Jump to content

Recommended Posts

Posted

Hi all,

 

I'm having a mare with BitLocker, I have a Head Teacher who refuses to have her laptop domain joined and as such works on a local profile, her drive is TPM encrypted with BitLocker and her GPU has failed, no problems I think, I have the recovery keys stored on the Admin drive, so I plonk the drive in a USB caddy recovery key in hand ready to unlock and de-crypt the drive, enter the key once... didn't work, fair enough i think, its a long key must be a typo, so I try again and the same occurs, incorrect key, so I check the encryption ID and it no longer matches the one created at the time of encryption!!! I know its not my fault as the head should be domain joined, and as she doesn't keep a backup only has herself to blame but I cant help feeling responsible!

 

Is there any external usb>hdmi devices I can use to boot the laptop? Is there anything at all i can do? or am I clutching at straws?

 

Thanks!

Posted

Does it still power up and spin the disk with the blown GPU? Could you plug it into a monitor and see if anything appears.

 

My guess is it will still come up with bitlocker as the disk had been removed and re-added. Then try entering the key.

 

No need to feel responsible. You told them that it needed to be on domain and they said no, it's on their head. You need to make this clear if you can't get anything off of it, that if it was on domain you wouldn't of had this problem and still had the files!

Posted

Isn't the problem the lack of recovery key? I'd expect if I wipe the TPM or pull the drive out and enter the (correct) recovery key it'll work fine, isn't that the point of the recovery key?

 

As for this problem, don't know if the key has changed since it was encrypted - another reason why it should be domain joined, as they are all stored in AD. Guess it's a "tough you should let it be domain joined, and tough you should back up your data" lesson time for the head.

Posted
Does it still power up and spin the disk with the blown GPU? Could you plug it into a monitor and see if anything appears.

This would be your best option.

 

If you can't get any video output, and if the computer has been set to allow RDP or File Sharing, you could try and get the data that way. If a password has been set for bitlocker and not just TPM, turn it on and wait a little while, then type the password for it to boot into Windows.

 

Good luck.

Posted
have they signed into a microsoft account on it if so the recovery key may be stored there. i assume at some point they have re encrypted it if the key dosent match and if its connected to a ms account it prompts you to back the key up there iirc
Posted
Isn't the problem the lack of recovery key? I'd expect if I wipe the TPM or pull the drive out and enter the (correct) recovery key it'll work fine, isn't that the point of the recovery key?

 

That's what we have experienced. We have had hard drives swap machines & go in caddies. After being given the recovery key they will unlock.

Posted
I have a Head Teacher who refuses to have her laptop domain joined and as such works on a local profile

It's possible to have a domain joined laptop with a local profile. That's how our staff laptops are setup (with folder redirection for all folders except AppData).

 

What did the head not like about the laptop being domain joined? Too many restrictions?

Posted

Sorry for the late reply's, because of Virgin's exceptional service I have no internet at home!

 

Does it still power up and spin the disk with the blown GPU? Could you plug it into a monitor and see if anything appears.

My guess is it will still come up with bitlocker as the disk had been removed and re-added. Then try entering the key.

 

I have tried plugging it in to a Clevertouch, no video output at all, so other than the BIOS beeps I cant even tell if its getting past POST. We had this discussion a few years ago now, I'm sure they will have no relocation of the conversation and as such it will be on my head.

 

AFAIK unless you have backed up the data from the drive using some kind of backup solution, the data is indeed gone for good if the TPM fails. Happy to be proved wrong though

 

The thing is the TPM hasn't failed, frustratingly its the GPU :(

 

Isn't the problem the lack of recovery key? I'd expect if I wipe the TPM or pull the drive out and enter the (correct) recovery key it'll work fine, isn't that the point of the recovery key?

 

I have the recovery key as I saved it at the time of encryption, there's no reason at all I can think of for it not matching, unless foul play is considered, then I have no proof at all.

 

It's possible to have a domain joined laptop with a local profile. That's how our staff laptops are setup (with folder redirection for all folders except AppData).

What did the head not like about the laptop being domain joined? Too many restrictions?

That's how I set up my folder redirection as well, shes worried that if her laptop is domain joined using offline files, she wouldn't be able to work at home if something goes wrong with the setup, the Assistant Head also takes the same stance.

 

Thanks all,

 

Looks like I'm going to have to suck it up and tell her all her data is gone, hopefully she will let me domain join her new laptop with redirected folders and offline files.

Posted
just an FYI there are some services on ebay that reflow laptop motherboards and fix GPU issues. Could be worth a look? Usually around the £50 - £70 mark.
Posted (edited)
Is the laptop no useable at all? If it POSTS but just has no display you could try a USB to VGA and connect a monitor that way and then turn BitLocker off and then you can get the data. Edited by Fazza
Posted

If you lose the TPM to a motherboard failure or some such, then the [correct] recovery key will still let you access the drive. That's what it's for. If the recovery key ID you have doesn't match what the volume is asking for, then it's not the correct key. I'd check through all your stored keys for that ID, just to be certain that you don't have it somewhere.

 

You can update a BitLocker volume to be secured by a new TPM (e.g. after a motherboard replacement), so presumably you can update it to be secured by a new numerical key also. Given that it's not domain-joined, could your end user have privileges enough to have fiddled with BitLocker and ended up doing just that?

Posted
If the laptop is still bootable, just no screen, why can't you install a remote viewing tool on there? We have Dameware here, it can be installed remotely.

 

Since it's a non-domain laptop, it may be that simple file sharing is on, or no file sharing, which would mean the it wouldn't be able to install. That's why I stated in my example 'if the computer has been set to allow RDP or File Sharing'.

 

...

If you can't get any video output, and if the computer has been set to allow RDP or File Sharing, you could try and get the data that way. If a password has been set for bitlocker and not just TPM, turn it on and wait a little while, then type the password for it to boot into Windows...

Posted

if the identity doesn't match then the head altered something and didn't inform you. They're going to attempt to blame you for their error, more troublesome is that the head doesn't trust you.

 

They ignored your advice and they have the responsibility for loosing their data, unfortunately they're your boss, so you're up poo creek.

 

F

Posted
Since it's a non-domain laptop, it may be that simple file sharing is on, or no file sharing, which would mean the it wouldn't be able to install. That's why I stated in my example 'if the computer has been set to allow RDP or File Sharing'.

 

 

Most software wouldn't use File Sharing or RDP, they'd be using RPC, WMI or Powershell to do the install, and I don't think they can be disabled without serious effort.

Posted
Most software wouldn't use File Sharing or RDP, they'd be using RPC, WMI or Powershell to do the install, and I don't think they can be disabled without serious effort.

But on a non-domain laptop they'd be firewalled off by default, and not picking up GPO applied firewall policies to allow them. :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...