bitlocker / manage USB drives for recovery passwords

Posted on 2009-12-20
Last Modified: 2012-05-08

Just encryptrd the C drive of a 2008 r2 server. I saved the recovery password on a USB-drive (as well as printed it). I can see three files on that USB stick (drive) now:


1. Can I copy those 3 files to anoher empty NTFS formatted USB -stick (and format the original Stick if I want)? Is the the recovery comprised by doing that?
2. If I want to Encrypt also the drive E on the same server should I use a blank NTFS formatted USB stick (drive) to store recovery password or can one USB stick hold recovery info for several drives and even several computers too?



Question by:RimFire007
    LVL 26

    Accepted Solution

    ad 1) you need only BEK file for recovery. Or your printed password. It's enough. Just copy BEK file to new usb stick and try :)
    ad 2) one USB stick can contain many BEK files. Their names are unique and your OS will select the matching one. i.e. you can create your "master" usb stick with all recovery files in your enterprise if you like.

    BEK files are "normal" files. Copy them, archive on DVDs, etc... They will work until they have their content and filename unchanged.

    Author Closing Comment

    Thank yor for your detailed answer.

    Furthermore, I can hve all BEK--files on encrypted USB-stick on secure area on corresponding folders and when needed copy those one I need on unsecured (standard primary) area.




    Featured Post

    Maximize Your Threat Intelligence Reporting

    Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

    Join & Write a Comment

    A few customers have recently asked my thoughts on Password Managers.  As Security is a big part of our industry I was initially very hesitant and sceptical about giving a program all of my secret passwords.  But as I was getting asked about them mo…
    You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
    This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
    This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now