At IU, how can I escrow BitLocker recovery information in Active Directory?
The policy setting described here allows you to manage the Active
Directory Domain Service (AD DS) backup of BitLocker Drive
Encryption recovery information. For more information, see the
Explain tab for the policy "Turn on BitLocker backup to
Active Directory Domain Services" within gpedit.msc.
Prerequisites
- You must have Windows 7 or Windows Vista
Enterprise or Ultimate.
- BitLocker must be turned off.
- The computer must be joined to Indiana University's ADS
domain.
- You must have administrative credentials on the computer on which BitLocker is being configured.
Instructions
To escrow BitLocker recovery information in Active Directory:
Windows 7
- To open the
Rundialog box, pressWindows-r(theWindowskey and the letterr).
- Type
gpedit.mscand clickOK.
- Expand
Computer Configuration, expandAdministrative Templates, and expandWindows Components. ClickBitLocker Drive Encryption.
- Under
Operating System Drives, selectChoose how BitLocker-protected operating system drives can be recovered.
- Select
EnabledandSave BitLocker recovery information to AD DS for operating system drives.
- Click
Apply, and thenOK.
- Under
Fixed Data Drives, selectChoose how BitLocker-protected fixed data can be recovered.
- Select
EnabledandSave BitLocker recovery information to AD DS for fixed data drives.
- Click
Apply, and thenOK.
- Under
Removable Data Drives, selectChoose how BitLocker-protected removable drives can be recovered.
- Select
EnabledandSave BitLocker recovery information to AD DS for removable data drives.
- Click
Apply, and thenOK.
Windows Vista
- To open the
Rundialog box, pressWindows-r(theWindowskey and the letterr).
- Type
gpedit.mscand clickOK.
- Expand
Computer Configuration, expandAdministrative Templates, and expandWindows Components. ClickBitLocker Drive Encryption.
- Double-click
Turn on BitLocker backup to Active Directory Domain Services.
- Select
Enabled.
- Select
Require BitLocker backup to AD DS.
- Select
Recovery Passwords and key packages.
- Click
Apply, and thenOK.
If your department leverages Active Directory to manage your Windows computers and you plan to enable BitLocker, UITS strongly encourages you to apply these settings via Group Policy.
Last modified on August 27, 2012.







