GPO policy: "Choose how BitLocker-protected fixed drives can be recovered" — require AD DS backup before enabling BitLocker. Controls whether BitLocker can be enabled on a fixed data drive before recovery information has been successfully backed up to Active Directory. Registry: HKLM\SOFTWARE\Policies\Microsoft\FVE:FDVRequireActiveDirectoryBackup (REG_DWORD). Reference: BitLocker CSP (FixedDrivesRecoveryOptions)
Values
| Enum Value | Description |
|---|---|
|
|
AD DS backup not required before enabling BitLocker (registry value 0). BitLocker can be enabled on fixed data drives even if AD DS backup has not yet completed. |
|
|
AD DS backup required before enabling BitLocker (registry value 1). BitLocker cannot be enabled on a fixed data drive until its recovery information has been successfully saved to Active Directory. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"NOT_REQUIRED"