker recovery key expire? ›

Bitlocker keys don't expire. The only time you would need to do this is when the machine protected by Bitlocker is reimaged or the TPM subsystem is reset in some way.

How do I get my computer out of BitLocker mode? ›

Follow the below-mentioned steps to know how to do the same:
  1. Open your Windows system's "Control Panel" utility using your preferred method.
  2. Once Control Panel is opened, go to its "System and Security" section.
  3. Click on "BitLocker Drive Encryption" and "Suspend Protection" to temporarily turn off BitLocker. That's it!
Jul 24, 2024

What causes BitLocker to trigger? ›

The BitLocker recovery key prompt can be triggered by a variety of reasons, including hardware changes, software updates (especially if BIOS update is involved), etc. It is not necessarily alarming. The recent security update can be definitely a trigger here as well.

How to fix BitLocker suspended? ›

In the Command Prompt window, type the following command and hit Enter.
  1. manage-bde -protectors –disable [drive letter:]
  2. manage-bde -protectors -enable [drive letter:]
  3. chkdsk [drive letter]: /f /r /x.
  4. repair-bde [drive letter:] [output drive letter:] -rp [BitLocker Recovery Key]
Jun 14, 2024

Top Articles
Mobile Home Loans: Your Quick Guide To Financing A Mobile Or Manufactured Home
This Is How Long Your Cash Physically Lasts
Tabc On The Fly Final Exam Answers
1movierulzhd.fun Reviews | scam, legit or safe check | Scamadviser
Co Parts Mn
Kagtwt
Hmr Properties
Dumb Money
Bestellung Ahrefs
Where does insurance expense go in accounting?
Los Angeles Craigs List
Bowie Tx Craigslist
7543460065
Midlife Crisis F95Zone
Connect U Of M Dearborn
Idaho Harvest Statistics
How to Create Your Very Own Crossword Puzzle
Sadie Proposal Ideas
623-250-6295
Apply for a credit card
Yisd Home Access Center
Slim Thug’s Wealth and Wellness: A Journey Beyond Music
Atlases, Cartography, Asia (Collection Dr. Dupuis), Arch…
Craig Woolard Net Worth
100 Gorgeous Princess Names: With Inspiring Meanings
WPoS's Content - Page 34
Will there be a The Tower season 4? Latest news and speculation
Cvs Sport Physicals
The Creator Showtimes Near Baxter Avenue Theatres
Ridge Culver Wegmans Pharmacy
Little Caesars Saul Kleinfeld
Memberweb Bw
Beth Moore 2023
Arcane Odyssey Stat Reset Potion
Sinai Sdn 2023
The Best Restaurants in Dublin - The MICHELIN Guide
Anya Banerjee Feet
968 woorden beginnen met kruis
Ferguson Employee Pipeline
Tyler Perry Marriage Counselor Play 123Movies
Janaki Kalaganaledu Serial Today Episode Written Update
Seven Rotten Tomatoes
Who Is Responsible for Writing Obituaries After Death? | Pottstown Funeral Home & Crematory
Executive Lounge - Alle Informationen zu der Lounge | reisetopia Basics
13 Fun & Best Things to Do in Hurricane, Utah
Panolian Batesville Ms Obituaries 2022
Chubbs Canton Il
tampa bay farm & garden - by owner "horses" - craigslist
Naomi Soraya Zelda
Heat Wave and Summer Temperature Data for Oklahoma City, Oklahoma
Wera13X
Latest Posts
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 6150

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.