Active Directory Bitlocker Recovery Key
If the computer detects a security risk (e.g., a TPM change, a BIOS update, or a forgotten password), it enters . In this state, the user must enter a 48-digit numerical password known as the Recovery Key to regain access to the data.
: By default, only Domain Administrators have permission to view recovery keys. However, these rights can be delegated to specific support personnel. Configuring Automatic Backup via Group Policy (GPO) active directory bitlocker recovery key