Forum Discussion
Bitlocker encryption
Hi, 
We have enabled Bitlocker using Intune and used AES 256bit XTS. But when we run manage-bde -status it says the encryption method is XTS-AES 128. 
Any suggestions on this?
Is it a potential Bug or Am i missing something on my end?
Thanks
- Ok, but if you want the intune clients to also have 256Bit... Then you will have to decrypt them and encrypt them again to fix that
 
18 Replies
- slykuehCopper Contributor
I tried to encrypt my WD external HD with backup files and it took more than 20 hours to go to 98.2% and stuck there. I tried to pause it and it did not respond. I used Powershell to Pause and Resume also did not work. I clicked the Manage Bitlocker only to get File Explorer not responding. And Bitlocker Drive Encryption (not responding).
I could not end (bitlocker) task and and it did not want to shutdown as it was stuck on file explorer. Only way is to turn the PC power off. Look like the bitlocker software is making my external HD inaccessible.
How can I undo the encryption?
 - shockotechcomIron ContributorNeed more detail. Do these devices support automatic encryption?
- Kashish_GoyalCopper ContributorCertainly, the devices support automatic encryption.
 
 - Any update?
- Kashish_GoyalCopper ContributorHi Harm, Sorry for the delayed response. We encrypted the devices straight with AES 256bit XTS and never used 128 XTS.
This was done using Endpoint Manager.
Devices managed by Intune says 128Bit.
Devices not managed by Intune says 256bit.- Ok, but if you want the intune clients to also have 256Bit... Then you will have to decrypt them and encrypt them again to fix that
 
 
 Kashish_Goyal this device was encrypted before with BitLocker prior applying the new settings?
- You have to decrypt before you can switch to a higher encryption method.