Forum Discussion
Endpoint security - Device encryption policy shows error
- Aug 13, 2021
Hi Marc,
Check if you can re-image the Windows 10 client to be sure.
Below the settings that difference from yours:
- BitLocker - Base Settings
Require storage cards to be encrypted (mobile only): Yes
Configure client-driven recovery password rotation: Azure AD-Joined devices only
BitLocker - Fixed Drive Settings
Enable BitLocker after recovery information to store: Not configured
BitLocker - OS Drive Settings
Compatible TPM startup : Allowed
Compatible TPM startup PIN: Blocked
Compatible TPM startup key: Blocked
Compatible TPM startup key and PIN: Blocked
Enable BitLocker after recovery information to store: Not configured
Block the use of certificate-based data recovery agent (DRA): Yes
BitLocker - Removable Drive Settings
Block write access to removable data-drives not protected by BitLocker: Yes
Hope this helps, and keep me posted.
Regards, Bilal
How does your assignment look like? Did you apply this policy on user- or device groups?
- marckuhnAug 12, 2021Brass ContributorHi Bilalel
i assigned it to the device group of all Windows devices. I'm not a 100% sure when to use device and when user policy.
What would you recommend?
Best regards
Marc- BilalelHaddAug 12, 2021Iron ContributorHi Marc,
When did you create the endpoint security profile? Sometimes it can take some time before the status changes. I've seen in the past that the status returned, is not always up to date. And indeed, you should apply this policy to device groups.
To give an answer to your question regarding device group assignment of user group assignment, it depends on the configuration, but choose for device group assignment if you want to apply settings on a device, regardless of who's signing in, it will always apply the configuration. Choose a user group assignment if you want to apply profile settings.
Regards, Bilal- marckuhnAug 12, 2021Brass ContributorHi Bilal
i'm working already with the device a couple of days. In the eventlog i don't see any issues for Bitlocker.
Thanks for your feedback on this. I will keep an eye on it, probably it will solve it one time.
So then probably that isn't an issue, just shows the error there.
Is it normal for the Bitlocker to have the used space encrypted only?
Or shouldn't this be the whole drive?
Many thanks and best regards
Marc