QuestionQ12

Secure Windows Server infrastructure

Your network includes an Active Directory Domain Services (AD DS) domain. The domain contains servers running Windows Server, and BitLocker recovery keys are stored in AD DS.

A server named Server1 starts in BitLocker recovery mode.

You need to identify the BitLocker recovery key for Server1.

Solution: You run repair-bde.exe using a BitLocker key package exported from AD DS.

Does this achieve the goal?

Explanation

repair-bde.exe uses a key package to attempt data recovery from a BitLocker-protected drive. It does not identify the BitLocker recovery password stored in Active Directory Domain Services for the server.

Community Discussion

No comments yet. Be the first to start the discussion!