Share via

Bitlocker key rotation

labadmin 0 Reputation points
2024-12-17T02:04:00.1666667+00:00

Hello All, we are a hybrid joined environment that is moving into using intune. Currently gpo policy controls bitlocker and keys write to ad ds but keys are visible in intune. Is it possible to rotate bitlocker keys via Intune with this setup or do we have to move to bitlocker being managed by intune configuration policy.

Microsoft Security | Intune | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-12-17T06:08:20.29+00:00

    @labadmin Thanks for posting in our Q&A.

    For this issue, did you want to save BitLocker keys to Entra ID? If yes, rotating BitLocker keys (which can be done using Intune) or send a script to them to force them to save their keys to Entra ID. I generally prefer using the script. You can push out a simple PowerShell script to do this. You can find many examples of a script that does it, but they all end up calling a single PowerShell cmdlet: https://learn.microsoft.com/en-us/powershell/module/bitlocker/backuptoaad-bitlockerkeyprotector?view=windowsserver2022-ps

    If you really want do BitLocker key rotation via intune, it is suggested to move to BitLocker being managed by intune configuration policy.

    If there is anything misunderstanding, please correct me.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.