100-140 Question 249
Select 2A user reports that they are unable to access their laptop after a recent restart and are prompted to enter a BitLocker recovery key. As an IT support technician, what is the most appropriate way to retrieve the BitLocker recovery key for the user?
- A
Check the user's Microsoft account for the recovery key.
- B
Disable BitLocker from the BIOS to bypass the recovery key prompt.
- C
Ask the user to reset their Windows password to unlock BitLocker.
- D
Verify if the recovery key is stored in Active Directory or Azure AD, depending on the organization's configuration.
Show answer and explanation
Correct answers: A, D
Explanation
The BitLocker recovery key is essential for unlocking an encrypted drive. It may be stored in the user's Microsoft account for personal devices or in Active Directory or Azure AD for organizational devices. These are the correct and secure methods to retrieve the recovery key, depending on the device management configuration. Disabling BitLocker from the BIOS or resetting passwords will not help in this scenario.
- A. Correct.
Microsoft accounts often store BitLocker recovery keys automatically if BitLocker was enabled using a personal account. This is a valid starting point.
- B. Incorrect.
Disabling BitLocker from the BIOS is not a valid or secure method to bypass the recovery key prompt. This is not recommended or feasible.
- C. Incorrect.
Resetting the Windows password does not bypass or unlock BitLocker. The recovery key is independent of the Windows login credentials.
- D. Correct.
In organizational environments, recovery keys may be stored in Active Directory (AD) or Azure AD if BitLocker was deployed centrally. This is a valid method for recovery.