How to retrieve forgotten Bitlocker Pin from AD

RockmanIT 256 Reputation points
2021-03-17T20:39:29.37+00:00

Looking on some feedback as to how to Setup Bitlocker in a GPO so that I can reset or relay a forgotten pin from AD to a client without touching their workstation.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,049 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426K Reputation points MVP
    2021-03-17T21:01:58.72+00:00

    This one may help.
    https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/bitlocker-recovery-password-viewer-tool

    --please don't forget to Accept as answer if the reply is helpful--


1 additional answer

Sort by: Most helpful
  1. Teemo Tang 11,331 Reputation points
    2021-03-18T02:58:00.33+00:00

    Yes, save BitLocker Recovery Keys in Active Directory is a command way for system admin to manage BitLocker recovery key or other information when user forget them.
    The following type of information is stored in AD DS
    Hash of the TPM owner password
    BitLocker recovery password
    BitLocker key package
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-and-adds-faq#what-type-of-information-is-stored-in-ad-ds

    Please refer to this guide to configure GPO
    Store and Retrieve BitLocker Recovery Keys from Active Directory
    https://4sysops.com/archives/store-and-retrieve-bitlocker-recovery-keys-from-active-directory/

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.