Intune Bitlocker Policy assignment status error

Redistro 211 Reputation points
2023-05-06T22:55:38.97+00:00

History: We have a couple of workstations that auto encrypt with AES-128. I pushed a script to decrypt the device and then pushed bitlocker policy to encrypt the device with AES-256.

Everything was good at first but now assignment status on the devices report error. I checked the status of bitlocker on the workstations and they are fully encrypted and turned on. On checking the event viewer here is what I see

User's image

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

Accepted answer
  1. Crystal-MSFT 53,986 Reputation points Microsoft External Staff
    2023-05-08T03:06:20.7933333+00:00

    @Redistro, Thanks for posting in Q&A. For the error message, it seems the error is with the CSP "SystemDrivesRequireStartupAuthentication". For this policy setting, it allows you to configure whether BitLocker requires additional authentication each time the computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM).

    https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#systemdrivesrequirestartupauthentication

    It seems we have configured "additional authentication at startup" as required. If we configure to silently enable BitLocker on the device, please ensure a TPM startup PIN or startup key is not set as required on a device. And also ensure the setting meets our situation.

    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#tpm-startup-pin-or-key

    Please check the above information and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.