Deny save or print recovery key again on Bitlocker OS drive
I have configured bitlocker and the only problem is that in the Manage BitLocker menu the end user can choose for the option Save or print recovery key again for the OS drive. Is there an possibility to remove this option since the keys are saved in the AD and i don't want the end user can save the key.
September 16th, 2011 11:01am

Yes, this is possible. Open GPO for bitlocker drive encryption and under Operating systems drive, there is a GPO to Save recovery information in AD. This policy will be enabled and in this policy there is a checkbox "Omit recovery screen" Please check that and apply this GPO to clients using gpupdate /force After this user will not see the screen to save or print the key.Manoj Sehgal
Free Windows Admin Tool Kit Click here and download it now
September 17th, 2011 6:32pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics