GPO: Enable BitLocker and Store Recovery Keys in AD

1. GPO

In Group Policy Management create a new GPO. Under Computer Configuration > Policies > Administrative Templates > Windows Components > BitLocker Drive Encryption:

  • Store BitLocker recovery information in Active Directory Domain Services: Enabled
  • Operating System Drives > Require additional authentication at startup: Enabled (default options)
  • Operating System Drives > Choose how BitLocker-protected operating system drives can be recovered: Enabled, and tick Do not enable BitLocker until recovery information is stored in AD DS.

2. Recovery key viewer on the AD server

Add the feature Remote Server Administration Tools > Feature Administration Tools > BitLocker Drive Encryption Administration Utilities (tools and Recovery Password Viewer), or:

Install-WindowsFeature RSAT-Feature-Tools-BitLocker -IncludeAllSubFeature

The computer object in Active Directory Users and Computers now has a BitLocker Recovery tab with the key.

3. Encrypt and check

Users can now turn on BitLocker (needs admin rights). Status:

manage-bde -status

For drives encrypted before the GPO, push the key to AD manually:

manage-bde -protectors -get C:
manage-bde -protectors -adbackup C: -id {PROTECTOR-ID}

Note: on old computers without a TPM, BitLocker asks for a password at every boot.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts