Intune - Bitlocker

karthik palani 1,036 Reputation points
2021-03-27T11:33:56.8+00:00

Hi All,

I have created a device configuration policy for Bitlocker and deployed to 20 users. I can see some status are weird and unable to understand the same. Please advice

  • Out of 20 machines 15 shows succeeded, in which when i verified Succeeded machines 1 or 2 machines are not encrypted others are ok. IS there any specific reason?
  • Remaining 5 machines shows not applicable and error. For error machines, there is a pop-up in which user need admin account to proceed. For not applicable machine, nothing happen

So i assume if the machine has Secure boot enabled - Silent bitlocker encryption is happening
If not secure boot - Those machines are getting error and pop up. Any logs please
Not applicable - Not sure what is the cause? Any logs

Errors from Bitlocker event:

Error machines - "BitLocker cannot use Secure Boot for integrity because it is disabled."
Succeeded machines - "Failed to backup BitLocker Drive Encryption recovery information for volume C: to your Azure AD.
TraceId: {0f93d1b9-073c-4e45-a980-92fedb4dd627}

Error: Access is denied."

Please suggest your view

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,919 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,373 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 49,346 Reputation points Microsoft Vendor
    2021-03-29T02:22:38.32+00:00

    @karthik palani , From your description, I know we configure silently Bitlocker via Intune policy. Firstly, please ensure "Device Prerequisites" are met on these devices:. Secondly, please check the startup PIN or start key configuration to see if it is also met.
    82158-image.png
    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#silently-enable-bitlocker-on-devices

    For the error "BitLocker cannot use Secure Boot for integrity because it is disabled", it seems the secure boot is not enabled, please check on the device to ensure it is enabled.
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/ts-bitlocker-intune-issues

    For the error "Failed to backup BitLocker Drive Encryption recovery information for volume C: to your Azure AD.Error: Access is denied.", this shows the backup Recovery information to AAD is failed. Silent Encryption does not supports enforcing startup authentication other than the default TPM. If your profile has authentication method set to Require for TPM+PIN or TPM+StartupKey, causes this failure. If recovery method is not set and is not configured to backup to AAD before enabling encryption, the profile fails with the same error event. Please ensure BitLocker recovery information to Azure Active Directory is set to Enabled and the startup authentication is configured correctly.

    Research and find a link about troubleshooting Bitlocker Silent Encryption for the reference:
    https://www.anoopcnair.com/intune-bitlocker-drive-encryption-part4/
    Note: non-Microsoft link, just for the reference.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2021-05-03T20:22:50.463+00:00

    There are known Bitlocker issues related to versions older than 1909. You should upgrade to 1909 or above and then check if silent encryption is going through or not.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.