Bitlocker policy not applying through Intune

Kaczmarek, David B 15 Reputation points
2023-02-07T21:09:46.1033333+00:00

I'm having some issues with certain devices not applying bitlocker policy through Intune. Most devices receive policy without issue and apply. Bitlocker encrypts right away and everything looks good. On a small section of computers, the policy is showing as succeeded in Intune and I can see on the computer that it's not applying. I've looked through all the obvious locations in Event Viewer:

DeviceManagement-Enterprise-Diagnostics-Provider

Bitlocker-API

These couple messages are all I can find but don't know what they refer to.

BitLocker CSP: GetDeviceEncryptionComplianceStatus indicates OSV is not compliant with returned status 0x2

CSP URI: (./Device/Vendor/MSFT/BitLocker/RequireDeviceEncryption), Result: (The device is not ready.).

These devices are no different than any other device that has received the policy without issue. They meet all pre-reqs and from the Intune side, everything looks good. No issues with TPM, WinRE is enabled. Are there any other places to look for logs to see what is happening?

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,406 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,241 Reputation points MVP
    2023-02-07T21:14:14.3633333+00:00

    What does it say in BitLocker API in event viewer? Can you share the export? Also, anything in system information?