21. Configure Active Directory to Store BitLocker Recovery Keys

Поделиться
HTML-код
  • Опубликовано: 6 сен 2024

Комментарии • 49

  • @fabriciomattos16
    @fabriciomattos16 2 месяца назад

    Didn't get this part of tutorial. Although I have the GPO configured and applied to the computer, do I have to manually enable BitLocker?

  • @HaiPhan-pw3pi
    @HaiPhan-pw3pi Год назад +1

    It worked, very helpful, thank you so much for sharing knowledge.

  • @chromamusic7501
    @chromamusic7501 Год назад +1

    Great video, very instructional. Got an odd ball question though, our current network has four separate domain controllers and they all work in parallel. Would installing these features on each domain controller one at a time cause any issues in regards to PC's becoming inaccessible? If we reboot one DC our full domain remains online, though what we're concerned about is if we enable BitLocker backups on one controller and it's out of sync with the others, think it may shut down? Or, is it fine if we install the BitLocker features on each domain controller one at a time? Thanks!

  • @romanmerkushev4360
    @romanmerkushev4360 11 месяцев назад +1

    Thank you so much for your video!

  • @faizbhagett2241
    @faizbhagett2241 8 месяцев назад

    have got message during encryption :Fehlermeldung: Die GPO-Einstellungen für BitLocker stehen in Konflikt
    The GPO settings for BitLocker are in conflict

  • @jeanca0426
    @jeanca0426 5 месяцев назад

    If I want yo use TPM, How will be the additional authentication setup?

  • @peteschaub7561
    @peteschaub7561 2 месяца назад

    Does anyone know how to increase the number of bad passwords before the Bitlocker recovery process starts? It seems to be set to 5 by default but I can't figure out how to change it.

  • @renatomateus5262
    @renatomateus5262 4 года назад +3

    Is it possible to encrypt windows 10 client disks by GPO without having to go the users machine? The video shows the Key controller GPO, but does not show encrypting disks by AD without the need Activate the bitlocker on the users machine. Thank you very much, and i look forward to It.

    • @sunny90908
      @sunny90908 2 года назад

      You can push manage bde toolkit to install bitlocker remotely to the domain machine

  • @rocharox
    @rocharox 2 года назад +2

    Good video.

  • @deniscostacantor
    @deniscostacantor 2 года назад +1

    Thank you very Much Perfect video very Helpful!!!!

  • @faizbhagett2241
    @faizbhagett2241 8 месяцев назад

    i have got only two option after encrypt c: save file recoverykey print. there is no option for password

  • @phutiish
    @phutiish 2 года назад

    I am unable to get next button even though I’ve followed all your steps. Another thing is I am prompted to save recovery keys in azure AD and I want it to be on premise AD. Please help

  • @thusithafernando8325
    @thusithafernando8325 3 года назад +1

    Thank you 😊

  • @shiyamsundar1740
    @shiyamsundar1740 4 года назад

    This is crystal clear...

  • @arcadeslum5882
    @arcadeslum5882 4 года назад

    I have a small and random case of AD losing bitlocker keys. Is there a way to protect the key from updating to blank or backup of my keys once they are stored or something?

  • @korcanyavuz1207
    @korcanyavuz1207 Год назад

    It works.. Thank you!

  • @technoshare9047
    @technoshare9047 3 года назад

    How to lock PC when a user enters an incorrect password several times, that user simply gets locked out of his account.
    How do you when the user enters the wrong password then goes to bitlocker recovery mode ?

  • @Deli0Man
    @Deli0Man 4 года назад

    I mean, what is now true? Should one not use MBAM to save Windows10 Clients keys in AD?

  • @deejagers716
    @deejagers716 Год назад

    Oke memberserver but what with client computers? Windows 10

    • @MSFTWebCast
      @MSFTWebCast  Год назад

      Same process for windows 10 client machine as well.

  • @nikhilkal
    @nikhilkal 4 года назад

    Video is very helpful i have one query and issue that the above steps are working properly but what we can do for another drives as well. I have tested it for D: drive but in active directory there is only C: drive key is backed up.

    • @abdulmowbinjadid
      @abdulmowbinjadid Год назад

      I am facing the same issue, did you find any solution?

  • @nashaatmena7687
    @nashaatmena7687 3 года назад

    thx for your valuable information video

  • @ahmedsaad-lk2og
    @ahmedsaad-lk2og 2 года назад

    thanks

  • @zachdouglas575
    @zachdouglas575 4 года назад

    does the "Require BitLocker backup to AD DS" mean that BitLocker will automatically enable on computers in the OU? I've found that computers are automatically seeming to have BitLocker enable for them. thanks.

    • @MSFTWebCast
      @MSFTWebCast  4 года назад

      Yes. it will be applicable to all computers stored in particular OU.

  • @sumitpandhare9625
    @sumitpandhare9625 4 года назад

    That will really so much helpful...😘😘

  • @imranawan9341
    @imranawan9341 4 года назад

    Nice video. Can you create a script or tell us how we can encrypt the OS hard drive... You have told us how to recover the bitlocker viz AD
    Thanks for sharing that

  • @kiranmestry3328
    @kiranmestry3328 3 года назад

    Is that possible to bitlocker key change automatically without reset by manually from client computer? If yes can you plz let me know the process and it can be changed once it being used
    Plz let us know if any process available

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      I am not aware if we can change the key that way. Need to check. I am not sure yet but I dont think it is possible.

  • @Deli0Man
    @Deli0Man 4 года назад

    So if I do understand U correctly, this information, that window 10 1607 and above is not storing the Keys in AD although the Setup has been done, is no more accurate?!
    "For Windows 10 1607 and above:
    TPM Owner Password is not stored in the AD at all. Even though you can configure GPO on previous operating system (Windows 8/Windows Server 2012 R2) “Turn on TPM backup to Active Directory Domain Services” or registry keys directly on the client machine:
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TPM\ActiveDirectoryBackup = 1
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TPM RequireActiveDirectoryBackup = 1
    Windows 10 1607 will ignore these values.
    Another thing which is worth to mention that GPO
    Computer Configuration\Administrative Templates\System\Trusted Platform Module Services\Turn on TPM backup to Active Directory Domain Services
    has been removed from ADMX templates in Windows 10 1607 and Windows Server 2016. Thus most of information provided in this article is for pre Windows 10 1607 editions."
    blogs.technet.microsoft.com/dubaisec/2017/02/28/tpm-owner-password/

    • @LiquidRetro
      @LiquidRetro 4 года назад

      So if running 1607 or higher, this video is really not worth doing then? There doesn't appear to be a fix or work around either?

  • @ciprianpopovici7532
    @ciprianpopovici7532 3 года назад

    It is possible to automatically unlock drive without enter a password at startup? Using the keys stored in TPM chip?

    • @icloudking1319
      @icloudking1319 3 года назад

      +1 (218) 331‑1763‬
      𝓦𝓱𝓪𝓽𝓼 𝓐𝓹𝓹

  • @rajivanand8544
    @rajivanand8544 4 года назад

    Very Nice Video.. :)

  • @foreign-livingtheamericand8782
    @foreign-livingtheamericand8782 3 года назад

    where the keys are stored in active directory? (pop)

    • @MSFTWebCast
      @MSFTWebCast  3 года назад

      Open Active Directory Users and Computers snap-in. --> Click the Computers container. --> Right-click on your target computer account and select Properties --> Go to the BitLocker Recovery tab. Here you can view all BitLocker recovery keys that were automatically backed up to AD.

  • @brianvolpone2617
    @brianvolpone2617 4 года назад

    Will this also work if your DC is Server 2016?

  • @Akira29H
    @Akira29H 3 года назад

    How to configure bitlocker without use /prompt password recover key in boot systems

    • @drewharden3905
      @drewharden3905 3 года назад

      Don't enable the GPO "Requires additional authentication at startup". It's only doing this for the demo because he's using a VM. In the real world you'll be encrypting physical machines and they'll authenticate with TPM

  • @KavanMavati
    @KavanMavati 4 года назад

    Every time you reboot machine it will ask for recovery key! How do you fix that

    • @bmx123pro
      @bmx123pro 4 года назад +2

      Skip the step at 3:42 which is require additional authentication at startup.

    • @TipooSultann
      @TipooSultann 4 года назад

      @@bmx123pro Still asking for password at startup