Exporting BitLocker recover key from Active Directory


  1. Log on to a domain controller
  2. Launch an escalated PowerShell session
  3. Find the computer in the domain:
    > $computer = Get-ADComputer -Filter { name -eq “computername“}
  4. Export the recovery info
    > Get-ADObject -Filter { objectclass -eq “msFVE-RecoveryInformation”} -SearchBase $computer.DistinguishedName -Properties “msFVE-RecoveryPassword”
  5. The password to recover the encrypted drive is in the “msFVE-RecoveryPassword” field of the output

