---
title: RecoveryPasswordOption enum | Wartiva GraphQL API
description: GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — recovery password option. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/recovery-password-option.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `RecoveryPasswordOption` enum

GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — recovery password option, under Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Fixed Data Drives. Controls whether a 48-digit recovery password may or must be generated when BitLocker is enabled on fixed data drives. Registry: HKLM\SOFTWARE\Policies\Microsoft\FVE:FDVRecoveryPassword (REG_DWORD). Reference: [BitLocker CSP (FixedDrivesRecoveryOptions)](https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#fixeddrivesrecoveryoptions)

## Values

| Enum Value | Description |
|---|---|
| `DISALLOW` | Recovery passwords are not allowed (registry value 0). A 48-digit recovery password will not be generated for fixed data drives. Users must use a different recovery method. |
| `REQUIRE` | A recovery password is required (registry value 1). BitLocker cannot be enabled on a fixed data drive unless a 48-digit recovery password is generated. |
| `ALLOW` | A recovery password is allowed but not required (registry value 2). Users may choose to generate a 48-digit recovery password, but it is optional. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"DISALLOW"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
