Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Network | Monitoring » How to delegate permissions for backing up TPM password
  • Featured image   The Local Device Name is Already in Use
    How to Fix The Local Device Name is Already in Use Windows
  • How to Convert a Distribution Group to a Security Group
    How to convert distribution group to security group Windows Server
  • MECM Deployment copy
    How to install Endpoint Configuration Manager on HyperV VM Windows Server
  • veeam
    How to uninstall Veeam Backup and Replication from your server Backup
  • windows10update 1
    License file was not found in the specified path (Error 0xc1570103) Windows Server
  • Cannot save to the location Windows
    How to Fix Cannot Save to Windows System32 Default.rdp Error Network | Monitoring
  • windows update 03
    Check if Windows Updates were installed Windows
  • SCSI Controoler HyperV issue failed to start VM
    Failed to Power on with Error ‘A virtual machine disk support provider for the specified file was not found Virtualization

How to delegate permissions for backing up TPM password

Posted on 15/10/202117/07/2024 Christian By Christian No Comments on How to delegate permissions for backing up TPM password
Delegating permissions

By delegating control over Active Directory, you are granting users or groups the permissions they need without adding users to privileged groups like Domain Admins, etc. You can use organizational units (OUs) to delegate the administration of objects, such as users or computers, within the OU to a designated individual or group. In this article, we will discuss How to delegate permissions for backing up TPM password. Please see How to enable or disable BitLocker Drive Encryption on Windows 10 and Virtual Machines, and how to clear, enable or disable TPM in Windows via the BIOS or UEFI.

The TPM owner password allows the ability to enable, disable, or clear the TPM without having physical access to the device. For example, by using the command-line tools remotely. The TPM owner password also allows manipulation of the TPM dictionary attack logic. Taking ownership of the TPM is performed by Windows as part of the provisioning process on each boot.

Furthermore, Ownership can change when you share the password or clear your ownership of the TPM so someone else can initialize it.: How to hide the Default BitLocker Drive Encryption item in the Windows Control Panel, how to delegate control for Bitlocker recovery keys in Active Directory, how to deploy Microsoft BitLocker Administration and Monitoring Tool,

Although the TPM owner password is not retained starting with Windows 10, version 1607, or Windows 11. You can change a default registry key to retain it.

However, we strongly recommend that you do not make this change. To retain the TPM owner password, set the registry key ‘HKLM\Software\Policies\Microsoft\TPM’ [REG_DWORD] ‘OSManagedAuthLevel’ to 4. The default value for this key is 2, and unless it is changed to 4 before the TPM is provisioned, the owner password will not be saved.

Windows will not retain the TPM owner password when provisioning the TPM. The password will be set to a random high entropy value and then discarded. Clearing or resetting the TPM resets it to an unowned state. After the TPM is cleared, Windows 10 or 11 OS will automatically re-initialize it and take ownership again.  In this way, the BitLocker encryptions work without any issues.

Delegate permissions Backing up TPM Password

However, Backing up the TPM owner information for a computer allows administrators in a domain to configure the TPM security hardware on the local computer remotely. Moreover, administrators might want to reset the TPM to the manufacturer’s defaults when they decommission or repurpose computers without being present at the computer.

In addition, To delegate this right to an Administrator, please follow the steps below. Launch the Active Directory Users and Computers. I will be using the “dsa.msc” to launch the ADUC snap-in as shown below.

TPM password backup

Nonetheless, This will open the Active Directory Users and Computers console (ADUC). In ADUC (dsa.msc), right-click on the OU that contains your computer objects, and select “Delegate Control”.

Backing up TPM credentials

Click on Next to continue

Permission delegation process

Consequently, This will open the Delegation of Control wizard. Click on Add

Delegating permissions

Here is a similar guide on how to do this “How to backup existing and new BitLocker recovery keys to Active Directory using a simple script“.

Similarly, Add the group you wish to delegate the right to backup BitLocker passwords to AD. Click on Next to proceed.

Screenshot-2021-10-15-at-20.40.59

Select “Create a custom take to delegate”, then click “Next”.

TPM password backup

Select “Only the following objects in the folder”, select “Computer objects”, and then click “Next”.

Screenshot-2021-10-15-at-22.16.59

De-select “General“, and select select Property-specific. Select “Property-specific“, select “Write msTPM-OwnerInformation“, and click “Next”.

Screenshot-2021-10-15-at-22.19.32

Click on Finish to complete the process of delegating permissions for backing up TPM password information.

Screenshot-2021-10-15-at-22.22.30

FAQs

What happens if you return a BitLocker volume to its original PC?

After being moved to a different computer, if the volume is moved back to original TPM it may reuse its original keys, provided they were not over-written. Each BitLockerâ„¢ instance will have a single set of keys if the keys are stored and have not been removed from the original computer the volume should work without recovery when moved back to the original computer

What happens when a User loses his BitLocker PIN?

The recovery key (RK) or recovery password must be used if the PIN is lost. When the PIN scenario is enabled and the new encrypted VMK blob
is stored, the system shall remove the encrypted VMK blob that was encrypted with only the TPM, if such blob is present – except for RK/RK or Recovery Password. In this manner, at next boot, the system will require the two-factor authentication, instead of working with only a TPM. Note: A user is able to change PIN, but it will not be saved/escrowed programmatically

I hope you found this blog post on How to delegate permissions for backing up TPM password helpful. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Network | Monitoring Tags:Bitlocker, TPM, Windows 10, Windows 11

Post navigation

Previous Post: Delegate control for BitLocker recovery keys in Active Directory
Next Post: Git config –global init.defaultBranch: Error cannot lock ref ‘refs/remotes/origin/windows’, not a directory

Related Posts

  • Microaoft Edge
    Bing AI-Powered Copilot: How to install Microsoft Edge on macOS Network | Monitoring
  • cisco general
    How to update Cisco ASA Network | Monitoring
  • Exchange Admin Centre   EMC
    How to grant Access to User Mailbox Network | Monitoring
  • Featured image Excel crash 1
    How to Fix Microsoft Excel Crash Issues Network | Monitoring
  • reset
    How to Reset a Snom Phone Network | Monitoring
  • hgbv
    Graphical Network Simulator: How to install GNS3 on macOS Network | Monitoring

More Related Articles

Microaoft Edge Bing AI-Powered Copilot: How to install Microsoft Edge on macOS Network | Monitoring
cisco general How to update Cisco ASA Network | Monitoring
Exchange Admin Centre   EMC How to grant Access to User Mailbox Network | Monitoring
Featured image Excel crash 1 How to Fix Microsoft Excel Crash Issues Network | Monitoring
reset How to Reset a Snom Phone Network | Monitoring
hgbv Graphical Network Simulator: How to install GNS3 on macOS Network | Monitoring

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Featured image   The Local Device Name is Already in Use
    How to Fix The Local Device Name is Already in Use Windows
  • How to Convert a Distribution Group to a Security Group
    How to convert distribution group to security group Windows Server
  • MECM Deployment copy
    How to install Endpoint Configuration Manager on HyperV VM Windows Server
  • veeam
    How to uninstall Veeam Backup and Replication from your server Backup
  • windows10update 1
    License file was not found in the specified path (Error 0xc1570103) Windows Server
  • Cannot save to the location Windows
    How to Fix Cannot Save to Windows System32 Default.rdp Error Network | Monitoring
  • windows update 03
    Check if Windows Updates were installed Windows
  • SCSI Controoler HyperV issue failed to start VM
    Failed to Power on with Error ‘A virtual machine disk support provider for the specified file was not found Virtualization

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.