A cloud-based identity and access management service for securing user authentication and resource access
BitLocker recovery key escrow failing silently for computer in Azure AD DS Standard tier, standalone domain
Zsolt Farkas
0
Reputation points
We have AD DS for Windows servers in our infrastructure. There is a domain group policy in place to allow Bitlocker key to be stored in AD. The policy is effective, and Bitlocker is successfully activated on the server.
When saving the key to AD, the command is executed seemingly successfully. However, the key never gets into the domain.
- Azure AD DS Standard tier, standalone
- BitLocker recovery key escrow failing silently
- Event 513 fires but
msFVE-RecoveryInformationobject not found on either DC - ACL verified correct including
ea715d30-...CreateChild entry - Reproducible on computer object
Is this some known limitation or do we have a problem in our Azure AD DS instance?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Sign in to answer