BitLlocker Keys in Azure AD for Existing and New W10 Devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1220777%22%20slang%3D%22en-US%22%3EBitLlocker%20Keys%20in%20Azure%20AD%20for%20Existing%20and%20New%20W10%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1220777%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20decent%2C%20step%20by%20step%20guides%20for%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEnabling%20BitLlocker%20and%20storing%20keys%20in%20Azure%20AD%20for%20Existing%20(No%20Wipe)%20and%20New%20(AutoPilot)%20W10%20Devices%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInfo%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1220777%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1223489%22%20slang%3D%22en-US%22%3ERe%3A%20BitLlocker%20Keys%20in%20Azure%20AD%20for%20Existing%20and%20New%20W10%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1223489%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20is%20a%20guide%20here%20%3CA%20href%3D%22http%3A%2F%2Fwww.rebeladmin.com%2F2019%2F09%2Fstep-step-guide-enable-bitlocker-cloud-managed-windows-10-devices-using-microsoft-intune%2F%26nbsp%3BBy%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.rebeladmin.com%2F2019%2F09%2Fstep-step-guide-enable-bitlocker-cloud-managed-windows-10-devices-using-microsoft-intune%2F%26nbsp%3BBy%3C%2FA%3E%20default%20it%20should%20store%20the%20key%20in%20Azure%20AD.%20On%20a%20test%20device%2C%20you%20can%20check%20out%20the%20Event%20Logs%20(%3C%2FP%3E%0A%3CP%3EApplication%20and%20Services%20Logs%20%26gt%3B%20Microsoft%20%26gt%3B%20Windows%20%26gt%3B%20BitLocker%20-API%20%26gt%3B%20Management)%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eand%20it%20should%20say%20its%20storing%20the%20key%20in%20Azure%20AD.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1223499%22%20slang%3D%22en-US%22%3ERe%3A%20BitLlocker%20Keys%20in%20Azure%20AD%20for%20Existing%20and%20New%20W10%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1223499%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F88404%22%20target%3D%22_blank%22%3E%40Nick%20Hogarth%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E404%20error%20on%20page%20buddy%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1223979%22%20slang%3D%22en-US%22%3ERe%3A%20BitLlocker%20Keys%20in%20Azure%20AD%20for%20Existing%20and%20New%20W10%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1223979%22%20slang%3D%22en-US%22%3EHi%20Stuart%3CBR%20%2F%3E%3CBR%20%2F%3EHave%20you%20tried%20Endpoint%20Protection%20Profile%20and%20Security%20Baseline%20with%20Write%20back%3F%20You%20may%20also%20need%20to%20OMI%20profile%20to%20have%20it%20without%20notification.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20it%20helps!%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fbitlocker-csp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fbitlocker-csp%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1225897%22%20slang%3D%22en-US%22%3ERe%3A%20BitLlocker%20Keys%20in%20Azure%20AD%20for%20Existing%20and%20New%20W10%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1225897%22%20slang%3D%22en-US%22%3ESorry%2C%20try%20%3CA%20href%3D%22http%3A%2F%2Fwww.rebeladmin.com%2F2019%2F09%2Fstep-step-guide-enable-bitlocker-cloud-managed-windows-10-devices-using-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.rebeladmin.com%2F2019%2F09%2Fstep-step-guide-enable-bitlocker-cloud-managed-windows-10-devices-using-microsoft-intune%2F%3C%2FA%3E%3C%2FLINGO-BODY%3E
Regular Contributor

Hi All

 

Any decent, step by step guides for:

 

Enabling BitLlocker and storing keys in Azure AD for Existing (No Wipe) and New (AutoPilot) W10 Devices?

 

Info appreciated

4 Replies

There is a guide here http://www.rebeladmin.com/2019/09/step-step-guide-enable-bitlocker-cloud-managed-windows-10-devices-... default it should store the key in Azure AD. On a test device, you can check out the Event Logs (

Application and Services Logs > Microsoft > Windows > BitLocker -API > Management) 

and it should say its storing the key in Azure AD. 

Hi Stuart

Have you tried Endpoint Protection Profile and Security Baseline with Write back? You may also need to OMI profile to have it without notification.

Hope it helps!
Moe

https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp