Managing and recovering encrypted volumes
Now that we have an understanding surrounding BitLocker setup and know that recovery information is saved inside of Active Directory Domain Services (or Azure AD prior to the looming April 2026 mainstream end of support for Microsoft BitLocker Administration and Monitoring), let’s walk through an overview of how we can manage BitLocker in a hybrid environment.
As with all Microsoft tools, there is a legacy configuration approach and a related PowerShell management approach. BitLocker is no exception here, as there is a myriad of PowerShell cmdlets to help you manage this task across an organization. A full list of PowerShell cmdlets for BitLocker administration can be found here: https://docs.microsoft.com/windows/security/information-protection/bitlocker/bitlocker-basic-deployment#encrypting-volumes-using-the-bitlocker-windows-powershell-cmdlets.
To reduce frustration for administrators and users, a feature called BitLocker Key...