21. Configure Active Directory to Store BitLocker Recovery Keys

Поділитися
Вставка
  • Опубліковано 28 гру 2024

КОМЕНТАРІ • 50

  • @chromamusic7501
    @chromamusic7501 Рік тому +1

    Great video, very instructional. Got an odd ball question though, our current network has four separate domain controllers and they all work in parallel. Would installing these features on each domain controller one at a time cause any issues in regards to PC's becoming inaccessible? If we reboot one DC our full domain remains online, though what we're concerned about is if we enable BitLocker backups on one controller and it's out of sync with the others, think it may shut down? Or, is it fine if we install the BitLocker features on each domain controller one at a time? Thanks!

  • @HaiPhan-pw3pi
    @HaiPhan-pw3pi Рік тому +1

    It worked, very helpful, thank you so much for sharing knowledge.

  • @romanmerkushev4360
    @romanmerkushev4360 Рік тому +1

    Thank you so much for your video!

  • @rocharox
    @rocharox 2 роки тому +2

    Good video.

  • @deniscostacantor
    @deniscostacantor 2 роки тому +1

    Thank you very Much Perfect video very Helpful!!!!

  • @fabriciomattos16
    @fabriciomattos16 6 місяців тому

    Didn't get this part of tutorial. Although I have the GPO configured and applied to the computer, do I have to manually enable BitLocker?

  • @jeanca0426
    @jeanca0426 9 місяців тому

    If I want yo use TPM, How will be the additional authentication setup?

  • @renatomateus5262
    @renatomateus5262 4 роки тому +3

    Is it possible to encrypt windows 10 client disks by GPO without having to go the users machine? The video shows the Key controller GPO, but does not show encrypting disks by AD without the need Activate the bitlocker on the users machine. Thank you very much, and i look forward to It.

    • @sunny90908
      @sunny90908 2 роки тому

      You can push manage bde toolkit to install bitlocker remotely to the domain machine

  • @nikhilkal
    @nikhilkal 5 років тому

    Video is very helpful i have one query and issue that the above steps are working properly but what we can do for another drives as well. I have tested it for D: drive but in active directory there is only C: drive key is backed up.

    • @abdulmowbinjadid
      @abdulmowbinjadid Рік тому

      I am facing the same issue, did you find any solution?

  • @thusithafernando8325
    @thusithafernando8325 3 роки тому +1

    Thank you 😊

  • @korcanyavuz1207
    @korcanyavuz1207 Рік тому

    It works.. Thank you!

  • @arcadeslum5882
    @arcadeslum5882 5 років тому

    I have a small and random case of AD losing bitlocker keys. Is there a way to protect the key from updating to blank or backup of my keys once they are stored or something?

  • @shiyamsundar1740
    @shiyamsundar1740 5 років тому

    This is crystal clear...

  • @phutiish
    @phutiish 2 роки тому

    I am unable to get next button even though I’ve followed all your steps. Another thing is I am prompted to save recovery keys in azure AD and I want it to be on premise AD. Please help

  • @faizbhagett2241
    @faizbhagett2241 11 місяців тому

    have got message during encryption :Fehlermeldung: Die GPO-Einstellungen für BitLocker stehen in Konflikt
    The GPO settings for BitLocker are in conflict

  • @sumeetpandhare
    @sumeetpandhare 5 років тому

    That will really so much helpful...😘😘

  • @nashaatmena7687
    @nashaatmena7687 4 роки тому

    thx for your valuable information video

  • @zachdouglas575
    @zachdouglas575 4 роки тому

    does the "Require BitLocker backup to AD DS" mean that BitLocker will automatically enable on computers in the OU? I've found that computers are automatically seeming to have BitLocker enable for them. thanks.

    • @MSFTWebCast
      @MSFTWebCast  4 роки тому

      Yes. it will be applicable to all computers stored in particular OU.

  • @peteschaub7561
    @peteschaub7561 6 місяців тому

    Does anyone know how to increase the number of bad passwords before the Bitlocker recovery process starts? It seems to be set to 5 by default but I can't figure out how to change it.

  • @faizbhagett2241
    @faizbhagett2241 11 місяців тому

    i have got only two option after encrypt c: save file recoverykey print. there is no option for password

  • @Deli0Man
    @Deli0Man 5 років тому

    I mean, what is now true? Should one not use MBAM to save Windows10 Clients keys in AD?

  • @technoshare9047
    @technoshare9047 3 роки тому

    How to lock PC when a user enters an incorrect password several times, that user simply gets locked out of his account.
    How do you when the user enters the wrong password then goes to bitlocker recovery mode ?

  • @deejagers716
    @deejagers716 Рік тому

    Oke memberserver but what with client computers? Windows 10

    • @MSFTWebCast
      @MSFTWebCast  Рік тому

      Same process for windows 10 client machine as well.

  • @brianvolpone2617
    @brianvolpone2617 4 роки тому

    Will this also work if your DC is Server 2016?

  • @rajivanand8544
    @rajivanand8544 4 роки тому

    Very Nice Video.. :)

  • @kiranmestry3328
    @kiranmestry3328 3 роки тому

    Is that possible to bitlocker key change automatically without reset by manually from client computer? If yes can you plz let me know the process and it can be changed once it being used
    Plz let us know if any process available

    • @MSFTWebCast
      @MSFTWebCast  3 роки тому

      I am not aware if we can change the key that way. Need to check. I am not sure yet but I dont think it is possible.

  • @ciprianpopovici7532
    @ciprianpopovici7532 4 роки тому

    It is possible to automatically unlock drive without enter a password at startup? Using the keys stored in TPM chip?

    • @icloudking1319
      @icloudking1319 3 роки тому

      +1 (218) 331‑1763‬
      𝓦𝓱𝓪𝓽𝓼 𝓐𝓹𝓹

  • @ahmedsaad-lk2og
    @ahmedsaad-lk2og 2 роки тому

    thanks

  • @imranawan9341
    @imranawan9341 5 років тому

    Nice video. Can you create a script or tell us how we can encrypt the OS hard drive... You have told us how to recover the bitlocker viz AD
    Thanks for sharing that

  • @foreign-livingtheamericand8782
    @foreign-livingtheamericand8782 3 роки тому

    where the keys are stored in active directory? (pop)

    • @MSFTWebCast
      @MSFTWebCast  3 роки тому

      Open Active Directory Users and Computers snap-in. --> Click the Computers container. --> Right-click on your target computer account and select Properties --> Go to the BitLocker Recovery tab. Here you can view all BitLocker recovery keys that were automatically backed up to AD.

  • @Deli0Man
    @Deli0Man 5 років тому

    So if I do understand U correctly, this information, that window 10 1607 and above is not storing the Keys in AD although the Setup has been done, is no more accurate?!
    "For Windows 10 1607 and above:
    TPM Owner Password is not stored in the AD at all. Even though you can configure GPO on previous operating system (Windows 8/Windows Server 2012 R2) “Turn on TPM backup to Active Directory Domain Services” or registry keys directly on the client machine:
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TPM\ActiveDirectoryBackup = 1
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TPM RequireActiveDirectoryBackup = 1
    Windows 10 1607 will ignore these values.
    Another thing which is worth to mention that GPO
    Computer Configuration\Administrative Templates\System\Trusted Platform Module Services\Turn on TPM backup to Active Directory Domain Services
    has been removed from ADMX templates in Windows 10 1607 and Windows Server 2016. Thus most of information provided in this article is for pre Windows 10 1607 editions."
    blogs.technet.microsoft.com/dubaisec/2017/02/28/tpm-owner-password/

    • @LiquidRetro
      @LiquidRetro 4 роки тому

      So if running 1607 or higher, this video is really not worth doing then? There doesn't appear to be a fix or work around either?

  • @Akira29H
    @Akira29H 3 роки тому

    How to configure bitlocker without use /prompt password recover key in boot systems

    • @drewharden3905
      @drewharden3905 3 роки тому

      Don't enable the GPO "Requires additional authentication at startup". It's only doing this for the demo because he's using a VM. In the real world you'll be encrypting physical machines and they'll authenticate with TPM

  • @KavanMavati
    @KavanMavati 5 років тому

    Every time you reboot machine it will ask for recovery key! How do you fix that

    • @bmx123pro
      @bmx123pro 4 роки тому +2

      Skip the step at 3:42 which is require additional authentication at startup.

    • @FunnyBollyywood
      @FunnyBollyywood 4 роки тому

      @@bmx123pro Still asking for password at startup