Issue
The drive was encrypted, but the recovery key was not sent to Nebula for storage.
Symptom
The Monitor > Drive Encryption page shows a Key escrow failed alert in the Issue column. Nebula does not report the drive as Encrypted until the recovery key is securely escrowed.
Cause
The ThreatDown agent successfully started BitLocker encryption but failed to deliver the recovery key to Nebula. Common causes include:
- The endpoint was offline or had no internet access at the time encryption completed.
- A network firewall or proxy is blocking outbound connections to Nebula.
Resolution
- The agent automatically attempts to escrow the recovery key the next time it connects to the internet.
- Verify the network access requirements are met. For more information, see Network access requirements and firewall settings for Nebula.
Return to Drive Encryption guide.