Return to site

Generate bitlocker recovery key from password

broken image

The site deploys the recovery service when you create a BitLocker management policy. The BitLocker recovery service is a server component that receives BitLocker recovery data from Configuration Manager clients. If any clients are on version 2010 or earlier, they need an HTTPS-enabled recovery service on the management point to escrow their keys. When both the site and clients are running Configuration Manager version 2103 or later, clients send their recovery keys to the management point over the secure client notification channel. This configuration doesn't affect the functionality of BitLocker management in Configuration Manager. With this change, you can enable the Configuration Manager site for enhanced HTTP. They escrow their recovery keys over the secure client notification channel. All version 2103 clients use the message processing engine component of the management point as their recovery service. It's no longer using legacy MBAM components, but is still conceptually referred to as the recovery service. Starting in version 2103, the implementation of the recovery service changed.

broken image