Forum Discussion

sumo83's avatar
sumo83
Iron Contributor
Feb 19, 2024

Bitlocker pushed via Intune does not work

Hello,

 

I'm trying to set up silent bitlocker deployment via Intune->Endpoint Security -> Disk Encryption. I have assigned a testing machine to it but it doesn't seems to enable bitlocker at all on the machine. I am attaching the configuration. We are in hybrid scenario and the computer is hybrid joined...

 

Now...

  • I can see the policy SUCCEEDED in intune... also "Per setting status" report shows all successful 
  • the laptop has only one drive - OS drive - and it is not encrypted
  • in Event Viewer, I see "Bitlocker CSP: OS Drive not protected"
  • before, I saw also "encryption type not supported" when I had "Full encryption" enabled. After changing it to "Used data only" this warning does not appear anymore

 

I have forced sync from the laptop.. also restarted few times already... but the drive still does not have bitlocker turned on. Btw, it is a fresh new laptop

 

Any advise? Am I missing anything here?

 

 

UPDATE:

I see one more warning in Event Viewer that is related to Bitlocker: "BitLocker CSP: GetDeviceEncryptionComplianceStatus indicates OSV is not compliant with returned status 0x106"

 

Regards,

Michal

 

 

 

 

  • G_Man's avatar
    G_Man
    Copper Contributor

    Hi, did you ever fix this? We have the same issue but we are Entra joined only. Identical models, some encrypt, some don't. Go figure....

    • sumo83's avatar
      sumo83
      Iron Contributor
      thanks for sharing this... Need to move us to full cloud and get rid of hybrid as soon as I can 🙂

      was trying to avoid GPO 🙂 ... Is this an intrusive GPO to existing machines? If I enable deploy the GPO to devices that already have bitlocker running, would there anything I should be aware of?
  • Hi Michal,

    I had a few challenges with the "Configure encryption methods". When I set these to not configured, BitLocker worked on the test device.

    Maybe it helps?

    Kind Regards,
    Tom
    • sumo83's avatar
      sumo83
      Iron Contributor
      Hi Tom.. thanks for advise... I've changed that one to "Not Configured".... but didn't help so far... Will leave it for few hours and check again...

Resources