Restrict the Bitlocker key recovery tab

Hi, i have a request to restrict who can see the Bitlocker recovery tab in AD.

can anyone provide the steps required as i was not involved in its setup so i am not sue if this has already been done.

thx

jason

 
July 13th, 2015 4:28pm

Hi jloster,

Thanks for your post.

Based on my knowledge, to view BitLocker Active Directory recovery passwords, you must be a domain administrator, or you must have been delegated permissions by a domain administrator. 

For your request to restrict the Bitlocker key recovery tab, I suggest you could  post to security forum for more support.

https://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserversecurity

Best Regards,

Mary Dong

Free Windows Admin Tool Kit Click here and download it now
July 14th, 2015 1:33am

Hello,

you can use Bitlocker recovery TAB script or delegation control wizard through script you can provide limited or read only access to service desk or restricted access to users to see Key for computer accounts.

http://blogs.technet.com/b/craigf/archive/2011/01/26/delegating-access-in-ad-to-bitlocker-recovery-information.aspx

https://technet.microsoft.com/en-us/library/cc771778(WS.10).aspx

On the link go through the steps mentioned in :  

Appendix A: Delegating Permission

July 14th, 2015 9:15am

Hello,

Hope your query resolved now. if yes can you mark proposed as Answer so that others can refer it.

Free Windows Admin Tool Kit Click here and download it now
July 18th, 2015 9:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics