Skip to content

Setting BitLocker GPO

Setting Up BitLocker Escrow with GPO

BitLocker Drive Encryption (BitLocker) provides data protection for Windows systems, but recovery of encrypted drives requires access to recovery keys. Storing these keys in Active Directory Domain Services (AD DS) centralizes management and ensures availability during emergencies. This guide explains how to configure BitLocker recovery key storage in AD DS and automate the process using Group Policy Objects (GPOs).


Prerequisites and Planning

Before configuring BitLocker escrow, ensure the following: - Domain Controller: The domain must be running Windows Server 2008 R2 or later with the AD DS schema updated for BitLocker. - Computers: Target systems must support BitLocker (Windows 10/11 Pro, Enterprise, or Education editions). - Permissions: The GPO must be linked to an Organizational Unit (OU) containing the target computers. The BitLocker Recovery Agent group must have Read permissions on the AD DS object where recovery keys are stored.


Step 1: Enable BitLocker with AD DS Escrow

Use the manage-bde command or PowerShell to enable BitLocker and specify AD DS as the recovery key storage location. For example:

# Enable BitLocker with AD DS escrow
manage-bde -on C: -usedspaceonly -RecoveryPassword <password> -RecoveryKey <AD_DS_DN>

Replace <password> with a strong recovery password and <AD_DS_DN> with the distinguished name (DN) of the AD DS object (e.g., OU=RecoveryKeys,DC=example,DC=com). The recovery key is stored in the specified AD DS location.

Note: If using GPO to automate escrow, the -RecoveryKey parameter is not required, as GPO will handle key storage.


Step 2: Configure BitLocker Escrow via GPO

  1. Open Group Policy Management Console (GPMC) and create/edit a GPO linked to the target OU.
  2. Navigate to:
  3. Computer Configuration > Policies > Administrative Templates > Windows Components > BitLocker Drive Encryption > Recovery Password.
  4. Enable the following policies:
  5. Store BitLocker recovery information in Active Directory Domain Services: This ensures recovery keys are stored in AD DS.
  6. Specify the Active Directory container for BitLocker recovery information: Set the DN of the OU where keys will be stored (e.g., OU=RecoveryKeys,DC=example,DC=com).
  7. Enable the policy Require BitLocker encryption on fixed drives to enforce encryption.

Example GPO Settings:

Policy: Store BitLocker recovery information in Active Directory Domain Services
   Enabled
   Recovery Key Container: OU=RecoveryKeys,DC=example,DC=com


Step 3: Automate Escrow with GPO

To automate recovery key storage, ensure the following: - GPO is linked to the target OU: This ensures all computers in the OU inherit the BitLocker policies. - Use the "Turn on BitLocker" template: This policy automatically enables BitLocker and stores recovery keys in AD DS if configured.

PowerShell Example to Verify Configuration:

Get-BitLockerVolume | Select-Object VolumePath, RecoveryKeyPath, RecoveryPassword

This command displays the recovery key location and password, confirming that keys are stored in AD DS.


Step 4: Validate and Troubleshoot

  • Check GPO inheritance: Use gpresult /H to verify that the GPO is applied correctly.
  • Verify AD DS permissions: Ensure the BitLocker Recovery Agent group has Read permissions on the recovery key container.
  • Test recovery key retrieval: Use the manage-bde -getrecoverykey command with the recovery password to confirm key accessibility.

Key takeaways

  • Store BitLocker recovery keys in AD DS for centralized management and redundancy.
  • Configure GPO policies to automate key storage, ensuring compliance with security requirements.
  • Validate permissions and GPO inheritance to avoid access issues during recovery.
  • Use PowerShell or manage-bde to enable BitLocker and verify key storage locations.