Hello,
We've been experiencing issues using Challenge/Response with the latest SafeGuard 8.00.5 client on Windows Bitlocker clients. We just had a case where a feature update occurred and the computer was not encrypted at the time (likely due to TPM status). When the computer updated to feature update 1803 it resolved it's TPM issue and was able to encrypt but when the update failed the actual .bek recovery key file was not able to unlock the drive.
Each time the computer restarted it would go to Bitlocker recovery, we'd execute challenge/response, and the computer would go into Windows recovery/repair. Then we attempted to unlock the drive and decrypt with the actual .bek file but it could not decrypt the drive, invalid key. We also attempted to repair the UEFI startup entries but that did not work. We basically got stuck.
This is not the first time we've had issues with SafeGuard/Bitlocker Challenge/Response. In some cases, updates/feature updates have broken the UEFI boot entries and the option to enter Challenge/Response disappeared. We've been able to repair that issue but with all the issues involved we'd like to move away from it completely and keep a simple Bitlocker configuration with recovery key.
So, is there an easy way to migrate away from Bitlocker C/R to standard recovery key without decrypting? What would be the process?
Bonus question, recommended method for moving clients from TPM to boot password without decrypting? Is this the right path? - https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/manage-bde-protectors
Thank you!
This thread was automatically locked due to age.