Migrate bitlocker from Mbam to sccm with TPM key

lalajee 1,811 Reputation points
2020-11-18T16:00:06.827+00:00

Hi, We need to Migrate Bitlocker from MABAM to SCCM (Mbam integrate) but I can't seem to find information on if it will move the TPM key to SCCM or not.

We are running SCCM 2002 (soon to be upgraded to 2009)
MBAM server is 2.3 (We are in process of upgrading this to 2.5)

We would like to integrate MBAM with SCCM but also migrate recover key + TPM key.
I know recovery key will be moved but will the TPM key moved too, if not how do I move the TPM key without re-encrypting the drive.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,769 questions
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
908 questions
Microsoft Configuration Manager
{count} votes

3 answers

Sort by: Most helpful
  1. Aravinth Mathan 321 Reputation points
    2020-11-18T18:18:36.88+00:00

    Hi @lalajee

    Are you referring to TPM startup pin on the device?
    If yes, that is specific to device and it is stored in TPM chip present locally on the device. So your during migration you don't have to worry about TPM pin. Just make sure the policy are replicated and there will not be any need for reencryption unless there is a bitlocker policy change

    Regards
    Aravinth

    If this is helpful,kindly accept as answer

    0 comments No comments

  2. Jason Sandys 31,171 Reputation points Microsoft Employee
    2020-11-18T19:12:15.713+00:00

    We are running SCCM 2002 (soon to be upgraded to 2009)

    There's no such thing as 2009 and never will be (at least not prod versions).

    Are you referring to the TPM Owner password? If so, why are you escrowing this at all? By default, Windows doesn't even store this -- it sets it and then throws it away.

    0 comments No comments

  3. lalajee 1,811 Reputation points
    2020-11-19T15:24:46.477+00:00

    Thats it TPM Owner password but does it not store a key into mbam server which can be use for somehting