You may manage BitLocker in your organization using SCCM (MBAM). It’s also possible to create a policy for Bitlocker if you’ve switched to modern management and Endpoint Manager (Intune).
If you’re not aware, Bitlocker is a Microsoft solution for drive encryption. Bitlocker is not a new solution. It has been introduced in Windows 7. As a system administrator, you can manage how to deploy it, its policy and the most important part, keeping the recovery key in a safe place.
BitLocker provides the most protection when used with a Trusted Platform Module (TPM) version 1.2 or later. The TPM is a hardware component installed in many newer computers by computer manufacturers.
In this post, we’ll show you how to create your first Intune Bitlocker policy (Endpoint Manager) for your Windows 10 computer. We’ll also give you some troubleshooting tips and tips on managing it in the long term.
In Microsoft Intune, there’s no specific requirement to create a Bitlocker policy except that you need the right permission.
However, if you’re unfamiliar with Bitlocker, there’s some requirement on the OS side. We recommend that you use a computer equipped with a TPM chip.
You can use the Endpoint Security Manager Built-in Role or create a new role and use the Remote Tasks permissions, including Bitlocker actions.
To use the Endpoint Security Manager role :

To use a new group :


It’s now time to create our first Bitlocker policy.




Suppose you need to install your policy without user intervention silently. You must set the following options in your configuration settings:
During the configuration settings section, make sure to configure Base Settings like below:

In the OS Drive Settings, configure the section like below:

In addition, Microsoft documentation state that the device must meet the following requirements for silent installation:




You can now log on a machine or use the portal to initiate a Sync request for your machine to receive the new policy.

It’s now time to see if our policy is working. To monitor your Bitlocker deployment :

Suppose you encounter an error while encrypting a device. The first step is to look at the Event Viewer of the affected machine.
Bitlocker events are stored in Applications and Services logs\Microsoft\Windows\BitLocker-API and BitLocker-DrivePreparationTool

From the Intune portal, you can view BitLocker Key IDs and Bitlocker recovery keys for your Windows 10 devices

We hope this article helps you to manage Windows 10 and your Intune Bitlocker Policy. Feel free to use the comment section if you have any questions.
Please fill out the form, and one of our representatives will contact you in Less Than 24 Hours. We are open from Monday to Friday.
Thank you for subscribing to our newsletter or requesting a quote. You will receive our next month's newsletter. If you have requested a quote, we will get in touch with you as soon as possible.
Something went wrong!
Thank for your reply!