Autopilot Reset asks for Bitlocker recovery key

Pavel yannara Mirochnitchenko 11,716 Reputation points
2022-02-07T10:19:21.923+00:00

I have very random experience with the Autopilot Reset process via Intune console, where in 50% of cases, computer is stuck with asking Bitlocker recovery key in a middle of the reset process. The fun thing is, that this happends randomly and I see this behavior in different Intune cloud-only enviroments. Any explanations or tricks for this. I want to avoid recovery key pop-up if possible.

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,248 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2022-02-08T01:47:23.54+00:00

    @Pavel yannara Mirochnitchenko , Based on my research, some specific events will cause BitLocker to enter recovery mode when attempting to start the operating system drive: Here is the link for the reference:
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-recovery-guide-plan#what-causes-bitlocker-recovery

    Also, I find it seems tracking changes in the PCRs can pin point which change is causing recovery action, Maybe we can try to see if we can find it.
    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/ts-bitlocker-decode-measured-boot-logs#:~:text=By%20tracking%20changes%20in%20the,%5CLogs%5CMeasuredBoot%5C%20folder

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Pavel yannara Mirochnitchenko 11,716 Reputation points
    2022-02-08T09:05:20.997+00:00

    Yea, I understand, that clearly Windows Reset manipulates the OS and stuff, but it still works in some cases for me. If Bitlocker would be not supported during Windows Reset, the entire Autpilot Reset is quite useless. In Intune configuration, there is no PCR level like in GPO there was.


  3. Pavel yannara Mirochnitchenko 11,716 Reputation points
    2022-02-09T06:20:40.997+00:00

    I guess there is no easy way to track down the recovery root cause from Event Viewer? Bitlocker API log does not reveal it, right?


  4. David Smith 1 Reputation point
    2024-01-11T11:58:18.8466667+00:00

    @Pavel yannara Mirochnitchenko I had this issue just recently, which mine was due to secure boot not being enabled. It threw me a curveball but the BitLocker-API mentioned secure boot integrity could not be use and I checked and it was disabled! re-enabled and Autopilot reset without the bitlocker prompt.

    0 comments No comments