

Kindly refer to the following similar guides on BitLocker. It allows you to configure your enterprise with the correct BitLocker encryption policy options, as well as monitor compliance with these policies. MBAM is an administrator interface used to manage BitLocker drive encryption.


In this guide, I will show you the steps on how to deploy MBAM for Bitlocker Administration. Kindly refer to these related guides: How to view BitLocker disk encryption status in Windows, how to backup existing and new BitLocker recovery keys to Active Directory, and BitLocker Drive Encryption architecture and implementation types on Windows. The following components are included in the MDOP suite: Microsoft Application Virtualization (App-V), Microsoft User Experience Virtualization (UE-V), Microsoft Advanced Group Policy Management (AGPM), Microsoft Diagnostics & Recovery Toolset (DaRT), and Microsoft BitLocker Administration and Monitoring (MBAM). Performing BitLocker Management with MBAM 2.5 Got a suggestion for MBAM?įor MBAM issues, use the MBAM TechNet Forum.Microsoft Desktop Optimization Pack ( MDOP) is a suite (portfolio) of technologies available to Software Assurance customers through an additional subscription. Your BitLocker recovery key is displayed in the Your BitLocker Recovery Key field.Įnter the 48-digit code into the BitLocker recovery screen on your computer to regain access to the computer. In the Reason field, select a reason for your request for the recovery key.Ĭlick Get Key. If the first eight digits match multiple keys, a message displays that requires you to enter all 32 digits of the recovery key ID. In the Recovery KeyId field, enter a minimum of eight of the 32-digit BitLocker Key ID that is displayed on the BitLocker recovery screen of your computer. To use the Self-Service Portal to regain access to a computer If the IT administrator configured an IIS Session State time-out, a message is displayed in the Self-Service Portal 60 seconds prior to the time-out. Otherwise, they must use the Helpdesk Portal for key recovery.Įnd users may experience lockouts if they:Ĭhange operating system files, the BIOS, or the Trusted Platform Module (TPM) The following instructions are written from the perspective of end users, but the information may be useful for IT administrators to understand.Īn end user must have physically logged on to the computer (not remotely) at least one time successfully to be able to recover their key using the Self-Service Portal. The Self-Service Portal requires no assistance from Help Desk staff. The website enables end users to independently regain access to their computers if they get locked out of Windows. The Self-Service Portal is a website that IT administrators configure as part of their Microsoft BitLocker Administration and Monitoring (MBAM) 2.5 deployment.
