QuestionQ10

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) domain. The domain contains servers running Windows Server, and BitLocker recovery keys are stored in AD DS.

A server named Server1 starts in BitLocker recovery mode.

You need to identify the BitLocker recovery key for Server1.

Solution: You use ADSI Edit to view the properties of the Server1 computer object.

Does this accomplish the goal?

Explanation

In AD DS, each BitLocker recovery password is stored in an ms-FVE-RecoveryInformation child object under the computer object, rather than as a property on the computer object itself. Viewing only the computer object's properties in ADSI Edit therefore does not identify the recovery key. Microsoft documents using the BitLocker Recovery tab in Active Directory Users and Computers to view recovery passwords associated with a computer.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!