Forum Discussion
BitLocker suspended by recent hotpatch?
Your concern is valid: a device left with BitLocker protection suspended still has encrypted data, but its normal protection checks are bypassed until protection is resumed. The information provided does not prove KB5123607 caused the change. Microsoft’s guidance says ordinary Windows quality updates do not require users to suspend BitLocker, and automatically suspended protection should normally resume at the next restart. Start by inventorying affected devices: capture protection status, suspension date, reboot history, hotpatch deployment ring, recovery-key escrow state, and BitLocker and update events. Immediately resume protection on devices that remain suspended, after confirming their recovery keys are available. Then reproduce the update in a pilot ring with before-and-after status collection; do not infer causation from timing alone. Check whether an Intune policy, remediation, firmware process, or other deployment is issuing an indefinite suspension. If the pilot reproduces it, open a Microsoft support case with the logs and update identifiers.