{"id":831,"date":"2023-08-15T11:13:06","date_gmt":"2023-08-15T03:13:06","guid":{"rendered":"https:\/\/www.ruianding.com\/blog\/?p=831"},"modified":"2023-09-14T19:28:24","modified_gmt":"2023-09-14T11:28:24","slug":"troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad","status":"publish","type":"post","link":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/","title":{"rendered":"Troubleshooting the Backup of BitLocker Keys to Azure AD"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Overview<\/h3>\n\n\n\n<p>Once the device is registered to Azure Active Directory (AAD), AAD provides an option to securely store the BitLocker recovery key within the AAD database.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\" alt=\"\" class=\"wp-image-836\" width=\"426\" height=\"321\"\/><\/figure>\n\n\n\n<p>AAD will provide the device with a certificate that is stored in the computer&#8217;s certificate store (for AAD-registered devices, the certificate is in the user store). This certificate&#8217;s subject name matches the AAD device ID, and it is issued by <strong>MS-Organization-Access.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-26.png\" alt=\"\" class=\"wp-image-833\" width=\"703\" height=\"213\"\/><\/figure>\n\n\n\n<p>To securely store the recovery key in AAD, the client machine needs to communicate with the https:\/\/enterpriseregistration.windows.net\/ endpoint. During this process, the client machine sends its key ID along with the recovery key. To establish its identity, the client needs to present its device certificate to this endpoint. To capture this uploading process for analysis, you can use tools like Fiddler.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. SSL Related Issue<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1.1 Monitoring the Entire Flow Using Fiddler<\/h4>\n\n\n\n<p>When enabling Fiddler&#8217;s capture feature, there&#8217;s a possibility of disrupting client certificate authentication, leading to a persistent HTTP 401 error.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-29.png\" alt=\"\" class=\"wp-image-839\" width=\"637\" height=\"415\"\/><\/figure>\n\n\n\n<p>To effectively capture Fiddler traces without this issue, it&#8217;s necessary to save the device certificate as <strong>&#8216;ClientCertificate.cer&#8217;<\/strong> in the following path: <code>%USERPROFILE%\\My Documents\\Fiddler2\\ClientCertificate.cer<\/code><\/p>\n\n\n\n<p class=\"has-luminous-vivid-amber-background-color has-background has-small-font-size\">This action enables Fiddler to automatically select the correct device certificate for the process.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1.2 The certificate issuer has been tampered with by the SSL inspector<\/h4>\n\n\n\n<p>I&#8217;ve encountered a situation where, while establishing a TLS handshake with the DRS endpoint, it became apparent from the Server Hello frames that an intermediary network device or proxy server was involved. This interference resulted in the alteration of the issuer information in the device certificate returned by the Server Hello. This alteration was responsible for the failure of BitLocker key backup as well.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-31.png\" alt=\"\" class=\"wp-image-842\" width=\"729\" height=\"307\"\/><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Once the device is registered to Azure Active Directory (AAD), AAD provides an option to securely store the BitLocker recovery key within the AAD database. AAD will provide the device with a certificate that is stored in the computer&#8217;s certificate store (for AAD-registered devices, the certificate is in the user store). This certificate&#8217;s subject [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[12,40,11],"tags":[],"class_list":["post-831","post","type-post","status-publish","format-standard","hentry","category-troubleshooting","category-drs-windows","category-workflow"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"og:description\" content=\"Overview Once the device is registered to Azure Active Directory (AAD), AAD provides an option to securely store the BitLocker recovery key within the AAD database. AAD will provide the device with a certificate that is stored in the computer&#8217;s certificate store (for AAD-registered devices, the certificate is in the user store). This certificate&#8217;s subject [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\" \/>\n<meta property=\"og:site_name\" content=\"\u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-15T03:13:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-09-14T11:28:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\" \/>\n<meta name=\"author\" content=\"Ruian Ding\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ruian Ding\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\"},\"author\":{\"name\":\"Ruian Ding\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"headline\":\"Troubleshooting the Backup of BitLocker Keys to Azure AD\",\"datePublished\":\"2023-08-15T03:13:06+00:00\",\"dateModified\":\"2023-09-14T11:28:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\"},\"wordCount\":285,\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\",\"articleSection\":[\"Troubleshooting\",\"Windows\",\"Workflow\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\",\"name\":\"Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\",\"datePublished\":\"2023-08-15T03:13:06+00:00\",\"dateModified\":\"2023-09-14T11:28:24+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png\",\"width\":617,\"height\":465},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.ruianding.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Troubleshooting the Backup of BitLocker Keys to Azure AD\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\",\"url\":\"https:\/\/www.ruianding.com\/blog\/\",\"name\":\"Ruian's Tech Troubleshooting Toolbox\",\"description\":\"Debug the World.\",\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"alternateName\":\"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\",\"name\":\"Ruian Ding\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"width\":284,\"height\":284,\"caption\":\"Ruian Ding\"},\"logo\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.\",\"sameAs\":[\"https:\/\/www.ruianding.com\"],\"url\":\"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/","og_locale":"en_US","og_type":"article","og_title":"Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT","og_description":"Overview Once the device is registered to Azure Active Directory (AAD), AAD provides an option to securely store the BitLocker recovery key within the AAD database. AAD will provide the device with a certificate that is stored in the computer&#8217;s certificate store (for AAD-registered devices, the certificate is in the user store). This certificate&#8217;s subject [&hellip;]","og_url":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/","og_site_name":"\u6781\u7b80IT\uff5cSimpleIT","article_published_time":"2023-08-15T03:13:06+00:00","article_modified_time":"2023-09-14T11:28:24+00:00","og_image":[{"url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png","type":"","width":"","height":""}],"author":"Ruian Ding","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ruian Ding","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#article","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/"},"author":{"name":"Ruian Ding","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"headline":"Troubleshooting the Backup of BitLocker Keys to Azure AD","datePublished":"2023-08-15T03:13:06+00:00","dateModified":"2023-09-14T11:28:24+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/"},"wordCount":285,"publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png","articleSection":["Troubleshooting","Windows","Workflow"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/","url":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/","name":"Troubleshooting the Backup of BitLocker Keys to Azure AD - \u6781\u7b80IT\uff5cSimpleIT","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png","datePublished":"2023-08-15T03:13:06+00:00","dateModified":"2023-09-14T11:28:24+00:00","breadcrumb":{"@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#primaryimage","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/08\/image-28.png","width":617,"height":465},{"@type":"BreadcrumbList","@id":"https:\/\/www.ruianding.com\/blog\/troubleshooting-the-backup-of-bitlocker-keys-to-azure-ad\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ruianding.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Troubleshooting the Backup of BitLocker Keys to Azure AD"}]},{"@type":"WebSite","@id":"https:\/\/www.ruianding.com\/blog\/#website","url":"https:\/\/www.ruianding.com\/blog\/","name":"Ruian's Tech Troubleshooting Toolbox","description":"Debug the World.","publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"alternateName":"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b","name":"Ruian Ding","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","width":284,"height":284,"caption":"Ruian Ding"},"logo":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/"},"description":"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.","sameAs":["https:\/\/www.ruianding.com"],"url":"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/comments?post=831"}],"version-history":[{"count":3,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/831\/revisions"}],"predecessor-version":[{"id":843,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/831\/revisions\/843"}],"wp:attachment":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/media?parent=831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/categories?post=831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/tags?post=831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}