Menu
CCMEXEC.COM – Enterprise Mobility
  • Home
  • General
  • Configuration Manager
  • Windows 10
  • Intune
  • GitHub
  • Windows 11
  • About the author
CCMEXEC.COM – Enterprise Mobility

BitLocker Administration Service in MEMCM

Posted on December 16, 2020December 16, 2020 by Johan

Starting in ConfigMgr Current branch 1910 integrated BitLocker management (MBAM) is supported. This is all well and fine except one detail; it does not include the Administration Service Endpoint available in MBAM standalone. This endpoint is, most cases, crucial if you are using any kind of automation, management system, custom helpdesk tool or such.

This article describes a simple hack, that is in no way endorsed or supported by Microsoft and consequently implemented at own risk, to get the service endpoint back. The method should be considered temporary, to bridge the gap until Microsoft eventually decides to include the functionality (we still hope for that).

If you are configuring integrated BitLocker management and have not used the admin service in a previous MBAM standalone installation, this information is probably of little, if any, value to you.

This table indicates what is missing in the integrated implementation.

As we can see the integrated solution lacks the “Administration Service”, some of us needs it and it is safe to say this loss is a significant drawback. However unsupported there is a way to get it back by manually copy it from an existing standalone installation. If you have not used MBAM standalone in the past, you will need to set up the solution first to get your hands on the necessary files.

Step #1: Copy the folder

Copy the “Administration Service” folder from “c:\inetpub\Microsoft BitLocker Management Solution” on the old standalone MBAM server to the same location on the server running the >> Portals << (Helpdesk and/or SelfService). Ensure the source installation is the latest, fully patched, version.

We also need to create this log folder for the new Application.

Step #2: Add the Application to IIS

Open IIS Manager and right click the site running your portals (typically Default Web Site). Click >> Add Application <<.

Fill in the necessary information for the new application.

Alias: MBAMAdministrationService

Application pool: MBAMWebSitePool

Physical path: C:\inetpub\Microsoft BitLocker Management Solution\Administration Service

Press “OK” when Done!

Make sure to enable Windows Authentication on the new Application:

Step #3: Correct web.config

Depending on if you are reusing the old security groups from the standalone installation or not you will have to edit the web.config file in the folder you just copied.

Locate the >> appSettings << section and make sure the two group names reflect your configuration:

Finally correct these two values to avoid running into SPN issues:

Replace <SERVER.DOMAIN.COM> with the FQDN of the server running the service.

Endpoint:

The admin service will now be available at:

https://<SERVER.DOMAIN.COM>/MBAMAdministrationService/AdministrationService.svc

Done!

  • ConfigMgr
  • MBAM Integrated SCCM
  • MEMCM
  • 1 thought on “BitLocker Administration Service in MEMCM”

    1. Pingback: Microsoft Cloud ve Datacenter Management Ocak 2021 Bülten – Sertaç Topal

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    My name is Jörgen Nilsson and I work as a Senior Consultant at Onevinn in Malmö, Sweden. This is my blog where I will share tips and stuff for my own and everyone elses use on Enterprise Mobility and Windows related topics.
    All code is provided "AS-IS" with no warranties.

    Tweets by ccmexec

    Recent Posts

    • Windows Servicing, Personal Teams and Success.cmd
    • Windows MDM Security Baseline – Settings Catalog
    • Configuring MS Edge Security Baseline v107 using Settings Catalog
    • Configuring Desktop App Installer using CSP and script?!
    • Customizing Taskbar and Start in Windows 11 22h2 with PowerShell

    ©2023 CCMEXEC.COM – Enterprise Mobility | WordPress Theme by Superb Themes
    This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish.Accept Reject Read More
    Privacy & Cookies Policy

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
    Non-necessary
    Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
    SAVE & ACCEPT