Viewer In Active Directory !!top!! - Enable Bitlocker Recovery Password
So he did the thing you’re not supposed to do. He found the script online—from a Microsoft GitHub archive—and ran it against the schema master.
He opened the Group Policy Management Console and navigated to: Computer Configuration -> Policies -> Administrative Templates -> Windows Components -> BitLocker Drive Encryption -> Operating System Drives So he did the thing you’re not supposed to do
He set the second dropdown to Store recovery passwords and key packages . Then, in the field below, he typed a name for the AD container: BitLockerRecovery . Then, in the field below, he typed a
Get-ADObject -Filter ObjectClass -eq "msFVE-RecoveryInformation" -SearchBase "DC=contoso,DC=com" Zero results. Of course. Leo copied it, dialed the VP, and read
Leo copied it, dialed the VP, and read it out in a flat monotone.
By 4 AM, the rain had stopped. Leo looked out the window. The parking lot lights reflected in the wet asphalt like tiny recovery keys waiting to be read.