UPDATE: There is currently an issue with the graph API permissions for reading the BitLocker recovery key info (the createdDateTime).
Watch here: • Updated BitLocker Key rotation
In the meantime, check out my updated version which uses a self-declared time stamp to rotate every 30 days:
https://github.com/stevecapacity/Intu...
Stay tuned
*********************************************************************************************
Last week wasn't fun for most folks.
But instead of going through a post-mortem debrief, I wanted to take a more proactive approach to help.
Many organizations had to get their BitLocker recovery keys to their support staff and end-users very quickly. Most of this was done by just a simple export of .csv files, and it's a good idea to them changed now they've been set free.
So today, I'll show you how we can use Intune, remediations, and Azure automation to ensure you Intune managed PCs having their BitLocker key automatically rotated every 30 days.
Mr. T-Bone's automation blog:
https://www.tbone.se/2024/01/04/creat...
Scripts used today:
https://github.com/stevecapacity/Intu...
Join the official Discord server
/ discord
Read more at
https://www.getrubix.com
Chapters
0:00:00 Dunkin problems
0:01:33 Today's topics
0:02:30 Rotate Bitlocker Key policy
0:03:24 How to manually rotate a key
0:04:37 How do we rotate all the keys?
0:05:28 Keys in the graph
0:08:43 To the white board!!!
0:10:10 Create the scripts
0:11:11 Client script
0:13:32 Webhook script
0:16:02 Getting the keys
0:20:42 Checking if the key date
0:24:17 Create an automation account
0:26:32 Mr. T-Bone's permission script
0:27:06 Add graph module
0:27:58 Create a runbook
0:29:05 Generate a webhook
0:29:35 Local test
0:31:07 Upload detection script to Intune
0:33:04 A proactive solution
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm