Bitlocker Recovery Key Azure Ad Review
without first verifying keys are no longer needed.
| Aspect | Detail | |--------|--------| | | AES-256 for stored keys | | Encryption in transit | TLS 1.2+ | | Audit logging | All key retrievals logged in Entra ID audit logs (Category: DeviceManagement) | | Key separation | Keys stored independently from user data | | Retention | Key persists even if device is disabled; removed only when device is deleted from Entra ID | | Compliance | Supports FedRAMP High, HIPAA, ISO 27001, SOC | bitlocker recovery key azure ad
When a Windows device is or Hybrid Entra ID joined , and BitLocker is enabled (either manually or via policy), the recovery password and key package are uploaded to the device’s object in Entra ID. without first verifying keys are no longer needed