Intune - Enable BitLocker TPM-device not activated

Chned 46 Reputation points
2020-09-29T13:05:31.127+00:00

In Intune I created under Endpoint security, Disk encryption a Policy for enabling BitLocker:

29095-block1.png

But the ProBook 440 G7 with TPM doesn't get BitLocker enabled. I do see at the sync info that the BitLocker Policy got received though..

29184-block.png

29126-ziee.png

Intune states:

29165-status.png

Why isn't this working?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,750 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. CiciWu-MSFT 1,206 Reputation points
    2020-09-30T02:35:15.693+00:00

    Please firstly check if account must have the applicable Intune role-based access control (RBAC) permissions.

    Also, it's possible that the underlying device hardware doesn't meet the requirements for BitLocker encryption. You can find the system requirements for BitLocker in the Windows documentation, but the main things to check are that the device has a compatible TPM chip (1.2 or later) and a Trusted Computing Group (TCG)-compliant BIOS or UEFI firmware.

    Reference: https://learn.microsoft.com/en-us/mem/intune/protect/troubleshoot-bitlocker-policies#troubleshooting-bitlocker-policy


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Chned 46 Reputation points
    2020-10-01T15:08:32.237+00:00

    What account and role are you aiming for?

    The hardware does have TPM, that's why I posted the screenshot which shows that it is TPM 2.0

    0 comments No comments

  3. Jörgen Nilsson 186 Reputation points
    2020-10-02T13:28:33.773+00:00

    Hi,
    Have you configured the other two settings that is mentioned here? they are required for silently activating BitLocker.

    • Warning for other disk encryption = Block.
    • Allow standard users to enable encryption during Azure AD Join = Allow

    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#silently-enable-bitlocker-on-devices

    That should do it
    Regards,
    Jörgen

    0 comments No comments