Jump to content

Recommended Posts

Posted

Devices using the legacy MBAM have the KeyRecoveryServiceEndPoint entry and configured in the registry, pointing to the legacy MBAM server. Though on my test device, I've removed all MBAM GPOs and pushed the (correct as far as I can tell) BitLocker configuration baselines to the device. I can see that CM takes over, as the baseline shows and is evaluated as compliant, but the KeyRecoveryServiceEndPoint registry entry is missing. The recovery key is not written to the CM database and there are no entries in MBAM section of Event Viewer that say the key has been escrowed.

 

I've been following Naill Brady's "BitLocker management – Part 8 Migration" video, which clearly shows the KeyRecoveryServiceEndPoint exists and points to the CM server.

 

I'm kind of stuck at the moment.

Posted

Update: It helps to look at the right tables when looking for keys. A few years ago, before true MBAM integration with SCCM - I tried to install MBAM on the SCCM server to utilise the same SQL server. At that point, the two IIS sites didn't work with each other, due to SPN issues. So it left the MBAM databases in SQL. I didn't realise the new integratated MBAM places the tables under the CM_SITE DB. So problem sorted and it's writing the keys automatically into the DB.

 

/Facepalm :doh:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...