BitLocker Encryption

IntuneUser 171 Reputation points
2022-07-07T06:30:34.5+00:00

I have deployed a BitLocker policy from Intune to the device.
The device gets successfully encrypted.
However, I can manually turn off bitlocker and de-crypt the device. Post that, Intune does not re-encrypt my device again.
Is there any way from Intune to prevent users from manually turning off BitLocker on their devices ?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,754 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,720 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 39,356 Reputation points
    2022-07-11T12:55:14.277+00:00

    Hi there,

    You can achieve this by BitLocker group policy settings. This policy setting is used to prevent users from turning BitLocker on or off on removable data drives.BitLocker Group Policy settings can be accessed using the Local Group Policy Editor and the Group Policy Management Console (GPMC) under Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption.

    Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives

    You can select property settings that control how users can configure BitLocker.

    BitLocker group policy settings

    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-driveaccess3

    I hope this information helps. If you have any questions please let me know and I will be glad to help you out.

    --------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--


1 additional answer

Sort by: Most helpful
  1. MTG 1,196 Reputation points
    2022-07-07T08:25:36.167+00:00

    Standard users cannot decrypt. Only admins can decrypt, which makes me wonder if your users are admins.