Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Why am I getting an event alert "A BitLocker recovery key has been revoked from: BKLAMME-8152Y0C" in the Sophos Cental console whenever I just read the Bitlocker recovery key?

Hello Peoples,

 

Why am I getting an event alert "A BitLocker recovery key has been revoked from: BKLAMME-8152Y0C" in the Sophos Cental console whenever I just read the Bitlocker recovery key?



This thread was automatically locked due to age.
Parents Reply Children
  • Hi balaramyerra,

    Regarding Mac encryption please review this this Apple article:
    https://support.apple.com/en-in/HT204837

    Regarding Sophos Central recovery key, please see below and let us know which steps you are following, and where are you getting stuck, so that we can better assist you.
    Here's how to recover the key and change a password:
    Retrieve recovery key (Mac)

    Note that: 
    On endpoints running macOS 10.12 or earlier, a new recovery key is created and stored in Sophos Central. A recovery key can only be used once. If you need to recover a computer again later, you need to retrieve a new recoverykey.
    On endpoints running macOS 10.13 and Apple File System (APFS), no new recovery key is created. The existing recovery key remains valid.

    Thanks!

  • Hi Barb,

     

    "On endpoints running macOS 10.13 and Apple File System (APFS), no new recovery key is created. The existing recovery key remains valid."

    As per this statement, will Sophos create an event in console that its been revoked once we check recovery key from console end ?

    Regards,

    Balarama Kishore Yerra

  • Hello  

    Sophos will not create an event in the console for MAC machines as a revoke mechanism is only for the Windows Operating system which uses Bitlocker as their native encryption.