Forum Discussion

Andrew Matthews's avatar
Andrew Matthews
Iron Contributor
Aug 08, 2018
Solved

Audit Log for BitLocker Recovery Keys in Azure AD

Escrowing BitLocker recovery keys to Azure AD is great functionality but I have been asked to find an audit trail when a user or administrator accesses the recovery keys. The IT Security function at ...
  • Gian202b's avatar
    Mar 26, 2021

    Andrew Matthews In case anyone else is looking for this feature - It seems it was added late last year in Azure AD.

     

    AUDITED BITLOCKER RECOVERY IN AZURE AD PUBLIC PREVIEW
    Service category: Device Access Management
    Product capability: Device Lifecycle Management

    When IT admins or end users read BitLocker recovery key(s) they have access to, Azure Active Directory now generates an audit log that captures who accessed the recovery key. The same audit provides details of the device the BitLocker key was associated with.

    End users can access their recovery keys via My Account. IT admins can access recovery keys via the BitLocker recovery key API in beta or via the Azure AD Portal.

    https://dirteam.com/sander/2020/10/06/whats-new-in-azure-active-directory-in-september-2020/

Resources