Intune Local GPO Change for Bitlocker Pre-boot Kyeboard Bypass

%3CLINGO-SUB%20id%3D%22lingo-sub-1231014%22%20slang%3D%22en-US%22%3EIntune%20Local%20GPO%20Change%20for%20Bitlocker%20Pre-boot%20Kyeboard%20Bypass%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1231014%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20been%20testing%20Bitlocker%20on%20my%20Surface%20Pro%20and%20ran%20into%20a%20small%20problem.%20I%20have%20configured%20to%20to%20boot%20with%20a%20PIN%20but%20it%20wont%20enable%20due%20to%20no%20pre-boot%20keyboard%20being%20avaialble.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20have%20tested%20the%20GPO%20below%20which%20does%20allow%20me%20to%20decrypt%20the%20drive%20and%20encrypt%20again.%20Is%20there%20a%20way%20I%20can%20push%20the%20GPO%20to%20the%20machine%20automatically%20from%20Intune%20as%20part%20of%20the%20pre-build%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20the%20Bitlocker%20encryption%20is%20not%20encrypting%20to%20the%20correct%20settings%2C%20it%20is%20defaulting%20to%20128bit%20and%20only%20active%20files%2C%20rather%20than%20the%20256%20and%20full%20drive%20encryption%20I%20have%20set.%20Is%20this%20due%20to%20it%20not%20being%20able%20to%20full%20configure%20using%20the%20Intune%20settings%20so%20it%20falls%20back%20to%20the%20default%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3CP%3EBen%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1231014%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1233888%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Local%20GPO%20Change%20for%20Bitlocker%20Pre-boot%20Kyeboard%20Bypass%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1233888%22%20slang%3D%22en-US%22%3EHi%20Ben%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHave%20you%20checked%20Endpoint%20Protection%20Config%20Profile-%26gt%3BWindows%20Encryption%20or%20Security%20Baseline%20-%26gt%3BBitlocker%20in%20Intune%3F%20It%20should%20have%20all%20the%20setting%20you%20looking%20for.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1234762%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Local%20GPO%20Change%20for%20Bitlocker%20Pre-boot%20Kyeboard%20Bypass%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1234762%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3EHi%2C%20yes%20I%20have%20checked%20all%20Bitlocker%20settings%20in%20Intune%20but%20unfortunately%20am%20unable%20to%20find%20this%20GPO.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20its%20not%20avaialble%20in%20Bitlocker%2C%20or%20Administrative%20Templates%2C%20is%20there%20a%20way%20to%20deploy%20a%20custom%20Intune%20policy%20which%20targets%20the%20local%20GPO%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1433253%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Local%20GPO%20Change%20for%20Bitlocker%20Pre-boot%20Kyeboard%20Bypass%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1433253%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20having%20the%20same%20issue%20with%20a%20new%20MS%20Surface%20Laptop%203.%3C%2FP%3E%3CP%3EI've%20configured%20require%20TPM%20and%20PIN%20through%20Intune%20policy%20and%20profile.%3C%2FP%3E%3CP%3EThe%20error%20states%20clearly%20that%20PIN%20is%20not%20possible%20because%20the%20Surface%20device%20has%20no%20boot-keyboard.%20I%20swear%20that%20this%20device%20has%20a%20none%20detatchable%20keyboard!%20%3A%5C%3C%2Fimg%3E%3C%2FP%3E%3CP%3EThe%20same%20policy%20and%20profile%20works%20fine%20on%20multiple%20Lenovo%20devices.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1435663%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20Local%20GPO%20Change%20for%20Bitlocker%20Pre-boot%20Kyeboard%20Bypass%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1435663%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F129710%22%20target%3D%22_blank%22%3E%40Ben%20Curran%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eyou%20have%20to%20assign%20your%20BitLocker%20Policy%20to%20a%20devices%20AAD%20group%20and%20ESP%20must%20be%20turned%20on%20otherwise%20you%20are%20too%20late%20and%20BitLocker%20Automatic%20encryption%20during%20AADJ%20will%20kick%20in%20to%20encrypt%20your%20device%20with%20default%20settings%20like%20128-bit%20used%20space%20etc.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESee%20all%20the%20detailed%20references%20here%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-autopilot%2Fbitlocker%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fwindows-autopilot%2Fbitlocker%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Foofhours.com%2F2019%2F08%2F26%2Fbitlocker-esp-and-windows-autopilot-working-in-harmony%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Foofhours.com%2F2019%2F08%2F26%2Fbitlocker-esp-and-windows-autopilot-working-in-harmony%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsetting-256-bit-encryption-for-bitlocker-during-autopilot-with%2Fba-p%2F323791%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsetting-256-bit-encryption-for-bitlocker-during-autopilot-with%2Fba-p%2F323791%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3CBR%20%2F%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

 

I have been testing Bitlocker on my Surface Pro and ran into a small problem. I have configured to to boot with a PIN but it wont enable due to no pre-boot keyboard being avaialble.

 

BitLocker Group Policy Settings("Enable use of BitLocker authentication requiring preboot keyboard input on slates")


I have tested the GPO below which does allow me to decrypt the drive and encrypt again. Is there a way I can push the GPO to the machine automatically from Intune as part of the pre-build?

 

Also the Bitlocker encryption is not encrypting to the correct settings, it is defaulting to 128bit and only active files, rather than the 256 and full drive encryption I have set. Is this due to it not being able to full configure using the Intune settings so it falls back to the default?

 

Regards

Ben

5 Replies
Hi Ben,

Have you checked Endpoint Protection Config Profile->Windows Encryption or Security Baseline ->Bitlocker in Intune? It should have all the setting you looking for.

@Moe_KinaniHi, yes I have checked all Bitlocker settings in Intune but unfortunately am unable to find this GPO.

 

If its not avaialble in Bitlocker, or Administrative Templates, is there a way to deploy a custom Intune policy which targets the local GPO?

I'm having the same issue with a new MS Surface Laptop 3.

I've configured require TPM and PIN through Intune policy and profile.

The error states clearly that PIN is not possible because the Surface device has no boot-keyboard. I swear that this device has a none detatchable keyboard! :\

The same policy and profile works fine on multiple Lenovo devices. @Moe_Kinani 

Hey @Ben Curran,

 

you have to assign your BitLocker Policy to a devices AAD group and ESP must be turned on otherwise you are too late and BitLocker Automatic encryption during AADJ will kick in to encrypt your device with default settings like 128-bit used space etc.

 

See all the detailed references here:

 

https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/bitlocker

https://oofhours.com/2019/08/26/bitlocker-esp-and-windows-autopilot-working-in-harmony/

https://techcommunity.microsoft.com/t5/intune-customer-success/setting-256-bit-encryption-for-bitloc...

 

best,
Oliver

Hi,

I am re-surfacing this issue as i have the same problem again. I have a Bitlocker policy, using the Endpoint security Disk encryption settings. My problem is the same as before, where I can set the policy to encrypt to 256 XTS, no PIN can be set as the system doesn't see the keyboard of the Suface Pro. I have exhausted all options, the only way I can get it to work is to set the encryption, then manually trigger the PIN settings from the Bilocker portal in Control Panel, once the GPO has been manually changed on the local machine.

My question is, what is the process for enabling PIN protected Bitlocker on machines that do not have a fixed keyboard?

Regards
Ben