Get-ADObject -Filter objectclass -eq "msFVE-RecoveryInformation" -and Name -like "*B1B2B3B4*" -Properties msFVE-RecoveryPassword
Replace the ID snippet below with the ID displayed on the user's screen.
The BitLocker Drive Encryption Administration feature must be installed on your Domain Controller or management workstation to provide the necessary tabs in AD management consoles.
Tip: If you don't know the full DistinguishedName (SearchBase), you can combine commands to find it automatically:
Click . The results will display the full 48-digit key and the computer it is linked to. Method 3: Using PowerShell
This is the most common method for administrators who prefer a visual interface.
: Click the BitLocker Recovery tab. All recovery passwords associated with that device will be listed here, along with their respective Recovery IDs .