Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saul_Goodman
Participant

Bitlocker Recovery Key

Hi Checkmates,

 

Im having a hard time using Harmony Endpoint FDE Bitlocker Management Recovery Key

 

I have a windows with unmanaged Bitlocker then i installed Harmony Endpoint agent with FDE Bitlocker.

Im doing test using Recovery Key and the challenge comes out.

In the Bitlocker Recovery Documentation below:

  1. Go to Computer Management > Full Disk Encryption Actions > Recovery > BitLocker Recovery

    The BitLocker Management Recovery window opens.

  2. Enter the Computer's Recovery Key ID of the client. The Recovery Key ID is a string of numbers and letters that looks like this:

    C9F38106-9E7C-46AE-8E88-E53948F11776

    After you type a few characters, the Recovery Key ID fills automatically.

The challenge here is i never knew what the Recovery Key ID is nor the first few characters.

When i go to the Bitlocker Management on Windows control panel it seems the Bitlocker Management Window are not accessible anymore i think it is because of the Harmony Endpoint FDE blade.

What are the right steps when deploying FDE Bitlocker Management?

Do i need to export all Recovery Keys from the Endpoint prior to installation of Harmony Endpoint FDE?

If yes what if there are a lot of endpoints with unmanaged Bitlocker? 

0 Kudos
5 Replies
_Val_
Admin
Admin

When you say " unmanaged", what do you mean, a standalone installation? Which versions of Bitlocker and Harmony are in use?

Saul_Goodman
Participant

HI Val,

 

by unmanaged i mean the bitlocker of windows is not centrally managed by bitlocker itself or any third party management but is now being managed by Check Point FDE 

 

The Harmony Agent installed is 86.25.5060

The Harmony Endpoint Management as a Service Version is 81.10.9.73

Version if bitlocker from "manage-bde -status" is Configuration Tool version 10.0.22000 (Not sure if im right)

 

0 Kudos
jcortez
Employee
Employee

@Saul_Goodman 

The expectation here is that you have a Windows machine at the blue BitLocker Recovery screen. There is a  Key ID provided there. The procedure you are giving is not how the product is intended to be used.

And as @_Val_  asked, what do you mean by unmanaged? If you have our client installed with our BitLocker NEM (Native Encryption Management) Policy assigned using our FDE Blade then it is no longer "unmanaged" but managed by a 3rd Party, in this case Check Point Harmony Endpoint.

Please expand.


Justin Cortez
Technology Leader | Endpoint Cyber Security Products | Americas Endpoint Team
0 Kudos
Saul_Goodman
Participant

Hi Justin

 

How do i access the "blue BitLocker Recovery screen"?

0 Kudos
jcortez
Employee
Employee

@Saul_Goodman 

That is a Windows question. By doing a quick Google search I was able to find this...

https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-recover...


Justin Cortez
Technology Leader | Endpoint Cyber Security Products | Americas Endpoint Team
0 Kudos