Link to home
Start Free TrialLog in
Avatar of RPPreacher
RPPreacherFlag for United States of America

asked on

Bitlocker, Windows 7 Ultimate and Server 2008 R2

These questions seem so easy that I should have found them in the 3 Microsoft Press books or over the last 90 minutes of Googling.

(1)  Do I need to do anything to Server 2008 R2 domain to store the bitlocker recovery keys?
(2)  How do I view the keys in AD to confirm that they are being stored?
(3)  How do I recover a drive if the user loses the key?

Thanks!
SOLUTION
Avatar of Rory de Leur
Rory de Leur
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Apologies for the duplicate response ... I meant to include under #2 above:

Check the following attributes via ADSIEdit or ADSI CLI tools (dsquery, ldifde, etc.):
  •               CN=ms-FVE-KeyPackage – attributeSchema  object
  • CN=ms-FVE-RecoveryGuid – attributeSchema  object
  • CN=ms-FVE-RecoveryInformation –  classSchema object
  • CN=ms-FVE-RecoveryPassword –  attributeSchema object
  • CN=ms-FVE-VolumeGuid – attributeSchema  object
  • CN=ms-TPM-OwnerInformation –  attributeSchema object