Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Network | Monitoring » Query MBAM to display the BitLocker Recovery report
  • Task Scheduler Error 0x2 1
    How to fix Windows Task Scheduler 0x2 Error Windows
  • Machine does not support XSAve
    How to disable side-channel mitigations on VMware Workstation Virtualization
  • Secure Web Server
    How to secure a Web Server on a Windows VM in Azure using TLS/SSL Certificates Saved in Azure Key Vault AWS/Azure/OpenShift
  • windows 1 2
    How does Dynamic Host Configuration Protocol work Windows Server
  • nodee
    How to install Cypress on Windows and perform Automation Windows
  • Enable or Disable Mac asking for Password
    Enable or Disable Mac asking for Password after Sleep or Screen Saver Mac
  • How to determine Active Directory Site Name
    How to determine Active Directory Site Name Network | Monitoring
  • dasfdg
    Unable to execute: The application GUID not found in the application list Windows Server

Query MBAM to display the BitLocker Recovery report

Posted on 13/10/202226/05/2025 Christian By Christian No Comments on Query MBAM to display the BitLocker Recovery report
images

MBAM reports compliance and other information about all of the computers it manages. The information on this topic can be used to help understand the Microsoft BitLocker Administration and Monitoring reports for enterprise and individual computer compliance and for key recovery activity. In this guide, you will learn how to query MBAM to display the BitLocker Recovery report. Please see: Enterprise Compliance, Computer Compliance, and Recovery Audit Report: Understanding the Microsoft BitLocker Administration and Monitoring (MBAM) reports fields,.

If you can configure SQL Server Reporting Services to send in Enterprise Compliance, Computer Compliance, and Recovery Audit Report on a periodic time (day, week, or on monthly basis) as you wish. Also, you may want to get a specific report for a period of time such as a Monday or week.

By this, you would like to get a list of devices that were recovered from a certain period of time. This guide will help you achieve this goal. Therefore, I would love to describe what can be achieved via the Recovery Audit Report!

Recovery Audit Report

Use this report type to audit users who have requested access to recovery keys. The report offers several filters based on the desired filtering criteria. Users can filter on a specific type of user, either a Help Desk user or an end-user.

Whether the request failed or was successful, the specific type of key requested, and the date range during which the retrieval occurred. The administrator can produce contextual reports based on need.

Also, see MBAM Frequent Report Errors: Understanding Microsoft BitLocker Administration and Monitoring compliance state and error status. How to fix you are not allowed to view this folder on SSRS: MBAM reports cannot be accessed because it could not load folder contents.

Who has access to the MBAM reports?

MBAM Report Users have access to the Compliance and Audit reports in the MBAM administration website.

Note: The local group for this role is installed on the Administration and Monitoring Server, Compliance and Audit Reports Server, and Compliance Status Database Server.

See this guide on how to determine why an MBAM protected device is non-compliant, and how to deploy Microsoft BitLocker Administration and Monitoring Tool.

Query MBAM to display the BitLocker Recovery report for a Specific Period

Open a web browser and navigate to the Administration and Monitoring website (SQL Server Reporting Services via your organisation). When launched, it should look like the image below.

Please select the Recovery Audit Report. 
Screenshot 2022 02 02 at 23.53.39

Select the filters for your Recovery Key Audit report. The available filters for Recovery Key audits are as follows below.

querrymmbamforreport2

The image below shows more filter that can be chosen from for the Recovery Key Audit report. 

querrymmbamforreport1
As you can see below, the results are displayed upon clicking on "View Reports". 

If you wish to share this with your superiors, kindly click on the Save Button in the reports.

Results can be saved in different formats, such as HTML, Microsoft Word, and Microsoft Excel.

querrymmbamforreport

Please see this guide for steps on how to create MBAM Enterprise and Compliance, and Recovery Audit reports.

Note: if you wish to generate an Enterprise Compliance Report, kindly keep this in mind. Historical MBAM client data is retained in the compliance database for historical reference in case a computer is lost or stolen.

When running enterprise reports, we recommend that you use appropriate start and end dates to scope the time frames for the reports from one to two weeks to increase reporting data accuracy.

FAQs

What is the default encryption algorithm for BitLocker?

The default BitLocker device encryption uses the XTS-AES 128-bit encryption method, by default

How can I speed up MBAM Reporting?

In addition to gpupdate /force, you can manually trigger MBAM client reporting using:

Invoke-MbamClientDeployment.ps1 –RecoveryServiceEndpoint https://mbamserver/MBAMRecoveryAndHardwareService/Core

Or restart the MBAM agent service: Restart-Service -Name “MDOP MBAM Agent”

Why do I see “No data available” for encryption status in MBAM?

The “No data available” message indicates that there is a delay configured for the MBAM (Microsoft BitLocker Administration and Monitoring) agent. This delay means the client does not report encryption status to the MBAM server in real-time and helps minimize server load time.

To resolve this, you will need to wait for the next reporting cycle to complete automatically or you can manually trigger a policy update by running the following command in an elevated Command Prompt:

I hope you found this blog post helpful on how to query MBAM to display the BitLocker Recovery report. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Network | Monitoring Tags:Bitlocker, BitLocker Recovery Keys, BitLocker Status, MBAM, MBAM Errors, MBAM Reports, Microsoft BitLocker Administration and Monitoring, Microsoft Windows, recovery, Windows 10, Windows 11

Post navigation

Previous Post: Install Mendeley Reference Manager: How to integrate Mendeley Cite for Microsoft Word on Mac
Next Post: Domain Naming System: Enabling DNS over TLS in Windows 11

Related Posts

  • Windows Admin Center v2   2401 install   2306 to 2311 upgrade
    Upgrade Windows Admin Center 2306 – 2311: Install WACmg 2410 Network | Monitoring
  • exchange 2016 1
    Failed Edge Transport: Easy Guide For Removal Network | Monitoring
  • Preventing Attacks on Cisco Switches Blog Header
    How to enable ssh via ASDM on Cisco ASA Network | Monitoring
  • Fixed Sysprep Generalize Copy
    How to Grant Local Admin Permissions to a Group [Part 1] Network | Monitoring
  • Screenshot 2020 05 14 at 19.08.33
    Backup image to TFTP server Network | Monitoring
  • Exchange Admin Centre   EMC
    How to grant Access to User Mailbox Network | Monitoring

More Related Articles

Windows Admin Center v2   2401 install   2306 to 2311 upgrade Upgrade Windows Admin Center 2306 – 2311: Install WACmg 2410 Network | Monitoring
exchange 2016 1 Failed Edge Transport: Easy Guide For Removal Network | Monitoring
Preventing Attacks on Cisco Switches Blog Header How to enable ssh via ASDM on Cisco ASA Network | Monitoring
Fixed Sysprep Generalize Copy How to Grant Local Admin Permissions to a Group [Part 1] Network | Monitoring
Screenshot 2020 05 14 at 19.08.33 Backup image to TFTP server Network | Monitoring
Exchange Admin Centre   EMC How to grant Access to User Mailbox Network | Monitoring

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a
 
  • Task Scheduler Error 0x2 1
    How to fix Windows Task Scheduler 0x2 Error Windows
  • Machine does not support XSAve
    How to disable side-channel mitigations on VMware Workstation Virtualization
  • Secure Web Server
    How to secure a Web Server on a Windows VM in Azure using TLS/SSL Certificates Saved in Azure Key Vault AWS/Azure/OpenShift
  • windows 1 2
    How does Dynamic Host Configuration Protocol work Windows Server
  • nodee
    How to install Cypress on Windows and perform Automation Windows
  • Enable or Disable Mac asking for Password
    Enable or Disable Mac asking for Password after Sleep or Screen Saver Mac
  • How to determine Active Directory Site Name
    How to determine Active Directory Site Name Network | Monitoring
  • dasfdg
    Unable to execute: The application GUID not found in the application list Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.