Configure MBAM services

Note: If MBAM is configured to run with Microsoft Configuration Manager, disable the "MBAM Status reporting service" and leave the "MBAM Status reporting service end point" blank. This information is managed in Microsoft Configuration Manager.

This policy setting allows you to manage the key recovery service backup of BitLocker Drive Encryption recovery information. This provides an administrative method of recovering data encrypted by BitLocker to prevent data loss due to lack of key information.

The URL for MBAM Recovery service endpoint is
http(s)://:/MBAMRecoveryAndHardwareService/CoreService.svc

The URL for MBAM Status reporting service endpoint is
http(s)://:/MBAMComplianceStatusService/StatusReportingService.svc

Replace the server name and port number on above URL based on the installation of the MBAM.

BitLocker recovery information includes the recovery password and some unique identifier data. You can also select to include a package that contains a BitLocker protected drive's encryption key. This key package is secured by one or more recovery passwords and may help perform specialized recovery when the disk is damaged or corrupted.

This policy setting manages how often the client will check the BitLocker protection policies and status on the client machine.

This policy setting allows you to manage the compliance and status information to be saved at report server location. This provides an administrative method of generating a compliance and status report.

This policy setting allows you to manage the frequency of the compliance and status information to be reported to the report service.

The frequency is every 1 minute to 2880 minutes (48 hours). The default for the client to check status is 90 minutes and the default for status reporting is 720 minutes. Frequency values smaller than the defaults will increase network and server utilization and could limit the number of clients MBAM can process.

If you enable this policy setting, key recovery info will be automatically and silently backed up to the configured key recovery server location and status report will be automatically and silently sent to configured report server location.

If you disable or do not configure this policy setting, the key recovery and the status report information will not be saved.

Supported on: At least Windows 7

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameUseMBAMServices
Value TypeREG_DWORD
Enabled Value1
Disabled Value0
Enable policy:
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameUseKeyRecoveryService
Value TypeREG_DWORD
Value1

MBAM Recovery service endpoint:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameKeyRecoveryServiceEndPoint
Value TypeREG_EXPAND_SZ
Default Value
Select BitLocker recovery information to store:


  1. Recovery password only
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
    Value NameKeyRecoveryOptions
    Value TypeREG_DWORD
    Value0
  2. Recovery password and key package
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
    Value NameKeyRecoveryOptions
    Value TypeREG_DWORD
    Value1

Enter client checking status frequency in (minutes):

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameClientWakeupFrequency
Value TypeREG_DWORD
Default Value90
Min Value1
Max Value2880
Configure MBAM Status reporting service:


  1. Disabled
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
    Value NameUseStatusReportingService
    Value TypeREG_DWORD
    Value0
  2. Enabled
    Registry HiveHKEY_LOCAL_MACHINE
    Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
    Value NameUseStatusReportingService
    Value TypeREG_DWORD
    Value1

MBAM Status reporting service endpoint:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameStatusReportingServiceEndpoint
Value TypeREG_EXPAND_SZ
Default Value
Enter status report frequency in (minutes):

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\FVE\MDOPBitLockerManagement
Value NameStatusReportingFrequency
Value TypeREG_DWORD
Default Value720
Min Value1
Max Value2880

bitlockermanagement.admx

Administrative Templates (Computers)

Administrative Templates (Users)