BitLocker recovery key escrow failing silently for computer in Azure AD DS Standard tier, standalone domain

Zsolt Farkas 0 Reputation points
2026-03-12T07:51:33.53+00:00

We have AD DS for Windows servers in our infrastructure. There is a domain group policy in place to allow Bitlocker key to be stored in AD. The policy is effective, and Bitlocker is successfully activated on the server.

When saving the key to AD, the command is executed seemingly successfully. However, the key never gets into the domain.

  1. Azure AD DS Standard tier, standalone
  2. BitLocker recovery key escrow failing silently
  3. Event 513 fires but msFVE-RecoveryInformation object not found on either DC
  4. ACL verified correct including ea715d30-... CreateChild entry
  5. Reproducible on computer object

Is this some known limitation or do we have a problem in our Azure AD DS instance?

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.