bitlocker - devices assigned in intune are not encrypted

%3CLINGO-SUB%20id%3D%22lingo-sub-3009302%22%20slang%3D%22en-US%22%3Ebitlocker%20-%20devices%20assigned%20in%20intune%20are%20not%20encrypted%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3009302%22%20slang%3D%22en-US%22%3E%3CPRE%3E%3CSPAN%20class%3D%22%22%3Ein%20endpoint%20manager%20I%20added%20bitlocker%20config%2C%20but%20encryption%20was%20not%20applied%20on%20some%20devices.%20configuration%20status%20-Assignment%20Status.%20I%20see%20no%20errors%20for%20these%20devices%20but%20-%20Encrypted%20none%20%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FPRE%3E%3CDIV%20class%3D%22lia-spoiler-container%22%3E%3CA%20class%3D%22lia-spoiler-link%22%20href%3D%22%23%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%20target%3D%22_blank%22%3ESpoiler%3C%2FA%3E%3CNOSCRIPT%3E(Highlight%20to%20read)%3C%2FNOSCRIPT%3E%3CDIV%20class%3D%22lia-spoiler-border%22%3E%3CDIV%20class%3D%22lia-spoiler-content%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot_39.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F329733iB32B049C3460FFC0%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screenshot_39.png%22%20alt%3D%22Screenshot_39.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3CNOSCRIPT%3E%3CDIV%20class%3D%22lia-spoiler-noscript-container%22%3E%3CDIV%20class%3D%22lia-spoiler-noscript-content%22%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FNOSCRIPT%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CPRE%3E%3CSPAN%20class%3D%22%22%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3009302%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Senior Member
in endpoint manager I added bitlocker config, but encryption was not applied on some devices. configuration status -Assignment Status. I see no errors for these devices but - Encrypted none 

Spoiler
Screenshot_39.png








 

1 Reply

Hi @danilbetagmailcom,

 

To silently enable bitlocker on devices via Endpoint security -> Disk encryption.

 

You can configure below settings

Mr_Helaas_0-1638017269353.png

 

 

 

Device Prerequisites:

A device must meet the following conditions to be eligible for silently enabling BitLocker:

  • If end users log in to the devices as Administrators, the device must run Windows 10 version 1803 or later, or Windows 11.
  • If end users log in to the the devices as Standard Users, the device must run Windows 10 version 1809 or later, or Windows 11.
  • The device must be Azure AD Joined or Hybrid Azure AD Joined.
  • Device must contain at least TPM (Trusted Platform Module) 1.2.
  • The BIOS mode must be set to Native UEFI only.

Source: Encrypt Windows devices with BitLocker in Intune - Microsoft Intune | Microsoft Docs

 

 

To monitor the device encryption you can check the following Microsoft documentation
Encryption report for encrypted devices in Microsoft Intune - Microsoft Intune | Microsoft Docs

 

I hope this will help you, and please let me know if you have more questions.

If this fix your problem and please mark my answer as the solution.

 

With kind regards,

 

Rene