Disable User's Ability to Export Bitlocker Keys

BlakeV 5 Reputation points
2023-03-14T01:34:04.31+00:00

We have Win10/11 devices managed via Intune. The Bitlocker key is stored in Intune. Is there a way for us to prevent our user's from going into their laptop control panel and exporting their Bitlocker key? We don't want our users to pull the SSD from their work laptop and move it to a personal device.

Windows for business Windows Client for IT Pros User experience Other
Microsoft Security Intune Other
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Dillon Silzer 57,826 Reputation points Volunteer Moderator
    2023-03-14T03:12:58.63+00:00

    Hello Blake,

    You can try hiding Bitlocker Management from Control Panel via GPO:

    Navigate to User Configuration > Policies > Administrative Templates > Control Panel and edit the “Hide specified Control Panel items” policy. After you enable the policy, you have to change the “List of disallowed Control Panel items” and add “BitLocker Drive Encryption.”

    User's image

    Cited from https://4sysops.com/archives/how-to-disable-bitlocker/


    If this is helpful please accept answer.

    0 comments No comments

  2. Crystal-MSFT 53,981 Reputation points Microsoft External Staff
    2023-03-15T01:12:17.21+00:00

    @BlakeV, Thanks for posting in Q&A.

    For the group policy Dillon mentioned, you can configure the similar one under Settings Catalog policy in Intune. Here are the detailed steps for your reference:

    1. Go to Devices->Configuration profiles, create profile.
    2. Platform: Windows 10 and later. Profile Type: Settings Catalog.
    3. Select the "Hide specific Control Panel items (User) under administrative Templates\Control Panel and set "Bitlocker Drive Encrption".

    User's image

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.