<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bitlocker recovery keys not present in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/371490#M422</link>
    <description>&lt;P&gt;Hi Dfalcon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a tool or some some log which can show, what prerequisites are not met? I have some PC's I think are compliant, but the &lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted"&gt;Disk Encryption Visibility&lt;/SPAN&gt;&lt;/SPAN&gt; portal doesn't share my opinion. And I don't know what is the problem.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 13:29:46 GMT</pubDate>
    <dc:creator>gbagita</dc:creator>
    <dc:date>2020-12-09T13:29:46Z</dc:date>
    <item>
      <title>Bitlocker recovery keys not present</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343002#M234</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I wanted to check if someone can shed some light on this issue I had.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During a Cortex XDR PoC, the end user activated the Disk encryption policy on a couple of workstations without confirming the pre-requisities so these workstations encrypted the HDD (C:) and after the first reboot started asking for the bitlocker recovery key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, the issue is that the key is not present on Active Directory and the user said that it got no other prompt to save the key on the endpoint. My question is that if XDR activated the bitlocker policy and if it was not able to save the recovery key, should it encrypt anyway? I now have a couple of workstations that have their disks encrypted and no way to rollback or unlock them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any tips/help/comments.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 11:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343002#M234</guid>
      <dc:creator>Bruno_Alipio</dc:creator>
      <dc:date>2020-08-10T11:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker recovery keys not present</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343184#M237</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43238"&gt;@Bruno_Alipio&lt;/a&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are several pre-reqs that must be checked off before enabling an encryption policy.&amp;nbsp; They can be found here:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/disk-encryption-using-bitlocker.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/endpoint-security/hardened-endpoint-security/disk-encryption-using-bitlocker.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you are having issues with decryption, it is best to contact Support for assistance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 01:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343184#M237</guid>
      <dc:creator>dfalcon</dc:creator>
      <dc:date>2020-08-11T01:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker recovery keys not present</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343223#M238</link>
      <description>Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/47142"&gt;@dfalcon&lt;/a&gt;, thanks for the feedback, I opened a case in support but unfortunately they where not able to help. I'm just trying to figure out the standard behavior if the prerequisites are not met. If the bitlocker process cant save the recovery keys to the AD, should it present a GUI to the user asking for USB/print/local file? Is there anyway that the XDR agent is enabling the bitlocker and asking for a silent process?</description>
      <pubDate>Tue, 11 Aug 2020 08:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/343223#M238</guid>
      <dc:creator>Bruno_Alipio</dc:creator>
      <dc:date>2020-08-11T08:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Bitlocker recovery keys not present</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/371490#M422</link>
      <description>&lt;P&gt;Hi Dfalcon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a tool or some some log which can show, what prerequisites are not met? I have some PC's I think are compliant, but the &lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted"&gt;Disk Encryption Visibility&lt;/SPAN&gt;&lt;/SPAN&gt; portal doesn't share my opinion. And I don't know what is the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 13:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bitlocker-recovery-keys-not-present/m-p/371490#M422</guid>
      <dc:creator>gbagita</dc:creator>
      <dc:date>2020-12-09T13:29:46Z</dc:date>
    </item>
  </channel>
</rss>

