Enable Bitlocker and Save Key to Network Share with Unattend?

2

1

Is there a way to enable bitlocker and save off key during setup via the unattend file? How else would you deploy bitlocker?

MattUebel

Posted 2011-08-03T12:16:22.013

Reputation: 1 443

Answers

1

The recommended store for BitLocker recovery keys is ActiveDirectory since it holds other sensitive information as well. Plus, you get the advantages of AD as well (for example, that the recovery key is replicated across the domain controllers so it is viewable as long as at least one DC is alive).

General information how to enable can be found on TechNet.

Are you using Microsoft Deployment Toolkit (MDT) to deploy Windows 7? If so, you can easily set BitLocker encryption using the GUI – see this blog post for details.

Sometimes it can happen that your AD has not the correct permissions for the computer to update the recovery key, which means the automatic rollout fails. A step by step guide to resolve this can be found here. Note: If this happens, you only need to set it once and then never bother with it again.

Tex Hex

Posted 2011-08-03T12:16:22.013

Reputation: 2 242