Hello.
We had an issue where a bitlocker'd laptop died and the SSD was pulled. In order to read the SSD in another computer we need to supply the recovery key which is stored in AD. Except, it wasn't, for this laptop only. We are investigating why (suspect a mobo replacement a few months ago might have wiped it out somehow).
I know the bitlocker key WAS there before this mobo replacement (as I used it to unlock the SSD at the time) so thought I could restore the computer object from a backup of a domain controller. Having loaded and browsed the relevant restore point using Veeam Explorer for Active Directory, I can see all the AD objects properties, but couln't see the recovery key, or any bitlocker data. I cancelled out of that and managed to recovery the key another way, but I was curious to know if I had restored the object, would the recovery key be there?
In ADSIedit, Bitlocker data is stored in a sub-property of the computer object as shown below. Computers that don't have bitlocker enabled show nothing in this right-side pane.
-
- Expert
- Posts: 147
- Liked: 28 times
- Joined: Oct 29, 2015 5:58 pm
- Full Name: Michael Yorke
- Contact:
-
- Veeam Software
- Posts: 3264
- Liked: 528 times
- Joined: Aug 28, 2013 8:23 am
- Full Name: Petr Makarov
- Location: Prague, Czech Republic
- Contact:
Re: Would computer AD object restore include bitlocker recovery key?
Hi Michael,
Please allow me to have some time to check this scenario. I'll update the topic as soon as I have more details.
Thanks!
Please allow me to have some time to check this scenario. I'll update the topic as soon as I have more details.
Thanks!
-
- Veeam Software
- Posts: 3264
- Liked: 528 times
- Joined: Aug 28, 2013 8:23 am
- Full Name: Petr Makarov
- Location: Prague, Czech Republic
- Contact:
Re: Would computer AD object restore include bitlocker recovery key?
Hello,
According to our tests:
Restore of this sub-property child object is included in the Computer object recovery operation despite we don't show this sub-property in VEAD.
Thanks!
According to our tests:
Yes, the recovery key will be there.DDIT wrote:but I was curious to know if I had restored the object, would the recovery key be there?
Restore of this sub-property child object is included in the Computer object recovery operation despite we don't show this sub-property in VEAD.
Thanks!
-
- Expert
- Posts: 147
- Liked: 28 times
- Joined: Oct 29, 2015 5:58 pm
- Full Name: Michael Yorke
- Contact:
Re: Would computer AD object restore include bitlocker recovery key?
Amazing! Thanks for testing and confirming. This is really helpful to know.
Who is online
Users browsing this forum: HenkeZan and 106 guests