BitLocker Encryption

IntuneUser 181 Reputation points
2022-07-07T06:30:34.5+00:00

I have deployed a BitLocker policy from Intune to the device.
The device gets successfully encrypted.
However, I can manually turn off bitlocker and de-crypt the device. Post that, Intune does not re-encrypt my device again.
Is there any way from Intune to prevent users from manually turning off BitLocker on their devices ?

Windows for business Windows Client for IT Pros Devices and deployment Configure application groups
Microsoft Security Intune Configuration
Microsoft Security Intune Other
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 39,916 Reputation points
    2022-07-11T12:55:14.277+00:00

    Hi there,

    You can achieve this by BitLocker group policy settings. This policy setting is used to prevent users from turning BitLocker on or off on removable data drives.BitLocker Group Policy settings can be accessed using the Local Group Policy Editor and the Group Policy Management Console (GPMC) under Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption.

    Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives

    You can select property settings that control how users can configure BitLocker.

    BitLocker group policy settings

    https://learn.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-group-policy-settings#bkmk-driveaccess3

    I hope this information helps. If you have any questions please let me know and I will be glad to help you out.

    --------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer--


1 additional answer

Sort by: Most helpful
  1. MTG 1,246 Reputation points
    2022-07-07T08:25:36.167+00:00

    Standard users cannot decrypt. Only admins can decrypt, which makes me wonder if your users are admins.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.