CHiLL Posted August 15, 2022 Posted August 15, 2022 Devices using the legacy MBAM have the KeyRecoveryServiceEndPoint entry and configured in the registry, pointing to the legacy MBAM server. Though on my test device, I've removed all MBAM GPOs and pushed the (correct as far as I can tell) BitLocker configuration baselines to the device. I can see that CM takes over, as the baseline shows and is evaluated as compliant, but the KeyRecoveryServiceEndPoint registry entry is missing. The recovery key is not written to the CM database and there are no entries in MBAM section of Event Viewer that say the key has been escrowed. I've been following Naill Brady's "BitLocker management – Part 8 Migration" video, which clearly shows the KeyRecoveryServiceEndPoint exists and points to the CM server. I'm kind of stuck at the moment.
CHiLL Posted August 16, 2022 Author Posted August 16, 2022 Update: It helps to look at the right tables when looking for keys. A few years ago, before true MBAM integration with SCCM - I tried to install MBAM on the SCCM server to utilise the same SQL server. At that point, the two IIS sites didn't work with each other, due to SPN issues. So it left the MBAM databases in SQL. I didn't realise the new integratated MBAM places the tables under the CM_SITE DB. So problem sorted and it's writing the keys automatically into the DB. /Facepalm
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now