Article ID: 928202 - Last Review: February 19, 2009 - Revision: 8.1 How to use the BitLocker Recovery Password Viewer for Active Directory Users and Computers tool to view recovery passwords for Windows VistaOn This PageINTRODUCTIONThis article describes how to use the BitLocker Recovery Password Viewer
for Active Directory Users and Computers tool. The BitLocker Drive Encryption feature is a data protection feature that is included with the following versions of Windows Vista:
Collapse this table
For more information about RSAT tools, click the following article number to view the article in the Microsoft Knowledge Base: 941314
(http://support.microsoft.com/kb/941314/
)
Microsoft Remote Server Administration Tools for Windows Vista
Collapse this table
For more information about how to obtain and use the bitlock repair tool, click the following article number to view the article in the Microsoft Knowledge Base: 933246
(http://support.microsoft.com/kb/933246/
)
Description of the BitLocker Drive Preparation Tool
OverviewThe BitLocker Recovery Password Viewer lets you locate and view BitLocker recovery passwords that are stored in AD DS. You can use this tool to help recover data that is stored on a volume that has been encrypted by using BitLocker. The BitLocker Recovery Password Viewer tool is an extension for the Active Directory Users and Computers MMC snap-in. After you install this tool, you can examine the Properties dialog box of a computer object to view the corresponding BitLocker recovery passwords. Additionally, you can right-click a domain container and then search for a BitLocker recovery password across all the domains in the Active Directory forest (multiple domains) .Before you can use the BitLocker Recovery Password Viewer tool to view BitLocker recovery passwords, the following conditions must be true:
http://windowshelp.microsoft.com/Windows/en-US/Help/86136f63-2f2f-40ad-a0d1-8293f4dbfc951033.mspx
(http://windowshelp.microsoft.com/Windows/en-US/Help/86136f63-2f2f-40ad-a0d1-8293f4dbfc951033.mspx)
Also, we recommend that you understand how to use BitLocker recovery passwords to unlock an encrypted volume. For more information about how to use BitLocker, visit the following Microsoft Web site:http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx (http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx) http://technet.microsoft.com/en-us/windowsvista/aa906017.aspx
(http://technet.microsoft.com/en-us/windowsvista/aa906017.aspx)
How to obtain the BitLocker Recovery Password Viewer toolHow to obtain the BitLocker Recovery Password Viewer tool for Windows Vista Enterprise, for Windows Vista Enterprise Service Pack 1, and for Windows Server 2008If you are using Windows Vista Enterprise or Windows Server 2008, visit the following Microsoft Web site to obtain this tool:http://www.microsoft.com/downloads/details.aspx?familyid=2786FDE9-5986-4ED6-8FE4-F88E2492A5BD&displaylang=en
(http://www.microsoft.com/downloads/details.aspx?familyid=2786FDE9-5986-4ED6-8FE4-F88E2492A5BD&displaylang=en)
How to obtain the BitLocker Recovery Password Viewer tool for Windows VistaTo install the BitLocker Recovery Password Viewer tool on a Windows XP-based computer, you must first install the latest version of the Windows Server 2003 Administration Tools. To obtain this program, visit the following Microsoft Web site:http://www.microsoft.com/downloads/details.aspx?FamilyID=E487F885-F0C7-436A-A392-25793A25BAD7&displaylang=en
(http://www.microsoft.com/downloads/details.aspx?FamilyID=E487F885-F0C7-436A-A392-25793A25BAD7&displaylang=en)
Installation rights for the BitLocker Recovery Password Viewer toolTo install the BitLocker Recovery Password Viewer tool successfully, the installation program must update the Active Directory configuration database.The installation program adds the following two attributes to AD DS if these two attributes are not already present. Collapse this table
Collapse this table
To summarize, you must have the following rights to install the BitLocker Recovery Password Viewer tool:
Registry informationBefore you run this tool on the domain for the first time, run the following command from your Windows system folder as an Enterprise Administrator: regsvr32.exe BdeAducExt.dll When you later use the tool on the domain, you will not have to run Regsvr32.exe.Installation troubleshooting informationThe installation rights are the same for Windows XP and Windows Vista. Use the following information to help troubleshoot installation error messages that you may receive when you install the BitLocker Recovery Password Viewer tool:Error message 1 Not enough storage is available to process this command. Error message 2 You do not have permission to update Windows XP. Please contact your system administrator. Error message 3 Cannot connect to the domain controller. You must be logged in as a domain user with a connection to the network.
You do not have permissions to perform this install. Enterprise administrative rights are required. Error message 5 Installation failed with error code: 0x8007200A To remove the BitLocker Recovery Password Viewer toolTo remove the Bitlocker Recovery tool, follow these steps:
Usage informationThe BitLocker Recovery Password Viewer tool extends the Active Directory Users and Computers MMC snap-in. To start Active Directory Users and Computers, click Start, click Run, type dsa.msc, and then click OK.The following information describes how to use the BitLocker Recovery Password Viewer tool. To view the recovery passwords for a computer
To copy the recovery passwords for a computer
To locate a recovery password
Collapse this image ![]() Frequently asked questions about the BitLocker Recovery Password Viewer toolQ1: How can the BitLocker Recovery Password Viewer tool help unlock an encrypted volume?A1: When you start the computer to the BitLocker Recovery screen, Windows Vista gives you a drive label and a password ID. You can use this information together with the BitLocker Recovery Password Viewer tool to locate the matching BitLocker recovery password that is stored in AD DS. Q2: Can anybody use the BitLocker Recovery Password Viewer tool to locate recovery passwords? A2: No. To view recovery passwords, you must be a domain administrator, or you must have been delegated permissions by a domain administrator. If a user who does not have sufficient rights installs the BitLocker Recovery Password Viewer tool, that user cannot locate any recovery passwords for any computer. Also, if you use the BitLocker Recovery Password Viewer tool to search for recovery passwords among all the domains in a forest, results are returned only from the domains in which you have sufficient rights. Note The BitLocker Recovery Password Viewer tool cannot distinguish between a situation in which no recovery passwords exist for a particular computer and a situation in which you do not have sufficient rights to view the recovery password for a particular computer. Q3: What if a stored recovery password does not appear on the "BitLocker Recovery" tab of a computer's "ComputerName Properties" dialog box? A3: Usually, the BitLocker recovery passwords for a particular computer appear on the BitLocker Recovery tab of the ComputerName Properties dialog box for that computer. However, if a computer is renamed, you may be unable to locate the correct computer. This is because the drive label information still contains the original computer name. In this situation, you must use the password ID information to search for the recovery password. Q4: Why are only the first eight characters of the password ID used to search for the location of a recovery password? A4: This is a design decision that is intended to help simplify searching for recovery passwords without sacrificing the accuracy of the search operation. Tests that randomly generated over one million password IDs typically yielded only 100 duplicates for the first eight characters of the password ID. Therefore, even if you have one million recovery passwords in a search domain, it is unlikely that two recovery passwords will be returned by a single search operation. Additionally, it is even more unlikely that more than two recovery passwords will be returned in the same search. Note We recommend that you examine the returned recovery password to make sure that it matches the whole password ID that you used to perform the search. This is to verify that you have obtained the unique recovery password. Q5: How long does it take to search for a recovery password across all domains? A5: Generally, it takes no more than several seconds to search for a password ID across all the domains of a forest. However, you may experience decreased performance if the following conditions are true:
A6: Use the following information to help troubleshoot issues that you experience when you use the BitLocker Recovery Password Viewer tool:
APPLIES TO
| Article Translations
|
Back to the top

