What’s the Best Way to Share BitLocker Keys Securely?

0
10
Asked By CuriousChipmunk42 On

How can I securely share BitLocker keys with users in my organization? Currently, our help desk just sends the keys via Teams chat, but I'm looking for a more secure method. We've got around 30,000 devices managed through Intune, and we're seeing an increase in calls for recovery keys, possibly due to a recent SecureBoot certificate update. One idea I had was to use expiring QR codes, but I'm not sure how safe that is. Am I overthinking this situation?

5 Answers

Answered By TeamRotate On

It’s a good practice to just rotate the key after the user successfully logs back in. Honestly, they probably write it down while you’re reading it out anyway, so better safe than sorry!

TrustyTechie -

Exactly, that’s the protocol we follow too—helps keep things secure.

LittleLiesLol -

Right! I tell users upfront that it's a one-time key, so they’re aware.

Answered By PortalPioneer On

You might want to think about setting up a BitLocker self-service recovery portal. It allows users to unlock their devices themselves without needing to contact support every time.

SkepticalSteve -

That could work, but if they’re using personal devices, it complicates things.

Answered By BitwardenBuddy On

Consider using Bitwarden Send if you have a password manager that offers that feature. It's a more secure method and gives you visibility without relying on third-party sites.

Answered By SecurityFirst34 On

You might be overthinking it a bit. Instead of complicating the sharing process, just share the key and change it later. Users often jot it down anyway, so rotating it right after they use it is a solid strategy.

BackupBob -

Exactly! We always change it after they've recovered.

Answered By TechGuru88 On

Honestly, just send the key through Teams or Slack and rotate it once the user is back online. It's straightforward and works.

HelpfulHannah -

Totally agree, rotating the key is key after it’s used!

RMMRandy -

Yeah, our remote monitoring system fetches the keys for us with no hassle.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.