使用PowerShell备份BitLocker密钥到Azure AD时遇JSON错误求助
解决BackupToAAD-BitLockerKeyProtector报「JSON value not found (0x83750009)」错误的方案
错误背景
执行BackupToAAD-BitLockerKeyProtector cmdlet将BitLocker恢复密钥备份到Azure AD时,出现以下COM错误:
BackupToAAD-BitLockerKeyProtector : JSON value not found. (Exception from HRESULT: 0x83750009) At line:1 char:1 + BackupToAAD-BitLockerKeyProtector -MountPoint $env:SystemDrive -KeyPr ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [Write-Error], COMException + FullyQualifiedErrorId : System.Runtime.InteropServices.COMException,BackupToAAD-BitLockerKeyProtector
已确认能通过Get-BitLockerVolume正常获取RecoveryPassword类型的KeyProtectorID和密钥内容。
常见原因
该错误(0x83750009)通常由以下场景导致:
- 设备未成功注册/加入Azure AD,或AAD连接状态异常
- BitLocker恢复密钥保护者未与Azure AD上下文绑定
- 执行命令的权限不足,或设备无法正常访问Azure AD服务
解决步骤
1. 验证设备的Azure AD注册状态
使用管理员权限运行以下命令,检查设备的AAD关联状态:
dsregcmd /status
重点查看AzureAdJoined或EnterpriseJoined字段,确保状态为YES,同时DeviceId有有效GUID值。如果未加入,执行以下命令重新注册:
# 退出当前AAD注册 dsregcmd /leave # 重新加入AAD dsregcmd /join
执行后需重启设备生效。
2. 确认Recovery Password保护者的有效性
即使能获取到KeyProtectorID,也需确保该保护者是可绑定到AAD的有效对象。执行以下脚本检查并创建(如果缺失):
$systemDrive = $env:SystemDrive $bitlockerVolume = Get-BitLockerVolume -MountPoint $systemDrive $recoveryKey = $bitlockerVolume.KeyProtector | Where-Object {$_.KeyProtectorType -eq "RecoveryPassword"} # 如果不存在Recovery Password保护者,新建一个 if (-not $recoveryKey) { Add-BitLockerKeyProtector -MountPoint $systemDrive -RecoveryPasswordProtector # 重新获取新建的保护者 $recoveryKey = (Get-BitLockerVolume -MountPoint $systemDrive).KeyProtector | Where-Object {$_.KeyProtectorType -eq "RecoveryPassword"} }
3. 重新执行密钥备份
以管理员权限运行PowerShell,使用明确的变量执行备份命令:
BackupToAAD-BitLockerKeyProtector -MountPoint $systemDrive -KeyProtectorId $recoveryKey.KeyProtectorId
4. 检查企业级配置限制
如果是域环境,确认:
- 组策略中未禁用「将BitLocker恢复信息备份到Azure AD」的选项
- Intune中的BitLocker策略已正确配置「备份恢复密钥到Azure AD」的规则
内容的提问来源于stack exchange,提问作者zyntrax
相关产品推荐
相关产品推荐

