Issue
A BitLocker recovery key is needed to unlock an endpoint that is no longer visible in Nebula.
Cause
When an endpoint is deleted from Nebula, its recovery keys are also removed. This applies to endpoints removed using the following methods:
- Delete action on the Manage > Endpoints page.
- Automatic removal due to inactive endpoint policy settings.
- Local uninstallation of the Endpoint Agent.
Resolution
To retrieve the recovery key for a deleted endpoint:
- Navigate to Monitor > Drive Encryption.
- Click Bulk Key Export > Existing + deleted endpoints.
- Locate the endpoint's recovery key in the exported CSV file.
Note: If the recovery key is invalid, the endpoint may have been re-encrypted after the agent was uninstalled. This means the key stored in Nebula is out of date.
Return to Drive Encryption guide.