GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — Active Directory backup information sub-option. Controls what BitLocker recovery information is stored in Active Directory Domain Services (AD DS) when backup is enabled for fixed data drives. Registry: HKLM\SOFTWARE\Policies\Microsoft\FVE:FDVActiveDirectoryInfoToStore (REG_DWORD). Reference: BitLocker CSP (FixedDrivesRecoveryOptions)
Values
| Enum Value | Description |
|---|---|
|
|
Store both BitLocker recovery passwords and key packages in AD DS (registry value 1). Both the 48-digit recovery password and the full key package (needed for advanced recovery) are backed up to AD DS. |
|
|
Store only BitLocker recovery passwords in AD DS (registry value 2). Only the 48-digit recovery password is backed up; the key package is not stored. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"PASSWORDS_AND_KEY_PACKAGES"