Bitlocker encryption through Intune management

Van M 0 Reputation points
2024-04-22T09:20:43.6533333+00:00

Hello, i have problem of domain joined devices in encypting them through bitlocker, i have a security baseline configuration on intune that applies to the devices, the configuration shows that all are successful meanwhile the bitlocker on the drive is not enabling , looks like its not forcing the devices to start encypting even though i have done multiple syncs, to mention that we have had this security baseline implemented on devices for along time.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,768 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 44,851 Reputation points Microsoft Vendor
    2024-04-23T01:46:22.2966667+00:00

    @Van M, Thanks for posting in Q&A. From your description, I know the policy has deployed to devices successfully. And we get error when enable on the device side. The error message is "The following DMA (Direct Memory Access) capable devices are not declared as protected from external access, which can block security features such as BitLocker automatic device encryption:".

    For this error, based on my researching, it seems windows has detected an attached Direct memory access (DMA)-capable device that might expose a DMA threat. Please verify that the device has no external DMA ports with the original equipment manufacturer (OEM). And add the device to the allowed list to see if it works.

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-protection/troubleshoot-bitlocker-policies#error-un-allowed-dma-capable-bus

    https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-bitlocker#un-allowed-dma-capable-busdevices-detected

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.