What action need to perform to fix " require bit locker" issue for non compliance devices in Intune

Ritesh Sharma 266 Reputation points
2023-01-21T16:14:34.1066667+00:00

Hi Team, I have many devices. Which are showing non compliance under Require Bitlocker. Please help to advise. What action is require from device or from Intune to get it fixed?

Also what is the difference between require bitlocker and require encryption of data storage?

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
143 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,624 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Paolo Miotti 5 Reputation points
    2023-01-22T15:05:48.8366667+00:00

    Hi Ritesh,

    you need in first create a Disk encryption policy, where you set and enable the disk encryption:

    User's image

    The difference between require bitlocker and require encryption of data storage, take a look to this article:

    [https://learn.microsoft.com/en-us/mem/intune/protect/compliance-policy-create-windows

    "The Encryption of data storage on a device setting generically checks for the presence of encryption on the device. For a more robust encryption setting, consider using Require BitLocker, which leverages Windows Device Health Attestation to validate Bitlocker status at the TPM level."

    Have a nice week end.

    1 person found this answer helpful.

  2. Crystal-MSFT 45,331 Reputation points Microsoft Vendor
    2023-01-23T02:25:31.0433333+00:00

    @Ritesh Sharma, Thanks for posting in Q&A.

    For the "Require Bitlocker" setting in compliance policy, it measures at boot time to see if Bitlocker encryption is completed. So, to make it compliant, we need to have BitLocker Drive Encryption enabled. Here is a link with more details:

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-protection/bitlocker-encrypted-device-not-compliant

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.