Forum Discussion
Steve Whitcher
Aug 13, 2020Bronze Contributor
What admin role grans permission to view devices' bitlocker recovery keys?
Which of the standard admin roles is required to view bitlocker recovery keys for a device in intune?
ReneZimmermann
Jan 27, 2021Copper Contributor
Ken Rappold Have you ever found a solution for that?
I'm also trying to give our service desk guys the ability to retrieve Bitlocker keys out of Intune (Endpoint Manager), but giving almost all "Read" rights with a custom role, they still get an error, as soon as they click on "Recovery keys".
Ken Rappold
Jan 27, 2021Brass Contributor
ReneZimmermann - Not thus far and haven't escalated this more than what you see in these posts. I may escalate when/if time allows.
- Thijs LecomteFeb 01, 2021Bronze ContributorBitlocker keys are not a part of Intune, but of AAD. So you need an AAD role for them to see the keys. Helpdesk admin is one of the ways to do it
- Ken RappoldFeb 02, 2021Brass Contributor
Thijs Lecomte - Agree, but the documentation states "
... you can view and manage BitLocker recovery keys when you view the encryption report. ... "
My input here is the data in the report should be made available via an RBAC permission. At a minimum, the Help Desk Role should be able to view the report and bitlocker recovery keys within.
- Thijs LecomteFeb 03, 2021Bronze ContributorI agree, it's a pain 😕