Bitlocker Intune assignment not silent

David Dawson 100 86 Reputation points
2024-11-11T19:46:57.75+00:00

We're in a pilot to set up Bitlocker on all of our Entra-joined Windows 10 and 11 clients. We'd like the deployment to occur silently. One of the Windows 11 22H2 that is getting the policy shows the end user a toast notification saying "Encryption needed. Your work or school requires this device to be encrypted. Select this notification to encrypt this device."

I've followed the article "Manage Disk Encryption policy for Windows devices with Intune" and see that my device is meeting requirements. The Intune device configuration settings are set for:

Encrypt device: Require
Warning for other disk encryption: Block
Allow standard users to enable encryption during Microsoft Entra join: Allow
User creation of recovery password: Allow 48-digit recovery password
User creation of recovery key: Allow 256-bit recovery key

The device is Entra-joined, has a TPM 2.0, and is booting via UEFI. I see in Settings that it is getting the Bitlocker policy. In Intune it says that the policy was successful. Everything looks good but the device keeps informing the end user that they need to do something to encrypt the disk. I'd like to enforce, not give the end-user an option, the Bitlocker encryption. What do I do next?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,932 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Xenia-MSFT 2,825 Reputation points Microsoft Vendor
    2024-11-12T02:17:28.29+00:00

    @David Dawson 100 Thanks for posting in our Q&A.

    For this issue, we appreciate your help to collect some information:

    1.Based on my research, I find someone said configuring any of the other compatible TPM settings as required will cause silent encryption to fail! so make sure you configure those Compatible TPM Startup PIN and Key Settings to blocked.

    User's image

    For more details, please refer to the following link:

    https://call4cloud.nl/bitlocker-remediations-recovery-escrow/#part1

    Note: Non-Microsoft link, just for the reference.

    2.Please check if you configure a TPM startup PIN or startup key on a device, BitLocker can't silently enable on the device, and instead requires interaction from the end user.

    Meanwhile, some versions of the security baseline for Microsoft Defender for Endpoint will configure both Compatible TPM startup PIN and Compatible TPM startup key by default. These configurations might block silent enablement of BitLocker. Please check if you deployed such security baseline policy.

    https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices#tpm-startup-pin-or-key

    If there is anything update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. David Dawson 100 86 Reputation points
    2024-11-12T18:50:18.6933333+00:00

    Thanks, Xenia. That's what we already have. We're using device configuration instead of doing it through Endpoint Security but I think that should provide the same outcome. I haven't made any changes and here's a screenshot.

    Bitlocker settings


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.