Here is the process to create a custom delegation to allow users (other than Domain Admins) to access Bitlocker Recovery keys.
- Log into AD Users and Computers
- Make a new Security group called “deleg-computer-bitlockerrecovery”
- Add the relevant users to the group
- Navigate to the OU where you want to start the delegation.
- Right-click on the OU and select ‘Delegate Control’
- In the ‘Users or Groups’ step enter the newly created “deleg-computer-bitlockerrecovery”
- In the ‘Tasks to Delegate’ select ‘Create a custom task to delegate’
- In the Active Directory Object Type dialog, select Only the following objects in the folder.
- In the list select msFVE-RecoveryInformation objects and click Next
- For permissions set as ‘Full Control’ and select finish
Source: https://blog.michaellecomber.info/2019/05/05/ad-delegate-access-to-view-bitlocker-recovery-keys/
Be First to Comment