You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

运行PowerShell脚本启用BitLocker时遇格式错误求助

解决BitLocker启用时RecoveryPassword参数格式错误问题

问题背景

我编写了一份在Windows设备上启用BitLocker的PowerShell脚本,根据微软文档说明,搭配-RecoveryPasswordProtector参数使用时,-RecoveryPassword参数应自动生成随机值,但该功能未生效。且受现有组策略限制,必须使用-RecoveryPasswordProtector参数,无法选用其他选项。

原脚本

# Define the length of the random string
$length = 48

# Define the character set
$characters = '1234567890'

# Create a random string
$randomString = -join ((1..$length) | ForEach-Object { Get-Random -Maximum $characters.length | ForEach-Object { $characters[$_] } })

# Output the random string
Write-Host "Random String: $randomString"

#Convert to a SecureString variable
$SecureString = ConvertTo-SecureString $randomString -AsPlainText -Force

# Output the random string
Write-Host "Secure String: $SecureString"

# Specify the drive letter
$drive = "C:"

# Turn on BitLocker for the drive
Enable-BitLocker -MountPoint $drive -RecoveryPasswordProtector -RecoveryPassword $SecureString -EncryptionMethod XtsAes128 -UsedSpaceOnly -SkipHardwareTest

微软文档相关说明

-RecoveryPassword
指定恢复密码。如果指定了RecoveryPasswordProtector参数但未指定此参数,cmdlet会创建随机密码。你可以输入48位数字密码,指定或生成的密码将作为卷加密密钥的保护程序。

运行错误信息

PS C:\Temp> & '.\Enable Bitlocker.ps1'
Random String: 965827285728398492106062495600759349012636829500
Secure String: System.Security.SecureString
Add-RecoveryPasswordProtectorInternal : The format of the recovery password provided is invalid. BitLocker recovery
passwords are 48 digits. Verify that the recovery password is in the correct format and then try again. (Exception
from HRESULT: 0x80310035)
At C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psm1:3675 char:36
+ ...  $nResult = Add-RecoveryPasswordProtectorInternal $MountPoint[$i] $Re ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Write-Error], COMException
    + FullyQualifiedErrorId : System.Runtime.InteropServices.COMException,Add-RecoveryPasswordProtectorInternal

Enable-BitLockerInternal : Group Policy settings require that a recovery password be specified before encrypting the
drive. (Exception from HRESULT: 0x8031002C)
At C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psm1:3738 char:48
+ ... eInternal = Enable-BitLockerInternal -MountPoint $BitLockerVolumeInte ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Write-Error], COMException
    + FullyQualifiedErrorId : System.Runtime.InteropServices.COMException,Enable-BitLockerInternal

已尝试的解决方式

  • 生成48位数字字符串后转换为SecureString变量传入
  • 跳过随机字符串生成,直接将固定48位数字字符串转换为SecureString
  • 跳过转换为SecureString步骤,直接使用随机字符串
  • 直接将48位数字字符串作为-RecoveryPassword的参数值
  • 参照微软文档示例,在-RecoveryPassword参数外添加方括号

最终解决方案

问题核心在于BitLocker恢复密码要求是带连字符分隔的格式:8组6位数字,用-连接(例如123456-789012-345678-901234-567890-123456-789012-345678),而非连续的48位数字串。同时,自动生成功能失效是因为组策略强制要求手动指定符合格式的恢复密码。

修改后的脚本如下:

# 生成符合BitLocker格式的48位恢复密码:8组6位数字,用连字符分隔
$recoveryPasswordSegments = 1..8 | ForEach-Object {
    -join (1..6 | ForEach-Object { Get-Random -Minimum 0 -Maximum 10 })
}
$recoveryPassword = $recoveryPasswordSegments -join '-'

# 将密码转换为SecureString类型
$secureRecoveryPassword = ConvertTo-SecureString $recoveryPassword -AsPlainText -Force

# 指定要加密的盘符
$drive = "C:"

# 启用BitLocker
Enable-BitLocker -MountPoint $drive -RecoveryPasswordProtector -RecoveryPassword $secureRecoveryPassword -EncryptionMethod XtsAes128 -UsedSpaceOnly -SkipHardwareTest

# 输出并保存恢复密码(务必妥善存档,丢失后无法解密磁盘)
Write-Host "生成的BitLocker恢复密码:$recoveryPassword"

说明

  1. 按BitLocker官方要求生成带分隔符的密码格式,解决参数格式错误问题
  2. 转换为SecureString类型满足Enable-BitLocker cmdlet的参数类型要求
  3. 最后输出密码用于存档,避免丢失导致数据无法恢复

内容的提问来源于stack exchange,提问作者Andrew Hughes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 15:58:16