Jump to content

Recommended Posts

Posted

I'm setting up a new win10 1903 machine and as this is for the admin office I'm enabling bitlocker. Normally I store the keys on a network drive that only I have access to but on this machine when I try to save the key only the C:\ drive is listed i.e. no network drives at all. I've tried two different logins and both the same. All mapped drives listed correctly in explorer.

 

Anyone come across this?

Posted

Thanks guys. I must confess I never got AD to store the keys before today even though GP was set to so I thought it must not be compatible with server 2012.

 

I checked GP settings and found the error, it had store keys in AD but for server 2008.

Posted
As well as storing in AD, we always take a manual backup of the key after imaging and store it on a network drive. You can set the default folder for manually backing up keys using GP, so that you're not having to browse for it each time.
Posted
I decided to use MBAM for BitLocker instead of storing the keys in AD. MBAM uses a SQL database to store the keys, integration into SCCM and also has a web-portal to easily recover keys. You can also browse the database manually for keys if necessary. The reason I chose MBAM over storing them in AD was in-case a computer or user account was deleted and the key lost with it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...