Forum Discussion
What admin role grans permission to view devices' bitlocker recovery keys?
Ken Rappold Have you ever found a solution for that?
I'm also trying to give our service desk guys the ability to retrieve Bitlocker keys out of Intune (Endpoint Manager), but giving almost all "Read" rights with a custom role, they still get an error, as soon as they click on "Recovery keys".
ReneZimmermann - Not thus far and haven't escalated this more than what you see in these posts. I may escalate when/if time allows.
- Thijs LecomteFeb 01, 2021Bronze ContributorBitlocker keys are not a part of Intune, but of AAD. So you need an AAD role for them to see the keys. Helpdesk admin is one of the ways to do it
- Ken RappoldFeb 02, 2021Brass Contributor
Thijs Lecomte - Agree, but the documentation states "
... you can view and manage BitLocker recovery keys when you view the encryption report. ... "
My input here is the data in the report should be made available via an RBAC permission. At a minimum, the Help Desk Role should be able to view the report and bitlocker recovery keys within.
- Thijs LecomteFeb 03, 2021Bronze ContributorI agree, it's a pain 😕