Setting BitLocker GPO
Setting Up BitLocker Escrow with GPO¶
BitLocker Drive Encryption (BitLocker) provides data protection for Windows systems, but recovery of encrypted drives requires access to recovery keys. Storing these keys in Active Directory Domain Services (AD DS) centralizes management and ensures availability during emergencies. This guide explains how to configure BitLocker recovery key storage in AD DS and automate the process using Group Policy Objects (GPOs).
Prerequisites and Planning¶
Before configuring BitLocker escrow, ensure the following: - Domain Controller: The domain must be running Windows Server 2008 R2 or later with the AD DS schema updated for BitLocker. - Computers: Target systems must support BitLocker (Windows 10/11 Pro, Enterprise, or Education editions). - Permissions: The GPO must be linked to an Organizational Unit (OU) containing the target computers. The BitLocker Recovery Agent group must have Read permissions on the AD DS object where recovery keys are stored.
Step 1: Enable BitLocker with AD DS Escrow¶
Use the manage-bde command or PowerShell to enable BitLocker and specify AD DS as the recovery key storage location. For example:
# Enable BitLocker with AD DS escrow
manage-bde -on C: -usedspaceonly -RecoveryPassword <password> -RecoveryKey <AD_DS_DN>
Replace <password> with a strong recovery password and <AD_DS_DN> with the distinguished name (DN) of the AD DS object (e.g., OU=RecoveryKeys,DC=example,DC=com). The recovery key is stored in the specified AD DS location.
Note: If using GPO to automate escrow, the -RecoveryKey parameter is not required, as GPO will handle key storage.
Step 2: Configure BitLocker Escrow via GPO¶
- Open Group Policy Management Console (GPMC) and create/edit a GPO linked to the target OU.
- Navigate to:
Computer Configuration > Policies > Administrative Templates > Windows Components > BitLocker Drive Encryption > Recovery Password.- Enable the following policies:
- Store BitLocker recovery information in Active Directory Domain Services: This ensures recovery keys are stored in AD DS.
- Specify the Active Directory container for BitLocker recovery information: Set the DN of the OU where keys will be stored (e.g.,
OU=RecoveryKeys,DC=example,DC=com). - Enable the policy
Require BitLocker encryption on fixed drivesto enforce encryption.
Example GPO Settings:
Policy: Store BitLocker recovery information in Active Directory Domain Services
Enabled
Recovery Key Container: OU=RecoveryKeys,DC=example,DC=com
Step 3: Automate Escrow with GPO¶
To automate recovery key storage, ensure the following: - GPO is linked to the target OU: This ensures all computers in the OU inherit the BitLocker policies. - Use the "Turn on BitLocker" template: This policy automatically enables BitLocker and stores recovery keys in AD DS if configured.
PowerShell Example to Verify Configuration:
This command displays the recovery key location and password, confirming that keys are stored in AD DS.
Step 4: Validate and Troubleshoot¶
- Check GPO inheritance: Use
gpresult /Hto verify that the GPO is applied correctly. - Verify AD DS permissions: Ensure the BitLocker Recovery Agent group has Read permissions on the recovery key container.
- Test recovery key retrieval: Use the
manage-bde -getrecoverykeycommand with the recovery password to confirm key accessibility.
Key takeaways¶
- Store BitLocker recovery keys in AD DS for centralized management and redundancy.
- Configure GPO policies to automate key storage, ensuring compliance with security requirements.
- Validate permissions and GPO inheritance to avoid access issues during recovery.
- Use PowerShell or
manage-bdeto enable BitLocker and verify key storage locations.