About
Careers
Support
Partners
Community
Contact
Product
Overview
IT Discovery
IT Inventory
IT Analytics
Features
Integrations
Use Cases
IT Asset Management
Cybersecurity
Active Directory Audit
Installing Software & Patches
Automated IT Inventory
Pricing
Resources
Support Knowledge Base
Videos
Testimonials
Vulnerability Updates
Patch Tuesday
Blog
Free Download
Lansweeper
»
Lansweeper questions
»
Bitlocker keys
Active Topics
Search
Join Now
Login
Notification
Error
OK
Bitlocker keys -
What permissions are needed to view
Posted:
Friday, May 20, 2022 9:04:47 AM(UTC)
ccm
Member
Original Poster
Posts: 3
0
Like
This issue has been solved!
Click here to view the solution
Hello,
I'm using lansweeper to report bitlocker keys in ad, however it only works if the user have domain admin rights something that i don't pretend!
I follow the guide to give lanswepper user local admin on machines and domain user in ad, but with that bitlocker report is empty...
#1
SWResearch
Member
Posts: 4
posted:
5/20/2022 9:18:58 AM(UTC)
Originally Posted by: ccm
Hello,
I'm using lansweeper to report bitlocker keys in ad, however it only works if the user have domain admin rights something that i don't pretend!
I follow the guide to give lanswepper user local admin on machines and domain user in ad, but with that bitlocker report is empty...
Account requires access to computer objects in AD, to access ms-Mcs-AdmPwd attribute on the computer object.
User Profile
View All Posts by User
View helpful posts
#2
ccm
Member
Original Poster
Posts: 3
posted:
5/20/2022 9:25:36 AM(UTC)
Is possible to create an account able to retrive the keys but don't have domain admin rights?
User Profile
View All Posts by User
View helpful posts
#3
SWResearch
Member
Posts: 4
posted:
5/20/2022 9:43:27 AM(UTC)
It doesn't require Domain Admin rights, just needs permissions to manage computer objects. For example all of our helpdesk staff have access to objects, i.e. so they can move them between OUs, delete or add computers, but they're not members of the Domain Admin group.
User Profile
View All Posts by User
View helpful posts
#4
ccm
Member
Original Poster
Posts: 3
posted:
5/20/2022 11:04:27 AM(UTC)
Originally Posted by: SWResearch
It doesn't require Domain Admin rights, just needs permissions to manage computer objects. For example all of our helpdesk staff have access to objects, i.e. so they can move them between OUs, delete or add computers, but they're not members of the Domain Admin group.
So should i create a group with that permissions or windows already have an pre created group with that settings?
Thanks
User Profile
View All Posts by User
View helpful posts
#5
SWResearch
Member
Posts: 4
posted:
5/20/2022 1:34:18 PM(UTC)
Apologies I was mixing up LAPS attribute and BitLocker recovery information, the attribute was msFVE-REcoveryInformation, see the following for details on setting up access,
https://kb.wisc.edu/iam/page.php?id=72670
User Profile
View All Posts by User
View helpful posts
Active Discussions
mail reports
by
Andy.S
Last post:
7/1/2022 2:38:18 PM(UTC)
Adding an "Employee ID" column to an asset report
by
ABaker
Last post:
6/30/2022 3:06:54 PM(UTC)
Firefox 102 & ESR 91.11
by
Esben.D
Last post:
6/30/2022 8:12:07 AM(UTC)
Performance report not shows result
by
NoraD
Last post:
6/28/2022 7:52:27 AM(UTC)
Duplicate AD Users
by
Randy Costa
Last post:
6/27/2022 5:25:04 PM(UTC)
Exporting Security event log from Windows results in an error
by
frankm0304
Last post:
6/24/2022 10:41:27 PM(UTC)
htblhistory = default table? unidentified in report generator
by
J_Hol
Last post:
6/23/2022 5:27:18 PM(UTC)
Multiple Devices Owned by Users (asset relations)
by
Adrian Scott
Last post:
6/22/2022 5:34:51 PM(UTC)