

Setup MEM Policy to escrow Bitlocker recovery passwords to Azure AD Device Accounts.Generate a list of Bitlocker recovery keys in MBAM SQL Server.I would suggest the a migration process with 5 steps. The key point of the migration is that, making sure the amount of the recovery key IDs listed by MBAM Server are the same as the ones listed by Azure AD before the cut-off point of time in the migration process. In order to future proof the Bitlocker Management and simplify the administration, some corporates have planned to migrate MBAM data directly from MBAM servers to Microsoft Endpoint Manager. Microsoft BitLocker Administration and Monitoring (MBAM) ended support on, extended support.On-premises BitLocker management using System Center Configuration Manager.Cloud-based BitLocker management using Microsoft Endpoint Manager.Microsoft provides a range of flexible BitLocker management alternatives to meet organization’s needs, as follows: Microsoft BitLocker Administration and Monitoring client agent: Used to manage and configure machines for BitLocker, and return data to the above administration components.ĭocumentation for MBAM can be downloaded from here.Today we discuss about MBAM's Bitlocker data migration to MEM.Group policy template: Configure managed clients using AD GPO.Compliance & audit reports: Use SQL Reporting Services to generate reports from the databases.Recovery & hardware database: stores recovery data for managed clients.Compliance and audit database: stores compliance data for managed clients.Administration & monitoring server: here you have the admin console and a portal, apparently with self-service support for recovery.Also, you can access recovery key information when a user forgets their PIN or password, or when their BIOS or boot record changes”. MBAM lets you select BitLocker encryption policy options appropriate to your enterprise so that you can monitor client compliance with those policies and report on the encryption status of the enterprise in addition to individual computers. “Microsoft BitLocker Administration and Monitoring (MBAM) provides a simplified administrative interface to BitLocker drive encryption (a feature included in Windows 7 Enterprise/Ultimate). To be honest, I hadn’t heard of this MBAM toolset until this morning it’s tucked away in MDOP (Microsoft Desktop Optimization Pack).
