bitlocker
64 TopicsHow do I backup my bitlocker recovery key
Hi, I am using Microsoft windows 10 pro and I just noticed that my computer has bitlocker enabled by default, but I don't have the recovery key. I am afraid of losing my important data and I don't have any secondary copy of files. Is there any way to back up the key to safe place and what is the prefer way to store it. I will appreciate if someone will help in this.Solved61KViews0likes7CommentsBitlocker Failing to encrypt Error: -2016346112 (No Error Code)
I'm just learning Intune and I'm setting up everything for the first time. I setup BitLocker I have my settings below. On my Virtual machine that I connected with Autopilot, Bitlocker encrypted the drive just fine (even though I get the same error code above). What I mean is, I can look in the Virtual Machine and it shows the drive is encrypted fine. For my desktop/Physical machine, however, it is not encrypted and I get the same error. If I go into the Device information and click on the properties all the settings are successful except for "Encrypt Devices" and that has a state details of: -2016346112 (No Error Code) If I click on that line the sidebar comes out and it says error code: 0x87d10000 Searching on the Internet reveals ZERO answers. I'm not sure what is going on here. Can anyone shed some light on this? Edit: I should mention my desktop has two Hard Drives. I don't know if that matters. Edit 2: I am running TPM 2.0 it is a new dell mfg'd in December.53KViews0likes17CommentsBitlocker keys not visible in Active Directory
Hello, We are enabling Bitlocker in our environment. I had configured all policies related to Bitlocker inside AD. For example, i configured Bitlocker to not start until recovery key backed up to AD. This is the policy about i want to ask something. I want to ask something about this policy because i had an issue with this policy. It seems it not working well or i am missing some point in the configuration. Let me explain what i'm doing after this configuration: - I start Bitlocker encryption, Bitlocker encrypt correctly the Hard Disk. When encrypt finish, I can see the tab on AD called "Bitlocker Recovery", but, at the time I open this tab to request the key stored i get an information message : "There is no elements on this view, To search a recovery key press right button on object domain ... etc ... ". My question is, i know that bitlocker can not start if key is not backed up on AD, so Bitlocker is correctly performed the encryption and the key is backed up on AD. For any reason i can not see the key, even domain admins can not see it. So, how can i see this keys in AD? I need something more, maybe a plugin? a feature? I'm running Windows 10 1809 Professional and Active Directory v 10.0.171321. Any help is really welcome. Thanks in advance. Rgards.42KViews0likes1CommentBitLocker recovery key not being uploaded into Intune when using BackupToAAD-BitLockerKeyProtector
Hello, We are having an issue with the BackupToAAD-BitLockerKeyProtector PowerShell cmdlet to upload the BitLocker recovery key of our devices into AAD/Intune. We currently use Sophos Device Encryption to encrypt our devices but want to migrate the recovery keys into Intune as we transition to Intune BitLocker policies. We created a script that attempts to upload the BitLocker recovery key into Intune but it appears the BackupToAAD-BitLockerKeyProtector cmdlet only works on devices where the user logs in with a domain account, and not a local Windows account. Is this standard behaviour? I would have assumed that since the device is enrolled into Intune it would use the Management Extension to communicate with Intune for this task - and have no reliance on the logged in user. Looking at the BitLocker PowerShell module itself, a method named " BackupRecoveryInformationToCloudDomain" is called when this cmdlet is executed. I haven't been able to find much online about what happens beyond here. It would be good to know a bit more about this cmdlet as documentation is limited online. CheersSolved38KViews0likes7Comments