Share via

Bitlocker policy - Endpoint Manager

Muri 1 Reputation point
2022-11-14T12:14:57.383+00:00

hello everyone,

we are starting to implement our Endpoint Manager infrastructure with Intune (policies, profiles, Rules etc) and we are still struggling with the Bitlocker feature.

We have the Bitlocker policy under the EndpointSecurity\DiskEncryption menu configured, activate and to our Group assigned.

Unfortunately, it seems that the policy had no effect on the devices except, the Bitlocker removable drive feature which, indicates that the policy is indeed being able to reach the endpoints.
Are we missing some Bitlocker requirements? How can we better troubleshooting?

Ps. Our devices are hybrid joined.

Thanks in advance
Muri

Microsoft Security | Intune | Configuration
0 comments No comments

3 answers

Sort by: Most helpful
  1. Muri 1 Reputation point
    2023-01-03T07:09:31.363+00:00

    Hello everyone,

    happy new year and sorry for the late reply.

    after the log analyse we could find out the configuration that was missing.

    Thanks everyone.
    Muri

    Was this answer helpful?


  2. Crystal-MSFT 54,311 Reputation points Microsoft External Staff
    2022-11-15T01:37:14.357+00:00

    @Muri , From your description, it seems the Bitlocker related policy is not working. If there's any misunderstanding, feel free to let us know.

    To clarify our issue, we can check the following information:

    1. Go to the policy side and check the "Device status" to see if the policy is applied successfully.
    2. Check the logs like Mobile device management (MDM) agent event log and BitLocker-API management event log to see if there's any finding.

    Meanwhile, here are some troubleshooting articles for your reference:
    https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-troubleshooting-bitlocker-policies-in-microsoft/ba-p/863670
    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-protection/troubleshoot-bitlocker-policies

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


  3. Pavel yannara Mirochnitchenko 13,456 Reputation points MVP
    2022-11-14T12:27:44.413+00:00

    Few tips:

    1. In Event Viewer, look for Windows\Bitlocker-API node. Events there will reveal you, why the automation did not kick in.
    2. In Intune Bitlocker policies, at least for testing, use "allowed" instead of "required" option in some settings.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.