Bitlocker with MDM policy does not works

Alejandro Hernández Gil 101 Reputation points
2022-03-24T15:03:05.213+00:00

Hi, I have configured a policy in endpoint.microsoft.com to enable bitlocker.

I have 2 computer to test. A computer works but other i have this events and i cant find information for this

The events are:

Event ID: 2900
CSP de BitLocker: GetDeviceEncryptionComplianceStatus indica OSV no es compatible con el estado devuelto 0x2

Event ID: 404
Administrador de configuración de MDM: estado de error de comando. Id. del origen de configuración: (5EAD92DD-FFC4-44B7-B84B-480AC6373FC9), nombre de inscripción: (MDMDeviceWithAAD), nombre de proveedor: (BitLocker), tipo de comando: (SetValue: from Replace), URI de CSP: (./Device/Vendor/MSFT/BitLocker/RequireDeviceEncryption), resultado: (El dispositivo no está listo.).

Any idea? Second computer is break o hardware failure?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,797 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,546 questions
{count} votes

Accepted answer
  1. Crystal-MSFT 44,831 Reputation points Microsoft Vendor
    2022-03-25T01:46:26.537+00:00

    @Alejandro Hernández Gil . Thanks for posting in Q&A.

    For the event 2900, it indicates a warning when the MDM client tries to assess the compliance state of the PC. In our situation, Bitlocker CSP is checking the compliance status on a Cloud PC, and obliviously the device is not BitLocker enabled.

    For event 404, it shows the device is not ready. This CSP is not supported on Home edition. Please ensure the windows 10 is supported.
    https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp

    After that, we can check the "device status" of the policy which enable Bitlocker to see if it is applied successfully. If yes, try to restart the device to see if it works.

    Meanwhile, here is a link with the troubleshooting steps. You can also read it as a reference:
    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/troubleshoot-bitlocker-policies

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

3 additional answers

Sort by: Most helpful
  1. christophe ghesquiere 1 Reputation point
    2022-03-24T21:15:40.753+00:00

    Hello,
    What is the windows 10 version?
    Do you login as administrator or not ?
    Do you have TPM?

    Check prerequisites:
    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#device-prerequisites

    Thanks
    Chris

    0 comments No comments

  2. Alejandro Hernández Gil 101 Reputation points
    2022-03-24T21:18:31.79+00:00

    Hi Cristopher,
    Windows 10 21H2, yes my user is administrator, yes TPM is 2.0 and is enabled.

    If i run tpm.msc the device is ready to use.

    0 comments No comments

  3. Pavel yannara Mirochnitchenko 12,371 Reputation points MVP
    2022-04-01T09:49:21.223+00:00

    Did you enable bitlocker from Endpoint Security / Disk Encryption node? You should use it always.

    0 comments No comments