Bitlocker pushed via Intune does not work

Brass Contributor

Hello,

 

I'm trying to set up silent bitlocker deployment via Intune->Endpoint Security -> Disk Encryption. I have assigned a testing machine to it but it doesn't seems to enable bitlocker at all on the machine. I am attaching the configuration. We are in hybrid scenario and the computer is hybrid joined...

 

Now...

  • I can see the policy SUCCEEDED in intune... also "Per setting status" report shows all successful 
  • the laptop has only one drive - OS drive - and it is not encrypted
  • in Event Viewer, I see "Bitlocker CSP: OS Drive not protected"
  • before, I saw also "encryption type not supported" when I had "Full encryption" enabled. After changing it to "Used data only" this warning does not appear anymore

 

I have forced sync from the laptop.. also restarted few times already... but the drive still does not have bitlocker turned on. Btw, it is a fresh new laptop

 

Any advise? Am I missing anything here?

 

bitlocker.jpg

 

UPDATE:

I see one more warning in Event Viewer that is related to Bitlocker: "BitLocker CSP: GetDeviceEncryptionComplianceStatus indicates OSV is not compliant with returned status 0x106"

 

Regards,

Michal

 

 

 

 

10 Replies
Hi Michal,

I had a few challenges with the "Configure encryption methods". When I set these to not configured, BitLocker worked on the test device.

Maybe it helps?

Kind Regards,
Tom
Hi Tom.. thanks for advise... I've changed that one to "Not Configured".... but didn't help so far... Will leave it for few hours and check again...
I'm curious!
no luck... left it overnight... restarted few times.... synced few times.... bitlocker still not enabled and I can still see the same events in event viewer
Please excuse the stupid question. But the requirements for BitLocker are already met? Hardware, TPM, operating system version etc.?
https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices

@TomWechsler not a stupid question at all.... Always better to double check it :) ... It is a brand new Lenovo X1 with up to date Windows 11... Intune Monitor shows below so it is TPM 2.0 as well...The laptop is also Hybrid Joined.... Not sure about BIOS UEFI though... haven't checked it..

 

 

sumo83_1-1708447558646.png

 

 

I have successfully set up BitLocker with a configuration profile. Perhaps you could also try a configuration profile with the exact same settings.

@sumo83 I see this often in a hybrid scenario. You can read my blogpost about this issue. Maybe it's your life saver.
https://www.burgerhout.org/the-bitlocker-haadj-nightmare/

was it on Hybrid Joined Devices Tom?
thanks for sharing this... Need to move us to full cloud and get rid of hybrid as soon as I can :)

was trying to avoid GPO :) ... Is this an intrusive GPO to existing machines? If I enable deploy the GPO to devices that already have bitlocker running, would there anything I should be aware of?