Enabled storing Bitlocker keys in Active Directory, is there a way to upload keys of drives encrypted before this?

Posted by Rossaluss on Super User See other posts from Super User or by Rossaluss
Published on 2012-10-23T10:14:06Z Indexed on 2012/10/23 11:04 UTC
Read the original article Hit count: 407

We have enabled storing of Bitlocker keys within the device object on Active Directory, however before this was implemented, we had encrypted 100+ devices using bitlocker and we've only found ways to upload the key to AD when enabling bitlocker for the first time on an install.

Does anybody know of a way where we can upload all the keys for all the devices which already had their drives encrypted with Bitlocker into their respective device objects in AD? Or are we going to have to decrypt and re-encrypt all the devices on the floor? (Google seems to say this is what we're going to have to do, however we're no experts in Bitlocker, so may have missed something)

When we go into Manage Bitlocker of an already encrypted device, we only get the same options of saving the key to a file, a memory stick or printing it out, no option is available to save to AD etc.

Any help would be appreciated.

© Super User or respective owner

Related posts about encryption

Related posts about active-directory