Which License is required to manage Bitlocker through Intune, is it Windows 10 pro or enterprise

SamarMumbai 0 Reputation points
2025-03-01T16:43:58.55+00:00

License Confusion for Managing BitLocker via Intune

License Confusion for Managing BitLocker via Intune

Scenario:

We are managing BitLocker through Intune, with recovery keys backed up to Entra ID for both Hybrid and Entra ID-joined devices. Our devices run Windows 10/11 Professional, and we have EMS E3 licenses.

Confusion:

Most Microsoft documents state that Windows 10/11 Professional is sufficient to enable and manage BitLocker.

However, one document mentions that Windows 10/11 Enterprise is required to manage BitLocker using CSP (Configuration Service Provider).

We need clarification on whether Windows 10/11 Professional is fully capable of BitLocker management via Intune or if Enterprise is required for CSP-based management.

I am providing reference Microsoft articles and screenshots to support this.

BitLocker Enablement:

https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/#windows-edition-and-licensing-requirements

BitLocker Management:

https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure?tabs=common#windows-edition-and-licensing-requirements

Encrypt Devices with Intune:

Encrypt Windows devices with Intune - Microsoft Intune | Microsoft Learn

"Information for BitLocker is obtained using the BitLocker configuration service provider (CSP). BitLocker CSP is supported on Windows 10 version 1703 and later, Windows 10 Pro version 1809 and later, and Windows 11."

Contradictory Statement Document:

BitLocker CSP | Microsoft Learn

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
2,020 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 38,000 Reputation points MVP
    2025-03-01T17:22:59.76+00:00

    https://learn.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp clearly states:

    To manage BitLocker through CSP except to enable and disable it using the RequireDeviceEncryption policy, one of the following licenses must be assigned to your users regardless of your management platform:

    • Windows 10/11 Enterprise E3 or E5 (included in Microsoft 365 F3, E3, and E5).
    • Windows 10/11 Enterprise A3 or A5 (included in Microsoft 365 A3 and A5).

    I gather the confusion might result from the distinction between supportability of the Windows OS Editions and the license type assignment.

    Btw. you should always verify the licensing requirements directly with your Microsoft account manager or Microsoft sales.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.