The Monitor > Drive Encryption page in Nebula displays the encryption status for each Windows workstation and its drives.
Encryption compliance
The Encryption Compliance widget at the top of the Drive Encryption page displays the percent of Windows endpoints that are fully encrypted. This helps quickly identify the organization's compliance with device security.
Endpoint drives list
The following details are available for each drive on this page:
| Column | Description |
|---|---|
| Drive | The drive letter on the endpoint. |
| Drive Status |
The encryption status of the specific drive.
|
| Drive type | Operating System or Fixed data drive. |
| Encrypted at | Date the drive was encrypted. |
| Encryption method |
How the drive was encrypted:
|
| Encryption scope |
The sectors encrypted:
|
| Endpoint | Endpoint name |
| Endpoint Status |
The endpoint's overall drive encryption status, derived from the state of all drives on the device.
|
| Issue | Problems encountered with the encryption on the endpoint. |
| Last Key Rotation | Last time the BitLocker key was rotated. |
| Policy | The policy applied to this endpoint. |
| Recovery Key |
BitLocker recovery key linked to the Key ID for this drive. The following actions are available in this cell:
|
Export recovery keys in bulk
Super Admins can export recovery keys from Nebula as a single CSV using the Bulk key export button, providing an offline backup of every key. This action is logged in the Activity Logs events. move this to the paragraph above. Choose from one of the following options:
- Existing endpoints only: Export the recovery keys of all current endpoints on the Drive Encryption page.
- Existing + deleted endpoints: Export the recovery keys of all current endpoints on the Drive Encryption page and previously deleted endpoints.
The exported CSV file includes one row per encrypted drive. A machine with multiple encrypted drives shows one row per drive. The report contains the following:
| Column | Description |
|---|---|
| Machine name | The name of the endpoint as shown in Nebula |
| Drive | Drive letter and type (e.g., C: OS Drive) |
| Key ID | The 8-character Key ID displayed on the BitLocker recovery screen |
| Recovery Key | The full 48-digit recovery password |
| Last rotation date | When the recovery key was most recently rotated |
Note: Treat the export as a highly sensitive credential. Anyone with access to the file and its password can decrypt any drive in your endpoints
For information on how to encrypt and unlock devices, see the following:
Return to Drive Encryption guide.