How to save the recovery key in AD through MDT 2008

Bitlocker activation in the MDT 2008 task sequence works great! In the lite touch deployment you can check the box that will tell it to save the recovery key in AD. When the task sequence is complete and drive encryption is complete, for some reason the key is not getting stored in AD. Why isn't the lite touch deployment storing the key in AD for me? I have verified the laptop IS in the domain while the encryption is occuring. Any thoughts?
Even though i set the value in customsettings.ini file, nothing is getting refelected in the Enbale bitlocker wizard. Below are the values set in the INI file;

SkipBitLocker=NO
BDEInstallSuppress=NO
BDEDriveLetter=Q:
BDEInstall=TPM
BDERecoveryKey=AD
BDEWaitForEncryption=TRUE
LVL 1
KC2TCApplication RepackagingAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Kelvin_KingCommented:
I have had the problem as well when setting up key escrow for BitLocker.

I'm not sure if it's the same problem, but for me it was because BitLocker requires that you extend the schema in the AD.

I can't remember the exact steps I did, but this is the documentation which I followed

http://www.microsoft.com/downloads/details.aspx?FamilyID=3a207915-dfc3-4579-90cd-86ac666f61d4&displaylang=en

Hope it helps you
-Kelvin
0
Kelvin_KingCommented:
I found this useful as well
http://technet.microsoft.com/en-us/library/cc766015.aspx

There are some scripts which you need to run to extend the AD schema.

And even then, I remembered that the scripts were written wrongly. I had to contact the BitLocker technical support team, send them the script and had them correct it for me.

I hope times have changed....

-Kelvin
0
Kelvin_KingCommented:
After doing a little bit more searching, also keep in mind that if you are using Windows server 2003, you'll need to install the WIndows Server Administration Tools for SP1:

http://www.microsoft.com/downloads/details.aspx?FamilyID=E487F885-F0C7-436A-A392-25793A25BAD7&displaylang=en

- Kelvin
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Kelvin_KingCommented:
Did the information help you?
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.