Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Understanding Microsoft BitLocker Administration and Monitoring Roles
  • command prompt powershell 670x335 1
    How to Start, Stop and Restart Windows Server Update WSUS Services via PowerShell and CMD Windows
  • GNS3
    How to Connect GNS3 to the internet on Windows Network | Monitoring
  • Screenshot 2021 02 14 at 00.35.50
    How to manage automatic login on Ubuntu Linux Linux
  • task manager not responding thumbnail
    Process Explorer: Replace built-in Task Manager Windows Server
  • vcenter sign on
    CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability Security | Vulnerability Scans and Assessment
  • Remove Frequently Used Folders from Quick Access in Windows 11
    How to Remove Frequently Used Folders from Quick Access in Windows 11 Windows
  • systemd services
    How to use Systemd Timers on Linux Linux
  • Screenshot 2020 12 06 at 17.44.32
    Windows cannot connect to the printer: Operation Failed with error 0x000004f8 Windows

Understanding Microsoft BitLocker Administration and Monitoring Roles

Posted on 07/02/202220/11/2023 Christian By Christian 4 Comments on Understanding Microsoft BitLocker Administration and Monitoring Roles
Microsoft BitLocker Administration and Monitoring Roles

Microsoft BitLocker Administration and Monitoring (MBAM) provides a simplified administrative interface that you can use to manage BitLocker drive encryption. In this article, we shall discuss “Microsoft BitLocker Administration and Monitoring Roles”. You can also report on the encryption status of an individual computer and on the entire enterprise. Please see MBAM Frequent Report Errors: Understanding Microsoft BitLocker Administration and Monitoring compliance state and error status.

As part of the prerequisites, you must define certain roles and accounts that are used in MBAM to provide security and access rights to specific servers and features. Such as the databases that are running on the instance of SQL Server and the web applications that are running on the Administration and Monitoring Server.

Kindly refer to the following guide: How to fix you are not allowed to view this folder on SSRS, how to correctly disable Microsoft BitLocker Administration and Monitoring encrypted devices, and how to hide the Default BitLocker Drive Encryption item in the Windows Control Panel.

Note: Once the installation of Microsoft BitLocker Administration and Monitoring (MBAM) concludes for all server features, administrative users should receive access to these features.

Users and Groups created in Active Directory to support MBAM installation

For optimal practice, assign administrators to Active Directory security groups. Then, add these groups to the relevant MBAM administrative local group. This ensures efficient management of MBAM server features.

We established the subsequent groups and users within Active Directory. Users do not have to have greater user rights. A domain user account is sufficient. You’ll have to specify the name of these groups during the configuration of MBAM 2.5.

Below are the created service accounts and security groups. Service Accounts (users) do not need to have greater user rights.

Service accounts and Security groups in active Directory
Active Directory

Once the Microsoft BitLocker Administration and Monitoring (MBAM) Setup concludes, all server features are ready. Now, we can grant access to these features for administrative users.

For optimal practice, administrators handling Microsoft BitLocker Administration and Monitoring Server features ought to join Domain Services security groups.

Next, ensure the inclusion of these groups in the appropriate MBAM administrative local group. This approach surpasses directly adding users to SSRS Users/Groups for MBAM report administration, as depicted in the image.

Add group or user Directly through SSRS

You are free to use any name of your choice. The image above and the table below illustrate my usage of descriptive names for clear identification within my Lab environment. You are free to use the name you like or as documented in the Microsoft guide.

Also, see how to check if Microsoft BitLocker Administration and Monitoring (MBAM) is installed on Windows and Unable to install Microsoft Bitlocker Administration: Uninstall your current version of MBAM and run setup again.

Example of Description Names to use within Lab Environment

NameSA/ SGDescription
MBAM-RO-SVCUser AccountRead-only service account: Domain user group whose members have read-only access to the reports in the Reports area of the Administration and Monitoring Website
MBAM-RW-SVCUser AccountRead/write service account
MBAM-IISAP-SVCUser AccountIIS application pool service account: Domain user account to be used by the application pool for the web applications. The same account also used to Configure Databases page.
MBAM Helpdesk UsersSecurity GroupMembers of this group are granted read-only access to the helpdesk portal
MBAM Advanced Helpdesk UsersSecurity GroupMembers of this group are provided with helpdesk access without the need to specify user and computer details for recovery
MBAM Report UsersSecurity GroupMembers of this group have access to the MBAM SSRS reports
MBAM Database Read-OnlySecurity GroupSecurity Group for adding Read-Only DB members
MBAM Database Read-WriteSecurity GroupSecurity Group for adding Read-Write DB members

The image below illustrates how we added these accounts and groups to the MBAM (SQL) Server, supporting MBAM deployment. In the post-installation of SQL Server, make sure that you provide the user accounts in SQL Server.

You can allocate permissions to users or groups responsible for setting up the MBAM database and reporting roles on the server. These same prerequisites also apply to the compliance and audit database.

Account added on MBAM (SQL), the account types and their permission types

To manage MBAM Administrator Role memberships

These roles are vital for the installation of MBAM features and the post-installation of MBAM features as well.

Kindly refer to this guide on Deploy MBAM. Also, see how these roles were used in the installation of the MBAM MBAM/features. On the Administration and Monitoring Server, add users to the following local groups to give them access to the MBAM Help Desk website features:

  • MBAM Helpdesk Users: Members of this local group can access the Drive Recovery and Manage TPM features on the MBAM Administration and Monitoring website. A Helpdesk User must complete all fields in Drive Recovery and Manage TPM as they are all mandatory.
  • MBAM Advanced Helpdesk Users: Members of this local group have advanced access to the Drive Recovery and Manage TPM features on the MBAM Administration and Monitoring website. Advanced Helpdesk Users need to fill only the Key ID field in Drive Recovery. For Manage TPM, only the “Computer Domain” and “Computer Name” fields are obligatory.

On the Administration and Monitoring Server. Add users to the following local group to enable them to access the Reports feature on the MBAM Administration and Monitoring website:

  • MBAM Report Users: Members of this local group can access the Reports features on the MBAM Administration and Monitoring website. The image below illustrates how the installation of MBAM reports utilizes this group.
configuring reports of MBAM

I hope you found this blog post on Microsoft BitLocker Administration and Monitoring Roles helpful. If you have any questions, please let me know in the comment session.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:MBAM, Microsoft BitLocker Administration and Monitoring

Post navigation

Previous Post: Enable Virtualization in BIOS: Determine if the Intel VT-x or AMD-V Virtualization Technology is enabled in BIOS
Next Post: Microsoft BitLocker Administration and Monitoring Report Fields

Related Posts

  • Fix Windows Installer Service Could Not Be Accessed Error
    How to Fix the “Windows Installer Service Could Not Be Accessed” Error While Installing an Application Windows
  • Featured image   Network Access Permission...
    Fix You Might Not Have Permission to Use This Network Resource Error Network | Monitoring
  • Windows10 11
    Block Upgrade to Windows 11 via Group Policy or Registry Windows
  • MAP virtual disk error
    Install Workstation Pro 17: Fix failed to initialise library for mounting and unmounting virtual disks Virtualization
  • Fixing TPM Vulnerability
    How to fix a vulnerable Trusted Platform Module [TPM] Windows
  • Screensaver
    How to Enable or Disable Screen Saver on Windows Windows

More Related Articles

Fix Windows Installer Service Could Not Be Accessed Error How to Fix the “Windows Installer Service Could Not Be Accessed” Error While Installing an Application Windows
Featured image   Network Access Permission... Fix You Might Not Have Permission to Use This Network Resource Error Network | Monitoring
Windows10 11 Block Upgrade to Windows 11 via Group Policy or Registry Windows
MAP virtual disk error Install Workstation Pro 17: Fix failed to initialise library for mounting and unmounting virtual disks Virtualization
Fixing TPM Vulnerability How to fix a vulnerable Trusted Platform Module [TPM] Windows
Screensaver How to Enable or Disable Screen Saver on Windows Windows

Comments (4) on “Understanding Microsoft BitLocker Administration and Monitoring Roles”

  1. Avatar photo Carry Josline says:
    20/11/2023 at 2:15 PM

    The Content is very useful.

    I want a suggestion from you regarding MBAM,

    We have MBAM application which is Upgraded from Windows 2012 R2 Data Center to Windows 2019 Data Center, and it is linked to SQL database which in running on Windows 2012 R2, our MBAM application is not working after the upgradation, Will there be any problem with these version difference or this is the only reason behind not working of MBAM application.

    Log in to Reply
    1. chris Christian says:
      20/11/2023 at 3:39 PM

      Thank you for your kind comment. Do you have also the servicing updates installed?

      Log in to Reply
      1. Avatar photo Carry says:
        22/11/2023 at 10:56 AM

        Yes, servicing updates are installed

      2. chris Christian says:
        22/11/2023 at 11:30 AM

        Not sure if this issue still persists. If it does, I would advise you to share the error messages with me. Please take a look at this: MBAM for BitLocker Administration setup.

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • command prompt powershell 670x335 1
    How to Start, Stop and Restart Windows Server Update WSUS Services via PowerShell and CMD Windows
  • GNS3
    How to Connect GNS3 to the internet on Windows Network | Monitoring
  • Screenshot 2021 02 14 at 00.35.50
    How to manage automatic login on Ubuntu Linux Linux
  • task manager not responding thumbnail
    Process Explorer: Replace built-in Task Manager Windows Server
  • vcenter sign on
    CVE-2021-22048: VMware vCenter Server updates address a privilege escalation vulnerability Security | Vulnerability Scans and Assessment
  • Remove Frequently Used Folders from Quick Access in Windows 11
    How to Remove Frequently Used Folders from Quick Access in Windows 11 Windows
  • systemd services
    How to use Systemd Timers on Linux Linux
  • Screenshot 2020 12 06 at 17.44.32
    Windows cannot connect to the printer: Operation Failed with error 0x000004f8 Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,836 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.