Jobos Posted June 27, 2019 Posted June 27, 2019 I'm setting up a new win10 1903 machine and as this is for the admin office I'm enabling bitlocker. Normally I store the keys on a network drive that only I have access to but on this machine when I try to save the key only the C:\ drive is listed i.e. no network drives at all. I've tried two different logins and both the same. All mapped drives listed correctly in explorer. Anyone come across this?
Hybrid Posted June 27, 2019 Posted June 27, 2019 I don't think you can do that by design. You need to change a GPO if you want to save BitLocker keys onto a mapped drive. I've just always saved them onto a non-encrypted USB stick or non-encrypted drive and moved them off after that. https://social.technet.microsoft.com/Forums/windows/en-US/bc437c96-0891-4f8b-8919-71c34c0002f5/cannot-save-bitlocker-recover-key-to-mapped-drive?forum=w7itprosecurity
gmonks Posted June 27, 2019 Posted June 27, 2019 You can also have the recovery keys stored in AD. I do here, I've found it really useful on more than one occasion. Store Bitlocker Recovery Keys in AD. 2
crc-ict Posted June 27, 2019 Posted June 27, 2019 You can also have the recovery keys stored in AD. I do here, I've found it really useful on more than one occasion. Store Bitlocker Recovery Keys in AD. +1 for this. Really useful.
Jobos Posted June 27, 2019 Author Posted June 27, 2019 Thanks guys. I must confess I never got AD to store the keys before today even though GP was set to so I thought it must not be compatible with server 2012. I checked GP settings and found the error, it had store keys in AD but for server 2008.
jthompson Posted June 28, 2019 Posted June 28, 2019 As well as storing in AD, we always take a manual backup of the key after imaging and store it on a network drive. You can set the default folder for manually backing up keys using GP, so that you're not having to browse for it each time.
CHiLL Posted June 28, 2019 Posted June 28, 2019 I decided to use MBAM for BitLocker instead of storing the keys in AD. MBAM uses a SQL database to store the keys, integration into SCCM and also has a web-portal to easily recover keys. You can also browse the database manually for keys if necessary. The reason I chose MBAM over storing them in AD was in-case a computer or user account was deleted and the key lost with it.
PotNoodleTech Posted June 28, 2019 Posted June 28, 2019 You can also have the recovery keys stored in AD. I do here, I've found it really useful on more than one occasion. Store Bitlocker Recovery Keys in AD. This is great just want I want to do. Thanks!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now