Windows 10: Bitlocker protection and Domain unenrollment Windows Issue

Discus and support Bitlocker protection and Domain unenrollment Windows Issue in Windows 10 Software and Apps to solve the problem; My client has left the company few years ago but has the laptop for personal use, his laptop was domain registered. I unenrolled his computer from... Discussion in 'Windows 10 Software and Apps' started by Saimon Karki, May 18, 2024.

  1. Bitlocker protection and Domain unenrollment Windows Issue


    My client has left the company few years ago but has the laptop for personal use, his laptop was domain registered. I unenrolled his computer from domain and once restarted I saw some unknown user account with password. There is no option to choose accounts on login page. Can't use utilman.exe trick due to bitlocker I can't access C drive. Any help will be appreciated. Client doesn't want to reset the PC cause he have many important files.

    :)
     
    Saimon Karki, May 18, 2024
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, May 18, 2024
    #2
  3. Paola Gar Win User
    Need to turn off Bitlocker to install Windows 10

    Hi,

    We suggest doing the following steps again to resolve the issue. To complete the procedure, make sure that you have the following information:

    • You must be able to provide administrative credentials.
    • The drive must be BitLocker-protected.
    To suspend BitLocker Drive Encryption on an operating system drive, please follow the steps below:

    • Click Start, click Control Panel, click
      System and Security, and then click BitLocker Drive Encryption.
    • Click Suspend Protection for the operating system drive.
    • A message is displayed, informing you that your data will not be protected while BitLocker is suspended and asking if you want to suspend BitLocker Drive Encryption.
    • Click Yes to continue and suspend BitLocker on the drive.

    Let us know how it goes.
     
    Paola Gar, May 18, 2024
    #3
  4. Arun B J Win User

    Bitlocker protection and Domain unenrollment Windows Issue

    BitLocker permanent loop

    Hi Laura,



    Thank you for posting your query in Microsoft Community.



    I understand your concern and will assist you to resolve this issue.


    • Did you make any changes prior to this issue?

    • Are you connected to Domain?

    • Are you using Windows 10 pro?


    I suggest you to follow the steps given in the article below and check if it helps.

    BitLocker Troubleshooting: Continuous reboot loop with BitLocker recovery on a slate device



    Hope this helps. If the issue remains unresolved, please get back to us and we would be happy to help.
     
    Arun B J, May 18, 2024
    #4
Thema:

Bitlocker protection and Domain unenrollment Windows Issue

Loading...
  1. Bitlocker protection and Domain unenrollment Windows Issue - Similar Threads - Bitlocker protection Domain

  2. Bitlocker recovery key in domain

    in Windows 10 Gaming
    Bitlocker recovery key in domain: HelloI have not the key of bitlockerRecovery Key ID : 409CC098-4E0D-498FBBDC6370F475198BDrive Label DEESKTOP-7VF35RVThe device name is Laptop1515 b https://answers.microsoft.com/en-us/windows/forum/all/bitlocker-recovery-key-in-domain/0bfb1429-6959-4be9-b609-70b0da741185
  3. Bitlocker recovery key in domain

    in Windows 10 Software and Apps
    Bitlocker recovery key in domain: HelloI have not the key of bitlockerRecovery Key ID : 409CC098-4E0D-498FBBDC6370F475198BDrive Label DEESKTOP-7VF35RVThe device name is Laptop1515 b https://answers.microsoft.com/en-us/windows/forum/all/bitlocker-recovery-key-in-domain/0bfb1429-6959-4be9-b609-70b0da741185
  4. Bitlocker protection and Domain unenrollment Windows Issue

    in Windows 10 Gaming
    Bitlocker protection and Domain unenrollment Windows Issue: My client has left the company few years ago but has the laptop for personal use, his laptop was domain registered. I unenrolled his computer from domain and once restarted I saw some unknown user account with password. There is no option to choose accounts on login page....
  5. Bitlocker protection and Domain unenrollment Windows Issue

    in Windows 10 Installation and Upgrade
    Bitlocker protection and Domain unenrollment Windows Issue: My client has left the company few years ago but has the laptop for personal use, his laptop was domain registered. I unenrolled his computer from domain and once restarted I saw some unknown user account with password. There is no option to choose accounts on login page....
  6. Bitlocker protection key

    in Windows 10 Software and Apps
    Bitlocker protection key: Hello, I had to face a problem with my account. Yesterday evening my motherboard of the syatem was placed, My laptop was asking for the BitLocker recovery codes and I was not able to access my device Which is a windows 11 laptop. I didn't know that updates cause such errors....
  7. it wont let me unenroll

    in Windows 10 Gaming
    it wont let me unenroll: i went in to the insider program and i want to leave but the option is greyed and I don't want to do a clean install I'm in beta and want to get out of insider https://answers.microsoft.com/en-us/windows/forum/all/it-wont-let-me-unenroll/9a98142b-1c0f-49e7-9280-2c1833225e10
  8. bitlocker data protection

    in Windows 10 Gaming
    bitlocker data protection: I encountered the bitlocker data protection message when I was trying to recover documents from my hard drive on my laptop. The Lenovo laptop kept over heating and the mother board failed. I removed the ssd drive from the laptop and using an enclosure to access the drive. I...
  9. bitlocker data protection

    in AntiVirus, Firewalls and System Security
    bitlocker data protection: I encountered the bitlocker data protection message when I was trying to recover documents from my hard drive on my laptop. The Lenovo laptop kept over heating and the mother board failed. I removed the ssd drive from the laptop and using an enclosure to access the drive. I...
  10. Enabling Bitlocker on an Entire Domain

    in Windows 10 Customization
    Enabling Bitlocker on an Entire Domain: My team and I, are currently looking into enabling Bitlocker on 500+ computers. Doing this manually would be a grievous task as we are international. All of our desired computers are under a domain and are able to be controlled by group policy. Though, Bitlocker GPO does not...