Forum Discussion
Steve Whitcher
Aug 13, 2020Bronze Contributor
What admin role grans permission to view devices' bitlocker recovery keys?
Which of the standard admin roles is required to view bitlocker recovery keys for a device in intune?
Ken Rappold
Jan 27, 2021Brass Contributor
ReneZimmermann - Not thus far and haven't escalated this more than what you see in these posts. I may escalate when/if time allows.
Thijs Lecomte
Feb 01, 2021Bronze Contributor
Bitlocker keys are not a part of Intune, but of AAD. So you need an AAD role for them to see the keys. Helpdesk admin is one of the ways to do it
- Ken RappoldFeb 02, 2021Brass Contributor
Thijs Lecomte - Agree, but the https://docs.microsoft.com/en-us/mem/intune/protect/encrypt-devices states "
... you can view and manage BitLocker recovery keys when you view the encryption report. ... "
My input here is the data in the report should be made available via an RBAC permission. At a minimum, the Help Desk Role should be able to view the report and bitlocker recovery keys within.
- Thijs LecomteFeb 03, 2021Bronze ContributorI agree, it's a pain 😕
- Ken RappoldFeb 03, 2021Brass Contributor
Thijs Lecomte and overpermissioned when all we need is L1 to access BitLocker keys for users.