TABLE OF CONTENTS
1. Introduction

Benefits
• Helpdesk and IT staff can retrieve BitLocker recovery passwords without requiring direct permissions to Active Directory. • Access to recovery passwords is controlled through five(9)s Console permissions. • Every retrieval of a recovery password is logged in the device history for auditing purposes.
2. Configuration
The BitLocker Recovery feature is available as a dedicated Home button permission and can be assigned to users through Role-Based Administration.
To retrieve BitLocker recovery passwords from Active Directory, the five(9)s Console service account requires read access to the ms-FVE-RecoveryInformation objects.
Alternatively, you can use a separate AD account by configuring the Central Search Active Directory Service Account. Grant the account the required permissions and add the following setting to:
C:\inetpub\wwwroot\five9sWS\settings.config
<add key="BitlockerUseAdServiceAccount" value="true" />Tags
- BitLocker
- Keys
Disclaimer
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article