Over time, Active Directory can collect too many BitLocker keys for the same computer. This happens when a device is set up again or re-encrypted. Because the old keys are never deleted in AD after the backup, it becomes difficult to find the right one when a user is locked out, hardware changes, or multiple BitLocker configuration changes.
When too many BitLocker recovery keys are present, it creates a confusing recovery experience, often after hardware changes, OS reinstallation, or similar events. In such cases, you can use the steps below to remove outdated recovery keys from computers in Active Directory.
Note: It is not recommended to delete recovery keys that are stored unless they are confirmed to be no longer needed.
- In an elevated PowerShell session, run the following command to retrieve the recovery keys linked to the specified computer, including their creation dates. Replace <ComputerDistinguishedName> with the distinguished name of the target workstation.
Get-ADObject -Filter 'objectClass -eq "msFVE-RecoveryInformation"'-SearchBase "<ComputerDistinguishedName>" -Properties msFVE-RecoveryPassword, whenCreated | Select-Object Name, DistinguishedName, msFVE-RecoveryPassword, whenCreated | Format-Table -AutoSize
- Select the correct key by matching the creation date and replace <RecoveryKey> in the cmdlet below with the Distinguished Name of the appropriate recovery key.
Remove-ADObject -Identity "<RecoveryKey>" -Confirm:$true
- Next, click “Y” to confirm the action to remove the BitLocker recovery key for the specified computer.
Note: Formatting a BitLocker-encrypted drive removes BitLocker protection, but it does not delete the recovery key stored in Active Directory. If BitLocker is enabled again, a new recovery key is backed up to Active Directory.
When multiple old recovery keys from the same computer make it difficult to identify the current key, admins can delete all existing keys and back up the current recovery key from the client machine. In such scenarios, you can use the following method to clear the existing records.
- Open PowerShell with admin privileges and run the following cmdlet to remove all the existing BitLocker keys for a computer in Active Directory. Replace <DistinguishedName> with the actual distinguished name of the computer.
Get-ADObject -Filter {objectClass -eq "msFVE-RecoveryInformation"} -SearchBase (Get-ADComputer "<DistinguishedName>").DistinguishedName | Remove-ADObject -Confirm:$true
- Then, confirm the prompt by selecting "A" to remove all the BitLocker recovery keys for the device.