GPO: Enable BitLocker and Store Recovery Keys in AD
1. GPO
In Group Policy Management create a new GPO. Under Computer Configuration > Policies > Administrative Templates > Windows Components > BitLocker Drive Encryption:
- Store BitLocker recovery information in Active Directory Domain Services: Enabled
- Operating System Drives > Require additional authentication at startup: Enabled (default options)
- Operating System Drives > Choose how BitLocker-protected operating system drives can be recovered: Enabled, and tick Do not enable BitLocker until recovery information is stored in AD DS.
2. Recovery key viewer on the AD server
Add the feature Remote Server Administration Tools > Feature Administration Tools > BitLocker Drive Encryption Administration Utilities (tools and Recovery Password Viewer), or:
Install-WindowsFeature RSAT-Feature-Tools-BitLocker -IncludeAllSubFeature
The computer object in Active Directory Users and Computers now has a BitLocker Recovery tab with the key.
3. Encrypt and check
Users can now turn on BitLocker (needs admin rights). Status:
manage-bde -status
For drives encrypted before the GPO, push the key to AD manually:
manage-bde -protectors -get C:
manage-bde -protectors -adbackup C: -id {PROTECTOR-ID}
Note: on old computers without a TPM, BitLocker asks for a password at every boot.