Event details
Have a question about Windows 11, device management, security, updates, or modern endpoint operations? This hour is dedicated entirely to your questions. Bring what's top of mind—from Windows 11 adop...
Heather_Poulsen
Updated Jul 07, 2026
Dom_Cote
Jul 16, 2026Iron Contributor
It is still REALLY hard to get new Windows Devices to encrypt Bitlocker with 256bit AES from OoBE.
Normally, the Entra join happens before Intune enrollment and Bitlocker policy deployment.
That causes Windows to do the stone-age 128bit AES encryption.
Currently, we cludge that by scheduling a decryption task and then letting Intune remediate it with the intended 256AES encryption. While it works, it is not elegant.
Can we get Windows do just encrypt with 256bit AES by default please? That'll fix so much