Jump to content

Recommended Posts

Posted

Hi all

 

I had reimaged some Laptops few weeks ago using MDT and noticed few machines have bitlocker prompt randomly!

 

No hardware has been changed so not sure reason but where can i find bitclocker key? i can see on some laptops the text file on root of C:

 

Can i tweak MDT so it saves the file on server somewhere?

Posted

You have a few options.

 

1) Setup MDT to save bitlocker keys to Active Directory during imaging. This would require making sure AD is setup to receive bit locker keys and your MDT task sequence has an enable bitlocker task ticked to save the key to active directory. You may need to set the correct group policies for the machines you're imaging also to make sure you can save the key.

 

2) Setup MBAM which seems to be the more modern method. I don't have any experience in this so can't help but will likely move to it at some point.

Posted

I use this. Stores the recovery key in the computer object in AD.

 

Screenshot 2022-07-20 153235.png

 

Very useful for when a member of staff encrypts an external drive and then forgets the password!

Posted
Ah does this also store external drive keys too?

 

It does! In the computer object of the device it was encrypted on but I find it’s easier just to search for the recovery ID in AD.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...