Event details
Why is there no support for Bitlocker Pin in Intune, when it's recommended to have one to prevent most hacks regarding Bitlocker?
Most resort to creating custom scripts to enable it and it would be great to have it in Intune and/or to understand to reasons why it's not there (maybe a technical limitation)
thks
Hi lalanc01. There is no official recommendation on whether orgs should use or not use a preboot authenticator (PBA) -- aka PIN -- for BitLocker. This is a complicated and touchy subject as there are pros and cons both ways and the choice should be based on your org's security posture and should not necessarily be a blanket choice for all devices either. There's also a lot of FUD out there on what and how BitLocker can be compromised and the ease of doing so which is another reason that your org should assess the risks (based on factual information) and make an informed choice based on this.
Moving on to your question, similar to many people's social media status, the short answer is "it's complicated". The basic challenge is that there isn't an adequate control in Windows itself to accommodate setting a PIN by a non-admin user when no PIN currently exists. There are workarounds for this including using a script/tool that is run elevated (this is what MBAM did) and there are solutions available in/from the community that do just this.
The good news is that there has been a possible strategy update around this. Nothing to share at this time other than we know this is a challenge and this is currently being revisited with the outcome hopefully being a direct control to allow for this. No guarantees or commitments though.