Why some devices have bitlocker keys and some don't

Xiomara Gonzalez 40 Reputation points
2023-07-26T13:08:24.2566667+00:00

Dear Team,

We have enabled Bitlocker for all of our devices in Intune. However, we don’t understand why we can see the bitlocker keys for some devices but not for others, for example the two devices shown below are both compliant, but we can see the recovery key for one but not for the other:

User's image

User's image

Do you know why this may be?

Thanks in advance!

Microsoft Security Intune Other
{count} votes

Accepted answer
  1. Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
    2023-07-26T17:05:04.3333333+00:00

    There might be knowing issue going on now, because all of sudden, disk encryption stopped working for few enviroments I know. Go to event viewer, under Windows and Apps, look for Bitlocker-API node and look for the error code you see there. If it is about not to be able to upload keys to AzureAD, it might be it. I keep you posted.

    2 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Simon Ren-MSFT 40,341 Reputation points Microsoft External Staff
    2023-07-27T09:09:31.05+00:00

    Hi,

    Thank you for posting in Microsoft Q&A forum.

    1,BitLocker recovery keys are only saved to AAD or AD at the time they are set (or reset). Thus, we can either rotate them (which can be done using Intune) or send a script to them to force them to save their keys to AAD. Just simply push a PowerShell script to the devices without recovery keys to force the escrow of the recovery keys to AAD. Refer to:

    How to force escrowing of Bitlocker recovery keys using Intune

    Get Intune devices with missing BitLocker keys in Azure AD

    2,If it doesn't work, please check the DeviceManagement-Enterprise-Diagnostic-Provider event log and Applications and Services Logs > Microsoft > Windows > BitLocker-API event log.

    For more information, please refer to:

    Using BitLocker recovery keys with Microsoft Endpoint Manager - Microsoft Intune

    Thanks for your time. Have a nice day!

    Best regards,

    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. Rudy Ooms 701 Reputation points MVP
    2023-07-31T11:49:19.5133333+00:00

    It depends... but I would wait untill Microsoft fixed a bug they are currently having

    https://call4cloud.nl/2023/07/0x80072f8f-a-bitlocker-odyssey/

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.