BitLocker Recovery

Modified on Mon, 3 Aug at 5:03 PM

TABLE OF CONTENTS


1. Introduction

The five(9)s Console allows authorized users to retrieve BitLocker recovery passwords stored in Active Directory. For security reasons, recovery passwords are masked by default. To reveal the full recovery password, enter the first 8 characters of the corresponding recovery password ID.


Benefits

• Helpdesk and IT staff can retrieve BitLocker recovery passwords without requiring direct permissions to Active Directory.
Access to recovery passwords is controlled through five(9)s Console permissions. Every retrieval of a recovery password is logged in the device history for auditing purposes.

2. Configuration

The BitLocker Recovery feature is available as a dedicated Home button permission and can be assigned to users through Role-Based Administration.


To retrieve BitLocker recovery passwords from Active Directory, the five(9)s Console service account requires read access to the ms-FVE-RecoveryInformation objects. 


Alternatively, you can use a separate AD account by configuring the Central Search Active Directory Service Account. Grant the account the required permissions and add the following setting to:


C:\inetpub\wwwroot\five9sWS\settings.config


 <add key="BitlockerUseAdServiceAccount" value="true" />
Last Modified Date
03.08.2026

Verified versions
five(9)s Console version 5.2

Tags
  • BitLocker
  • Keys  

Disclaimer
Even though every care has been taken by five(9)s GmbH to ensure that the information contained in this publication is correct and complete, it is possible that this is not the case. five(9)s GmbH provides the publication "as is", without any warranty for its soundness, suitability for a different purpose or otherwise. five(9)s GmbH is not liable for any damage which has occurred or may occur as a result of or in any respect related to the use of this publication. five(9)s GmbH may change or terminate this publication at any time without further notice and shall not be responsible for any consequence(s) arising there from. Subject to this disclaimer, five(9)s GmbH is not responsible for any contributions by third parties to this publication.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article