Since you have backup the key and saved to ad, i suggest you check whether the key is available again. Thus ultimately, your question, as noted, is. The different measurement results in the message from bitlocker that the system boot information has changed and bitlocker forces the customer to enter the recovery key (or.
If it is lost, i am afraid we will lost it forever as zigzag pointed out. A recovery key is a combination of 48 bit numbers. Here is an article about the backing up.
We need the key to access the bitlocker. Is there a supported method to incorporate existing bitlocker recovery key information from computer accounts in active directory to the mbam database? The enable bitlocker task sequence step simply configures the proper local policy in windows for windows to store the key in ad. For aes 256 i have all 3 policies set in gp on my base image (comp config > windows components > bitlocker drive encryp > choose drive encryption method).
I have found this powershell script and am having trouble modifying it to only pull computer objects that do not have a bitlocker key stored in ad. There is no template for bitlocker dra in. Ithis script pulls all computers but i am. We have a 2008 r2 domain but our ca's are 2003.
I need to deploy bitlocker with fips compliance enabled so looking to use dra for recovery.