Client event logs
Applies to: Configuration Manager (current branch)
On a Configuration Manager client to which you deploy a BitLocker management policy, use the Windows Event Viewer to view BitLocker client event logs. Go to Applications and Services Logs, Microsoft, Windows, MBAM for both Admin and Operational event logs.
An error occurred while applying MBAM policies.
Details: BitLocker Drive Encryption only supports Used Space Only encryption on thin provisioned storage.
This error occurs if you try to use BitLocker to encrypt a virtual machine that's running Windows 10 version 1803 or earlier. Earlier versions of Windows 10 don't support full disk encryption. BitLocker management policies enforce full disk encryption.
Details: The data area passed to a system call is too small.
To resolve this issue, restart the computer.
An error occurred while sending encryption status data.
The system volume is missing. SystemVolume is needed to encrypt the operating system drive.
The TPM hardware is missing. TPM is needed to encrypt the operating system drive with any TPM protector.
The computer is exempted from Encryption. Machine's hardware status: Exempted
The computer is exempted from encryption. Machine's hardware status: Unknown
Hardware exemption check failed.
The user is exempt from encryption.
The user requested an exemption.
User exemption check failed.
The user postponed the encryption process.
TPM initialization failed. The user rejected the BIOS changes.
Unable to connect to the MBAM Recovery and Hardware service.
Details: The parameter is incorrect.
This error occurs if the website isn't HTTPS, or the client doesn't have a PKI cert.
The BitLocker management policy is in conflict or corrupt.
Detected OS volume encryption policies conflict. Check BitLocker policies related to OS drive protectors.
Detected fixed data drive volume encryption policies conflict. Check BitLocker policies related to fixed data drive protectors.
An error occurred while encrypting. A data recovery agent (DRA) protector is required in FIPS mode for pre-Windows 8.1 machines.
Failed to reset TPM lockout.
Failed to retrieve TPM OwnerAuth from MBAM services.
Failed to update the DLL search path for WMI provider.
Agent stopping. Timed-out waiting for MBAM WMI provider instance.
The BitLocker management policies were applied successfully.
The encryption status data was sent successfully.
Successfully connected to the MBAM Recovery and Hardware service.
The TPM OwnerAuth is escrowed.
The BitLocker recovery key for the volume is escrowed.
The BitLocker recovery key for the volume is updated.
The enforce policy date...is set for the volume
The enforce policy date...has been cleared for the volume.
Successfully reset TPM lockout.
Successfully retrieved TPM OwnerAuth from MBAM services.
Removable drive was mounted.
Removable drive was unmounted.
Failure to connect to the MBAM Recovery and Hardware service prevented BitLocker management policies from being applied successfully to the volume.
Locked volume state prevented BitLocker management policies from being applied successfully to the volume.
Failure to connect to the MBAM Compliance and Status service prevented the transfer of encryption status data.
For more information on using these logs, see BitLocker event logs.
For more troubleshooting information, see Troubleshoot BitLocker.