QuestionQ13

Deploy and manage AD DS

Your network includes an Active Directory Domain Services (AD DS) domain. The domain contains servers running Windows Server, and BitLocker recovery keys are stored in AD DS.

A server named Server1 starts in BitLocker recovery mode.

You need to identify the BitLocker recovery key for Server1.

Solution: You use ntdsutil.exe on a domain controller.

Does this accomplish the goal?

Explanation

BitLocker recovery passwords stored in AD DS are retrieved by using BitLocker Recovery Password Viewer in Active Directory Users and Computers, where the computer object's BitLocker Recovery tab can display its associated passwords. ntdsutil.exe manages and maintains AD DS but does not provide the BitLocker recovery-password lookup needed to identify Server1's key.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!